File name:

mt4setup.exe

Full analysis: https://app.any.run/tasks/77bc7842-73c1-4693-90b2-c3e14c503460
Verdict: Malicious activity
Analysis date: November 24, 2020, 08:35:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

A0FC738599E51A343F105E12B6F5D8DE

SHA1:

986041ACD5D891316A508951B14EBF783FFDA5D2

SHA256:

1A1D4E12C4C8F5074A8AFFBD7F3174928F509189EDE7C970C9F9FF5F55D02653

SSDEEP:

24576:tYUJ84V4U6llJpiVNEplb9kDkvvr9eG+9QLh9VXAyn59dGlU//QrKrB73L:tYUe64U6ll2VNEplby8vrAGvLhDXAyvh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • terminal.exe (PID: 3508)
    • Changes settings of System certificates

      • mt4setup.exe (PID: 688)
  • SUSPICIOUS

    • Creates files in the user directory

      • mt4setup.exe (PID: 688)
      • terminal.exe (PID: 1300)
      • metaeditor.exe (PID: 3608)
      • terminal.exe (PID: 3508)
    • Starts Internet Explorer

      • mt4setup.exe (PID: 688)
    • Low-level read access rights to disk partition

      • mt4setup.exe (PID: 688)
      • terminal.exe (PID: 1300)
    • Reads internet explorer settings

      • mt4setup.exe (PID: 688)
    • Creates a directory in Program Files

      • mt4setup.exe (PID: 688)
      • terminal.exe (PID: 1300)
    • Executable content was dropped or overwritten

      • mt4setup.exe (PID: 688)
    • Drops a file with a compile date too recent

      • mt4setup.exe (PID: 688)
    • Drops a file with too old compile date

      • mt4setup.exe (PID: 688)
    • Modifies the open verb of a shell class

      • terminal.exe (PID: 1300)
    • Drops a file that was compiled in debug mode

      • mt4setup.exe (PID: 688)
    • Changes IE settings (feature browser emulation)

      • terminal.exe (PID: 1300)
    • Creates a software uninstall entry

      • mt4setup.exe (PID: 688)
    • Reads the cookies of Mozilla Firefox

      • terminal.exe (PID: 3508)
    • Executed via COM

      • explorer.exe (PID: 256)
    • Creates files in the program directory

      • mt4setup.exe (PID: 688)
    • Reads the cookies of Google Chrome

      • terminal.exe (PID: 3508)
    • Application launched itself

      • mt4setup.exe (PID: 2172)
    • Adds / modifies Windows certificates

      • mt4setup.exe (PID: 688)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2584)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 856)
      • mt4setup.exe (PID: 688)
      • iexplore.exe (PID: 2268)
      • iexplore.exe (PID: 2584)
      • terminal.exe (PID: 3508)
    • Changes settings of System certificates

      • iexplore.exe (PID: 856)
    • Changes internet zones settings

      • iexplore.exe (PID: 2584)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2268)
      • iexplore.exe (PID: 856)
    • Creates files in the user directory

      • iexplore.exe (PID: 856)
      • iexplore.exe (PID: 2268)
      • iexplore.exe (PID: 2584)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 856)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 2268)
      • terminal.exe (PID: 3508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1970:01:14 15:15:28+01:00
PEType: PE32
LinkerVersion: 14.28
CodeSize: 1015808
InitializedDataSize: 163840
UninitializedDataSize: 2306048
EntryPoint: 0x32b200
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.2693
ProductVersionNumber: 5.0.0.2693
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: https://www.metaquotes.net
CompanyName: MetaQuotes Software Corp.
FileDescription: Setup
FileVersion: 5.0.0.2693
InternalName: Setup
LegalCopyright: © 2000-2020, MetaQuotes Software Corp.
LegalTrademarks: MetaTrader
OriginalFileName: Setup
ProductName: Setup
ProductVersion: 5.0.0.2693
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mt4setup.exe no specs mt4setup.exe iexplore.exe iexplore.exe iexplore.exe terminal.exe explorer.exe no specs explorer.exe no specs terminal.exe metaeditor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
256C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
688"C:\Users\admin\AppData\Local\Temp\mt4setup.exe" C:\Users\admin\AppData\Local\Temp\mt4setup.exe
mt4setup.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
HIGH
Description:
Setup
Exit code:
1
Version:
5.0.0.2693
Modules
Images
c:\users\admin\appdata\local\temp\mt4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
856"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2584 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1300"C:\Program Files\MetaTrader\terminal.exe" /installC:\Program Files\MetaTrader\terminal.exe
mt4setup.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
HIGH
Description:
MetaTrader 5 Client Terminal
Exit code:
0
Version:
5.0.0.2361
Modules
Images
c:\program files\metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2172"C:\Users\admin\AppData\Local\Temp\mt4setup.exe" C:\Users\admin\AppData\Local\Temp\mt4setup.exeexplorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
5.0.0.2693
Modules
Images
c:\users\admin\appdata\local\temp\mt4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2268"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2584 CREDAT:1127433 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2584"C:\Program Files\Internet Explorer\iexplore.exe" https://content.mql5.com/go?v=1&link=https%3A//www.mql5.com/en/auth_register&id=ykuizkyahdaqpjsdhdpvmsmoqpfaqjhdcb&a=ccgidfqshcoacujujprnhtfkqctiqgnc&s=fa340bacde3ca2bbaab1856a37465d0a3823b161d1ae476a2ecd3c7b1ba349a1&uid=woehsideklzedcjtuunsulpsdqdnvxao&scr_res=1280x720&ref=install.metatrader5.com&ac=160620696028186&utm_codepage=1033&utm_uniq=5188572453715588992&utm_link=C47020742EC89D79A373F18D94D38C10&ref=install.metatrader5.comC:\Program Files\Internet Explorer\iexplore.exe
mt4setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3012"C:\Windows\explorer.exe" "C:\Program Files\MetaTrader\terminal.exe"C:\Windows\explorer.exemt4setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3508"C:\Program Files\MetaTrader\terminal.exe" C:\Program Files\MetaTrader\terminal.exe
explorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaTrader 5 Client Terminal
Exit code:
0
Version:
5.0.0.2361
Modules
Images
c:\program files\metatrader\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3608"C:\Program Files\MetaTrader\metaeditor.exe" /compile:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /time:0 /flg:0 /stop:se2376_1365843C:\Program Files\MetaTrader\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Exit code:
0
Version:
5.0.0.2361
Modules
Images
c:\program files\metatrader\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dbghelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
2 729
Read events
2 428
Write events
300
Delete events
1

