download:

CarboniteUpgrade-pro-client.exe

Full analysis: https://app.any.run/tasks/9acfb7d4-0890-4cd6-9a38-ca597a8d1cf0
Verdict: Malicious activity
Analysis date: December 21, 2019, 17:56:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9FAAFCB8110BF0DC7993992D1234F3A1

SHA1:

4C424FE45DB99BC6CA2C87D42B2A4060CE8BDB7D

SHA256:

18624C5BF3D03C8BB8D40F97978D6B66256EA76861B878AAFE2D22FFF1A3F940

SSDEEP:

393216:TZXLcMe3BR9Y26PClleqOek+EeESbQI4wROOHNV:JC3a2YIlTeQQI4wrNV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Loads dropped or rewritten executable

      • svchost.exe (PID: 864)
      • regsvr32.exe (PID: 2708)
      • explorer.exe (PID: 920)
    • Changes the autorun value in the registry

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Application was dropped or rewritten from another process

      • CarboniteUI.exe (PID: 3160)
      • carboniteservice.exe (PID: 1528)
      • CarboniteUI.exe (PID: 2104)
      • carboniteservice.exe (PID: 640)
    • Loads the Task Scheduler COM API

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
      • explorer.exe (PID: 920)
      • carboniteservice.exe (PID: 640)
    • Registers / Runs the DLL via REGSVR32.EXE

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Reads internet explorer settings

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
      • CarboniteUI.exe (PID: 3160)
    • Executable content was dropped or overwritten

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Creates a software uninstall entry

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Creates files in the program directory

      • explorer.exe (PID: 920)
      • CarboniteUI.exe (PID: 3160)
      • carboniteservice.exe (PID: 640)
      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Adds / modifies Windows certificates

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
    • Creates files in the Windows directory

      • svchost.exe (PID: 864)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 2708)
    • Executed as Windows Service

      • carboniteservice.exe (PID: 640)
  • INFO

    • Reads settings of System Certificates

      • CarboniteUpgrade-pro-client.exe (PID: 1848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:04:30 17:42:44+02:00
PEType: PE32
LinkerVersion: 10
CodeSize: 632832
InitializedDataSize: 16643584
UninitializedDataSize: -
EntryPoint: 0x31192
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 6.3.5.8094
ProductVersionNumber: 6.3.5.8094
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral 2
CharacterSet: Windows, Latin1
CompanyName: Carbonite, Inc.
FileDescription: Carbonite Setup
FileVersion: 6.3.5 build 8094 (Apr-30-2019)
InternalName: CarboniteSetup.exe
LegalCopyright: © Carbonite, Inc., 2005-2019 All rights reserved
OriginalFileName: CarboniteSetup.exe
ProductName: Carbonite Setup
ProductVersion: 6.3.5 build 8094 (Apr-30-2019)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Apr-2019 15:42:44
Detected languages:
  • English - United Kingdom
  • English - United States
Debug artifacts:
  • C:\Jenkins\workspace\endpoint\Endpoint_Stability\EndpointStability_Build\Carbonite\ClientWin\Build\Release\CarboniteSetup.pdb
CompanyName: Carbonite, Inc.
FileDescription: Carbonite Setup
FileVersion: 6.3.5 build 8094 (Apr-30-2019)
InternalName: CarboniteSetup.exe
LegalCopyright: © Carbonite, Inc., 2005-2019 All rights reserved
OriginalFilename: CarboniteSetup.exe
ProductName: Carbonite Setup
ProductVersion: 6.3.5 build 8094 (Apr-30-2019)

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 30-Apr-2019 15:42:44
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0009A798
0x0009A800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.6056
.rdata
0x0009C000
0x0003197E
0x00031A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.66769
.data
0x000CE000
0x0000913C
0x00004600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.73134
.rsrc
0x000D8000
0x00FA951C
0x00FA9600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.99724

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.20798
985
Latin 1 / Western European
English - United States
RT_MANIFEST
2
6.53314
1720
Latin 1 / Western European
UNKNOWN
RT_ICON
3
6.59901
2440
Latin 1 / Western European
UNKNOWN
RT_ICON
4
7.9919
51192
Latin 1 / Western European
UNKNOWN
RT_ICON
5
6.51575
4264
Latin 1 / Western European
UNKNOWN
RT_ICON
6
6.63994
6760
Latin 1 / Western European
UNKNOWN
RT_ICON
7
0
482
Latin 1 / Western European
UNKNOWN
RT_STRING
8
3.14652
492
Latin 1 / Western European
UNKNOWN
RT_STRING
9
2.24826
90
Latin 1 / Western European
UNKNOWN
RT_STRING
19
1.02225
176
Latin 1 / Western European
UNKNOWN
RT_STRING

