| File name: | lcFGnjYe2QlfWRaCZBbTzO.zip |
| Full analysis: | https://app.any.run/tasks/20827437-0e35-4db7-926b-c4c808ba4121 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | December 18, 2018, 15:14:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 37170BFF36921D8A5BA44CDFF4E52729 |
| SHA1: | 614B85A7D72851DA289F95AA16BB19C191497F1B |
| SHA256: | 153D21F86ADD500EE0D5581EB7B4D7B2280DAFA327377013B744AEB79D407173 |
| SSDEEP: | 24576:UMd0/VEUYT4ym7PiwT6tgCLxttEARCFYRqRvxJFgVFEADkVSDd3cMld:UMK9EUQ477PiC6GCL3K8qRvxjmbDkuhH |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:12:18 11:07:04 |
| ZipCRC: | 0xbec0bee9 |
| ZipCompressedSize: | 1303498 |
| ZipUncompressedSize: | 1332968 |
| ZipFileName: | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Program Files\AVG\Antivirus\aswidsagent.exe" | C:\Program Files\AVG\Antivirus\aswidsagent.exe | services.exe | ||||||||||||
User: SYSTEM Company: AVG Technologies CZ, s.r.o. Integrity Level: SYSTEM Description: AVG Software Analyzer Exit code: 0 Version: 18.8.4.1339 Modules
| |||||||||||||||
| 624 | AvEmUpdate.exe /installer1 /emupdater /applydll "C:\Program Files\AVG\Antivirus\Setup\fe2f42e9-3748-40c9-8c54-784562f34018.dll" | C:\Program Files\AVG\Antivirus\AvEmUpdate.exe | AvEmUpdate.exe | ||||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Emergency Update Exit code: 0 Version: 18.8.4084.0 Modules
| |||||||||||||||
| 648 | C:\Users\admin\AppData\Local\WhatsApp\Update.exe --checkForUpdate https://web.whatsapp.com/desktop/windows/release/ia32?version=0.3.1649 | C:\Users\admin\AppData\Local\WhatsApp\Update.exe | — | WhatsApp.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
| 920 | C:\Users\admin\AppData\Local\WhatsApp\app-0.2.2732\WhatsApp.exe --reporter-url=https://web-crashlog.whatsapp.net/upload.php --application-name=WhatsApp --v=1 | C:\Users\admin\AppData\Local\WhatsApp\app-0.2.2732\WhatsApp.exe | WhatsApp.exe | ||||||||||||
User: admin Company: WhatsApp Integrity Level: MEDIUM Description: WhatsApp Exit code: 0 Version: 1.4.2 Modules
| |||||||||||||||
| 928 | "C:\Program Files\AVG\Antivirus\RegSvr.exe" "C:\Program Files\AVG\Antivirus\aswAMSI.dll" | C:\Program Files\AVG\Antivirus\RegSvr.exe | — | instup.exe | |||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Antivirus Installer Exit code: 0 Version: 18.8.4084.0 Modules
| |||||||||||||||
| 1024 | cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D39016406360932.dat" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1204 | C:\Windows\system32\reg.exe ADD HKCU\Software\Classes\whatsapp /f | C:\Windows\system32\reg.exe | — | WhatsApp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1248 | C:\Users\admin\AppData\Local\WhatsApp\Update.exe --createShortcut=WhatsApp.exe --shortcut-locations=StartMenu | C:\Users\admin\AppData\Local\WhatsApp\Update.exe | — | WhatsApp.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1420 | /d /c TIMEOUT 1 & cmd /d /c copy /B /Y "C:\Users\admin\AppData\Local\Temp\D85911679986161.dat"+"C:\Users\admin\AppData\Local\Temp\D85911679986162.dat" "C:\Users\admin\AppData\Local\Temp\in7E200845\754ECA65_stp\uninstaller.exe" & cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D85911679986161.dat" & cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D85911679986162.dat" | C:\Windows\system32\cmd.exe | — | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1676 | "C:\Users\admin\AppData\Local\WhatsApp\app-0.3.1649\WhatsApp.exe" | C:\Users\admin\AppData\Local\WhatsApp\app-0.3.1649\WhatsApp.exe | Update.exe | ||||||||||||
User: admin Company: WhatsApp Integrity Level: MEDIUM Description: WhatsApp Exit code: 0 Version: 0.3.1649 Modules
| |||||||||||||||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\lcFGnjYe2QlfWRaCZBbTzO.zip | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3524 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3524.9058\installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | — | |
MD5:— | SHA256:— | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\0013DF18.log | — | |
MD5:— | SHA256:— | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_positions.scss | text | |
MD5:D70EE316E26374F839174916490E937E | SHA256:3AFFBAEB6F57451FAF94CA9CBCAB2504EF75DF0E8570AA7BE99DD52C9CECB8E7 | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_visibility.scss | text | |
MD5:02061AEA75EAC76FFF1D2A8E9607D64C | SHA256:F32292CF3212F83814C985AA82F0F8A0E8DADA0AEE81CD7401AA3AAC08E45BC0 | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_colors.scss | text | |
MD5:2DA278FBB61E370E0CC9F548E8154E1C | SHA256:857A73FC1DA7CF54525048AA60EC9E2F07328EE1D718A66E3B17186170BB5B5B | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_float.scss | text | |
MD5:BC5EB91B59A99E0FC439E02F80319975 | SHA256:EAF9D36E3E75177E64090AC71C6FCF9BB6465CD21F5C0A5CCB05666033609DA8 | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_typography.scss | text | |
MD5:0D6E99087615172921E0383B0BCE87D2 | SHA256:A94BD2FB6595FAEA527116D8D8EE090FF74E89216EF3C9260F5F0B5BFA330E0E | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_margin.scss | text | |
MD5:E83D43D06045E990E910E494AEBAE8AE | SHA256:15484F9E0794F7526E5671615BCDBB436DC7F53012387821D2163CE59FA5E84B | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_backgrounds.scss | text | |
