| URL: | https://zinfandel.centrastage.net/csm/profile/downloadAgent/e432dfa4-71de-4105-bca4-dc6f87df7956 |
| Full analysis: | https://app.any.run/tasks/3a479d7f-8297-4236-ada3-3447cf61bf42 |
| Verdict: | Malicious activity |
| Analysis date: | July 15, 2022, 21:26:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 4224824FF159F4861CA47F535D83F46F |
| SHA1: | 62FF64A8B02B155F06B14F86F6FAB1A6EE8A3981 |
| SHA256: | 15B259D35A4CB381B6DA2D0B981E31AA8647B07AF31709F9D62F2F7FF1804908 |
| SSDEEP: | 3:N8XBMXEf/tIKVXoaFICqWXOuadIDvG:2XBMXu/hV4aFEuad7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3492 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 456 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=976 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1888 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 756 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=600 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 764 | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: LOCAL SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 780 | C:\Windows\Temp\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\SSU_Clean.exe /S | C:\Windows\Temp\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\SSU_Clean.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop Remote software updater enables updates and enhancements to the Splashtop Remote. Exit code: 0 Version: 1.1.12.1 Modules
| |||||||||||||||
| 916 | "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i autologin=1,hidewindow=1,autoupdate=0,confirm_d=0,reqsyspwd=0,loopback=1 | C:\Windows\Temp\unpack\PreVerCheck.exe | Splashtop_Streamer.exe | ||||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop® Streamer Exit code: 0 Version: 3.50.2.28 Modules
| |||||||||||||||
| 960 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1548 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 964 | C:\Windows\System32\cmd.exe /C "taskkill.exe /F /IM SRChat.exe /T" | C:\Windows\System32\cmd.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 996 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1044,13188139369393783860,145733981083428834,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2556 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30972049 | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30972049 | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2844) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3216 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62D1DB89-C90.pma | — | |
MD5:— | SHA256:— | |||
| 2844 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | binary | |
MD5:— | SHA256:— | |||
| 2844 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | der | |
MD5:— | SHA256:— | |||
| 3324 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6A2279C2CA42EBEE26F14589F0736E50 | der | |
MD5:— | SHA256:— | |||
| 3324 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 3324 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6A2279C2CA42EBEE26F14589F0736E50 | binary | |
MD5:— | SHA256:— | |||
| 3324 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | der | |
MD5:— | SHA256:— | |||
| 3324 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | binary | |
MD5:— | SHA256:— | |||
| 2844 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 3216 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 173.194.160.72:80 | http://r3---sn-1gi7znes.gvt1.com/edgedl/release2/chrome_component/adzydrxsf3el6cyy2rjdi72igdpq_2838/jflookgnkcckhobaglndicnbbgbonegd_2838_all_ac7qgzy74prsoqyprd2pjde3a5ha.crx3?cms_redirect=yes&mh=od&mip=45.132.226.166&mm=28&mn=sn-1gi7znes&ms=nvh&mt=1657920023&mv=m&mvi=3&pl=24&rmhost=r1---sn-1gi7znes.gvt1.com&shardbypass=sd&smhost=r3---sn-1gi7znek.gvt1.com | US | — | — | whitelisted |
— | — | HEAD | 302 | 142.250.184.206:80 | http://redirector.gvt1.com/edgedl/release2/chrome_component/adzydrxsf3el6cyy2rjdi72igdpq_2838/jflookgnkcckhobaglndicnbbgbonegd_2838_all_ac7qgzy74prsoqyprd2pjde3a5ha.crx3 | US | — | — | whitelisted |
3324 | iexplore.exe | GET | 200 | 52.222.250.112:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
3324 | iexplore.exe | GET | 200 | 18.66.107.194:80 | http://crl.rootca1.amazontrust.com/rootca1.crl | US | der | 493 b | whitelisted |
3324 | iexplore.exe | GET | 200 | 18.66.242.94:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
1572 | chrome.exe | GET | 302 | 142.250.181.238:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx | US | html | 556 b | whitelisted |
2844 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
3324 | iexplore.exe | GET | 200 | 18.64.100.193:80 | http://s.ss2.us/r.crl | US | der | 434 b | whitelisted |
3324 | iexplore.exe | GET | 200 | 18.66.121.29:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAvrs2VEvVAj%2FgH28N%2F48UQ%3D | US | der | 471 b | whitelisted |
— | — | GET | 206 | 173.194.160.72:80 | http://r3---sn-1gi7znes.gvt1.com/edgedl/release2/chrome_component/adzydrxsf3el6cyy2rjdi72igdpq_2838/jflookgnkcckhobaglndicnbbgbonegd_2838_all_ac7qgzy74prsoqyprd2pjde3a5ha.crx3?cms_redirect=yes&mh=od&mip=45.132.226.166&mm=28&mn=sn-1gi7znes&ms=nvh&mt=1657920023&mv=m&mvi=3&pl=24&rmhost=r1---sn-1gi7znes.gvt1.com&shardbypass=sd&smhost=r3---sn-1gi7znek.gvt1.com | US | binary | 5.66 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3324 | iexplore.exe | 52.222.214.44:443 | zinfandel.centrastage.net | Amazon.com, Inc. | US | suspicious |
3324 | iexplore.exe | 52.222.250.112:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
3324 | iexplore.exe | 18.66.242.155:80 | ocsp.rootca1.amazontrust.com | Massachusetts Institute of Technology | US | whitelisted |
1572 | chrome.exe | 142.250.186.67:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
1572 | chrome.exe | 142.250.186.142:443 | clients2.google.com | Google Inc. | US | whitelisted |
2844 | iexplore.exe | 204.79.197.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
3324 | iexplore.exe | 18.66.107.194:80 | crl.rootca1.amazontrust.com | Massachusetts Institute of Technology | US | whitelisted |
1572 | chrome.exe | 52.222.214.40:443 | zinfandel.centrastage.net | Amazon.com, Inc. | US | suspicious |
3324 | iexplore.exe | 52.222.214.125:443 | zinfandel.centrastage.net | Amazon.com, Inc. | US | suspicious |
3324 | iexplore.exe | 18.66.242.94:80 | o.ss2.us | Massachusetts Institute of Technology | US | unknown |
Domain | IP | Reputation |
|---|---|---|
zinfandel.centrastage.net |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
s.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
clients2.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
— | — | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
Process | Message |
|---|---|
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUnPack::FindHeader] Name:C:\ProgramData\CentraStage\Splashtop\Splashtop_Streamer.exe (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUnPack::FindHeader] Sign Size:7776 (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUnPack::FindHeader] Header offset:429568 (Last=183) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUnPack::UnPackFiles] FreeSpace:234096865280 FileSize:36885504 (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:01 [CUnPack::UnPackFiles] (1/5)UnPack file name:C:\Windows\TEMP\unpack\setup.msi (36885504) (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:02 [CUnPack::UnPackFiles] UnPack count:1 len:36885504 File:(null) (Last=0) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:02 [CUnPack::UnPackFiles] FreeSpace:234059968512 FileSize:15 (Last=183) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:02 [CUnPack::UnPackFiles] (2/5)UnPack file name:C:\Windows\TEMP\unpack\run.bat (15) (Last=122) |
Splashtop_Streamer.exe | [2012]2022-07-15 22:31:02 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) (Last=0) |