Imports

ADVAPI32.dll
GDI32.dll
KERNEL32.dll
NETAPI32.dll
OLEAUT32.dll
PSAPI.DLL
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
Secur32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start carboniteupgrade-pro-client.exe regsvr32.exe no specs carboniteui.exe carboniteservice.exe svchost.exe explorer.exe carboniteui.exe carboniteservice.exe carboniteupgrade-pro-client.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
640"C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe"C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
services.exe
User:
SYSTEM
Company:
Carbonite, Inc. (www.carbonite.com)
Integrity Level:
SYSTEM
Description:
Carbonite Secure Backup Engine
Exit code:
0
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\program files\carbonite\carbonite backup\carboniteservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
864C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
920explorer.exeC:\Windows\explorer.exe
winlogon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1528"C:\Program Files\Carbonite\Carbonite Backup\carboniteservice" /serviceC:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
CarboniteUpgrade-pro-client.exe
User:
admin
Company:
Carbonite, Inc. (www.carbonite.com)
Integrity Level:
HIGH
Description:
Carbonite Secure Backup Engine
Exit code:
0
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\program files\carbonite\carbonite backup\carboniteservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1848"C:\Users\admin\AppData\Local\Temp\CarboniteUpgrade-pro-client.exe" C:\Users\admin\AppData\Local\Temp\CarboniteUpgrade-pro-client.exe
explorer.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
HIGH
Description:
Carbonite Setup
Exit code:
0
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\users\admin\appdata\local\temp\carboniteupgrade-pro-client.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2104"C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe" /regserverC:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
CarboniteUpgrade-pro-client.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
HIGH
Description:
Carbonite User Interface
Exit code:
0
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\program files\carbonite\carbonite backup\carboniteui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2708"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll"C:\Windows\system32\regsvr32.exeCarboniteUpgrade-pro-client.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3160"C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe" /finalizeevent:c47d293a-e740-449d-8b7e-e672da0b2966 /reguid %7B22222222-2222-2222-2222-222200001848%7D /correlationid {ED5AF033-9496-4EDF-A656-4D02E5299F21}C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
explorer.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
MEDIUM
Description:
Carbonite User Interface
Exit code:
0
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\program files\carbonite\carbonite backup\carboniteui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3168"C:\Users\admin\AppData\Local\Temp\CarboniteUpgrade-pro-client.exe" C:\Users\admin\AppData\Local\Temp\CarboniteUpgrade-pro-client.exeexplorer.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
MEDIUM
Description:
Carbonite Setup
Exit code:
3221226540
Version:
6.3.5 build 8094 (Apr-30-2019)
Modules
Images
c:\users\admin\appdata\local\temp\carboniteupgrade-pro-client.exe
c:\systemroot\system32\ntdll.dll
Total events
3 426
Read events
3 034
Write events
386
Delete events
6

Modification events

(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Carbonite\CarboniteSetup
Operation:writeName:LogErrorCount
Value:
1
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019122120191222
Operation:writeName:CachePath
Value:
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019122120191222
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019122120191222
Operation:writeName:CachePrefix
Value:
:2019122120191222:
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019122120191222
Operation:writeName:CacheLimit
Value:
8192
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019122120191222
Operation:writeName:CacheOptions
Value:
11
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019122120191222
Operation:writeName:CacheRepair
Value:
0
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019092020190921
Operation:delete keyName:
Value:
(PID) Process:(1848) CarboniteUpgrade-pro-client.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
CarboniteUpgrade-pro-client.exe
Executable files
4
Suspicious files
8
Text files
1 750
Unknown types
53