MD5:6092A3768F84CFBC6E5C52301F5B63EA | SHA256:8A22A3285F3C7D82AA1A4273BDD62729DA241723507C1ECD5D2FD0A24C12E23B | |||
| 2816 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | C:\Users\admin\AppData\Local\Temp\inH130229655360\css\helpers\_clearfix.scss | text | |
MD5:ADD166BC071472DC105F4734D2DCF0E2 | SHA256:75EBE8B4A4CBBAC0EB4DE35B60972452B4526C56EEFB5186DD40A92C70773377 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | GET | 301 | 104.27.136.111:80 | http://median.mp3.es/uploads/installer_logos/programs/56/228656/65333.png | US | — | — | shared |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | HEAD | 200 | 149.202.192.156:80 | http://i_mp3-es_WhatsApp-para-PC-0-2-2732--32-bit.foramuinareqy.com/crawled_soft/2/2/idpf-mp300z4b8d2d6b7445358785154a7fa1034b68-ici-5889c16d992e22.71369822-chrome-idpf/228656-691348-whatsapp-for-pc.exe | FR | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 54.154.255.147:80 | http://os.guarddownloadsapps.com/Vittalia_ns/ | IE | binary | 455 Kb | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | GET | 200 | 146.185.27.53:80 | http://img.guarddownloadsapps.com/img/Tavasat/15Feb17/v2/EN.png | GB | image | 43.9 Kb | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | POST | 200 | 52.214.73.247:80 | http://rp.guarddownloadsapps.com/ | IE | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 52.214.73.247:80 | rp.guarddownloadsapps.com | Amazon.com, Inc. | IE | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 54.154.81.16:80 | info.guarddownloadsapps.com | Amazon.com, Inc. | IE | whitelisted |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 104.27.136.111:80 | median.mp3.es | Cloudflare Inc | US | shared |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 104.27.136.111:443 | median.mp3.es | Cloudflare Inc | US | shared |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 54.154.255.147:80 | os.guarddownloadsapps.com | Amazon.com, Inc. | IE | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 146.185.27.53:80 | img.guarddownloadsapps.com | UK-2 Limited | GB | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 149.202.192.156:80 | i_mp3-es_whatsapp-para-pc-0-2-2732--32-bit.foramuinareqy.com | OVH SAS | FR | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 185.59.222.146:80 | cdneu.vittaliacdn.com | Datacamp Limited | NL | malicious |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | 199.115.112.67:80 | cdnus.vittaliacdn.com | Leaseweb USA, Inc. | US | malicious |
1904 | avgSetup.exe | 172.217.168.46:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
rp.guarddownloadsapps.com |
| malicious |
info.guarddownloadsapps.com |
| malicious |
median.mp3.es |
| unknown |
os.guarddownloadsapps.com |
| malicious |
img.guarddownloadsapps.com |
| malicious |
i_mp3-es_whatsapp-para-pc-0-2-2732--32-bit.foramuinareqy.com |
| malicious |
cdneu.vittaliacdn.com |
| malicious |
cdnus.vittaliacdn.com |
| suspicious |
www.google-analytics.com |
| whitelisted |
iavs9x.avg.u.avcdn.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1 |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2 |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4 |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3 |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Generic Protocol Command Decode | SURICATA HTTP Host header invalid |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | A Network Trojan was detected | SC TROJAN_DOWNLOADER Possible threat - .exe downloading with HEAD option |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Generic Protocol Command Decode | SURICATA HTTP Host header invalid |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | Generic Protocol Command Decode | SURICATA HTTP Host header invalid |
2744 | installer_whatsapp_para_pc_0_2_2732__32_bit_.exe | unknown | SURICATA IPv4 invalid checksum |
Process | Message |
|---|---|
WhatsApp.exe | [920:3532:1218/151702:VERBOSE1:crash_service_main.cc(76)] Session start. cmdline is [--reporter-url=https://web-crashlog.whatsapp.net/upload.php --application-name=WhatsApp --v=1]
|
WhatsApp.exe | [920:3532:1218/151702:VERBOSE1:crash_service.cc(142)] window handle is 00030180
|
WhatsApp.exe | [920:3532:1218/151702:VERBOSE1:crash_service.cc(284)] pipe name is \\.\pipe\WhatsApp Crash Service
dumps at C:\Users\admin\AppData\Local\Temp\WhatsApp Crashes
|
WhatsApp.exe | [920:3532:1218/151702:VERBOSE1:crash_service.cc(288)] checkpoint is C:\Users\admin\AppData\Local\Temp\WhatsApp Crashes\crash_checkpoint.txt
server is https://web-crashlog.whatsapp.net/upload.php
maximum 128 reports/day
reporter is electron-crash-service
|
WhatsApp.exe | [920:3532:1218/151702:VERBOSE1:crash_service_main.cc(92)] Ready to process crash requests
|
WhatsApp.exe | [920:1828:1218/151702:VERBOSE1:crash_service.cc(317)] client start. pid = 2168
|
WhatsApp.exe | [920:3064:1218/151703:VERBOSE1:crash_service.cc(325)] client end. pid = 2168
|
WhatsApp.exe | [920:3064:1218/151704:VERBOSE1:crash_service.cc(346)] zero clients. exiting
|
WhatsApp.exe | [920:3532:1218/151704:VERBOSE1:crash_service.cc(486)] session ending..
|
WhatsApp.exe | [920:3532:1218/151704:VERBOSE1:crash_service.cc(491)] clients connected :1
clients terminated :1
dumps serviced :0
dumps reported :0
|