Dropped files

PID
Process
Filename
Type
1848CarboniteUpgrade-pro-client.exeC:\Users\Public\Desktop\CarboniteSetup.logtext
MD5:
SHA256:
864svchost.exeC:\Windows\appcompat\programs\RecentFileCache.bcftxt
MD5:
SHA256:
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F.tmpcompressed
MD5:
SHA256:
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-bg_flat_100_000000_40x100.pngimage
MD5:C18CD01623C7FED23C80D53E2F5E7C78
SHA256:0E1AC198171A7EFB4E331B0AA097A8AA1D4EBDBADE5B29C4861BB422F95F1BE7
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-icons_222222_256x240.pngimage
MD5:EBE6B6902A408FBF9CAC6379A1477525
SHA256:A2CCFDC001858222885A9DF39200840AC7A3F479BA889727D32A10398DB7918A
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-bg_glass_50_708f11_1x400.pngimage
MD5:389C98192B3B251DEF1049C48AE5799F
SHA256:55C3271763FCC0AD1131A05294D44E49792D203192161F38933B206E57E624AE
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-bg_flat_95_fef1ec_40x100.pngimage
MD5:952E00271F260843DE98780F181587D4
SHA256:E163E903808496D8CED19C1144D363BAD94DB913A59732A583B5CC077C8D11CC
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-bg_glass_50_829a39_1x400.pngimage
MD5:E6C3763CE9D6885C843F50271DE92690
SHA256:CBAD22BAB026FDDF634085B65BCB773F3EE1CF09733AA5B07C429DA47D2B34CB
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-bg_flat_75_ffffff_40x100.pngimage
MD5:8692E6EFDDF882ACBFF144C38EA7DFDF
SHA256:39AB7CCD9F4E82579DA78A9241265DF288D8EB65DBBD7CF48AED2D0129887DF5
1848CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F\css\kermit\images\ui-icons_333333_256x240.pngimage
MD5:548A05AF48EF6545DB2FD999B12CA937
SHA256:5C7ADBCEF7C072227C543049B008500D44D90F0698E1D9B05F4BE2B354226660
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
7
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1848
CarboniteUpgrade-pro-client.exe
GET
200
205.185.216.10:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
1848
CarboniteUpgrade-pro-client.exe
GET
200
205.185.216.10:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
1848
CarboniteUpgrade-pro-client.exe
GET
200
143.204.208.228:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1848
CarboniteUpgrade-pro-client.exe
205.185.216.10:80
www.download.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
1848
CarboniteUpgrade-pro-client.exe
143.204.208.228:80
x.ss2.us
US
suspicious
1848
CarboniteUpgrade-pro-client.exe
45.60.155.109:443
www.carbonite.com
US
unknown
1848
CarboniteUpgrade-pro-client.exe
52.216.142.62:443
s3.amazonaws.com
Amazon.com, Inc.
US
shared
1848
CarboniteUpgrade-pro-client.exe
143.204.214.87:443
zna7usvzk4.execute-api.us-east-1.amazonaws.com
US
unknown
1848
CarboniteUpgrade-pro-client.exe
199.87.217.73:443
account.carbonite.com
EVAULT INCORPORATED
US
unknown
3160
CarboniteUI.exe
143.204.214.87:443
zna7usvzk4.execute-api.us-east-1.amazonaws.com
US
unknown

DNS requests

Domain
IP
Reputation
www.carbonite.com
  • 45.60.155.109
suspicious
zna7usvzk4.execute-api.us-east-1.amazonaws.com
  • 143.204.214.87
  • 143.204.214.6
  • 143.204.214.77
  • 143.204.214.85
suspicious
x.ss2.us
  • 143.204.208.228
  • 143.204.208.222
  • 143.204.208.42
  • 143.204.208.196
whitelisted
www.download.windowsupdate.com
  • 205.185.216.10
  • 205.185.216.42
whitelisted
account.carbonite.com
  • 199.87.217.73
unknown
s3.amazonaws.com
  • 52.216.142.62
shared

Threats

No threats detected
Process
Message
CarboniteUpgrade-pro-client.exe
LogMsg is not open.
CarboniteUpgrade-pro-client.exe
LogMsg is not open.
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.33+00:00 > 2096:CarboniteSetup(6.3.5 build 8094 (Apr-30-2019)) 32-bit starting. Command Line:"c:\users\admin\appdata\local\temp\carboniteupgrade-pro-client.exe"
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.33+00:00 E 2096:ERROR: Localizer::Load C:\Users\admin\AppData\Local\Temp\skin\CarboniteSetup.strings(failed open) 3 2019-12-21T17:57:20.33+00:00 E 2096:ERROR: Localizer::String 86 cannot be localized - not found
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.38+00:00 @ [BrowserControl] 2096:carbonite::BrowserControl::SetClientSite(1) Config.SetISM is 1
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.39+00:00 # 3984:Unzip: C:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F.tmp to C:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F. Msg=74, Retry=0
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.39+00:00 W 3984:Warning: `anonymous-namespace'::GetMaxAutoRetryCount(Could not open reg key: SOFTWARE\Carbonite\CarboniteSetup)
CarboniteUpgrade-pro-client.exe
failed to change date on .\ in C:\Users\admin\AppData\Local\Temp\Crb-{ED5AF033-9496-4EDF-A656-4D02E5299F21}\CrbCA5F - 3
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.52+00:00 @ 2096:carbonite::CrbInternetSecurityManager::ProcessUrlAction - processing URL res://ieframe.dll/unknownprotocol.htm, action is 9984
CarboniteUpgrade-pro-client.exe
2019-12-21T17:57:20.53+00:00 @ 2096:carbonite::CrbInternetSecurityManager::ProcessUrlAction - processing URL res://ieframe.dll/unknownprotocol.htm, action is 8454