Modification events

(PID) Process:(2172) mt4setup.exeKey:HKEY_CURRENT_USER\Software\MetaQuotes Software
Operation:writeName:ID
Value:
5188572453715588992
(PID) Process:(2172) mt4setup.exeKey:HKEY_CURRENT_USER\Software\MetaQuotes Software
Operation:writeName:Install.Time
Value:
1606206957
(PID) Process:(2172) mt4setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2172) mt4setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(688) mt4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\MetaQuotes Software
Operation:writeName:ID
Value:
5188572453715588992
(PID) Process:(688) mt4setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(688) mt4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Operation:writeName:Blob
Value:
0400000001000000100000008CCADC0B22CEF5BE72AC411A11A8D8120F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B817E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703010B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748506200000001000000200000008D722F81A9C113C0791DF136A2966DB26C950A971DB46B4199F4EA54B78BFB9F53000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070303190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
(PID) Process:(688) mt4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Operation:writeName:Blob
Value:
04000000010000001000000087CE0B7B2A0E4900E158719B37A893720F00000001000000140000006DCA5BD00DCF1C0F327059D374B29CA6E3C50AA60300000001000000140000000563B8630D62D75ABBC8AB1E4BDFB5A899B24D431D00000001000000100000004F5F106930398D09107B40C3C7CA8F1C0B000000010000001200000044006900670069004300650072007400000014000000010000001400000045EBA2AFF492CB82312D518BA7A7219DF36DC80F6200000001000000200000003E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308190000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000BB030000308203B73082029FA00302010202100CE7E0E517D846FE8FE560FC1BF03039300D06092A864886F70D01010505003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3036313131303030303030305A170D3331313131303030303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AD0E15CEE443805CB187F3B760F97112A5AEDC269488AAF4CEF520392858600CF880DAA9159532613CB5B128848A8ADC9F0A0C83177A8F90AC8AE779535C31842AF60F98323676CCDEDD3CA8A2EF6AFB21F25261DF9F20D71FE2B1D9FE1864D2125B5FF9581835BC47CDA136F96B7FD4B0383EC11BC38C33D9D82F18FE280FB3A783D6C36E44C061359616FE599C8B766DD7F1A24B0D2BFF0B72DA9E60D08E9035C678558720A1CFE56D0AC8497C3198336C22E987D0325AA2BA138211ED39179D993A72A1E6FAA4D9D5173175AE857D22AE3F014686F62879C8B1DAE45717C47E1C0EB0B492A656B3BDB297EDAAA7F0B7C5A83F9516D0FFA196EB085F18774F0203010001A3633061300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041445EBA2AFF492CB82312D518BA7A7219DF36DC80F301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010505000382010100A20EBCDFE2EDF0E372737A6494BFF77266D832E4427562AE87EBF2D5D9DE56B39FCCCE1428B90D97605C124C58E4D33D834945589735691AA847EA56C679AB12D8678184DF7F093C94E6B8262C20BD3DB32889F75FFF22E297841FE965EF87E0DFC16749B35DEBB2092AEB26ED78BE7D3F2BF3B726356D5F8901B6495B9F01059BAB3D25C1CCB67FC2F16F86C6FA6468EB812D94EB42B7FA8C1EDD62F1BE5067B76CBDF3F11F6B0C3607167F377CA95B6D7AF112466083D72704BE4BCE97BEC3672A6811DF80E70C3366BF130D146EF37F1F63101EFA8D1B256D6C8FA5B76101B1D2A326A110719DADE2C3F9C39951B72B0708CE2EE650B2A7FA0A452FA2F0F2
(PID) Process:(688) mt4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0
Operation:writeName:Blob
Value:
040000000100000010000000FA68BCD9B57FADFDC91D068328CC24C10F00000001000000300000000B043572C899DEC43EFD590CFCE610CF443A6315925EBFE589F7506907E44824608489581C7CA0E041458514CF157614030000000100000014000000D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF01D0000000100000010000000280CF6042C30A2646644BA7286A3AA971400000001000000140000003AE10986D4CF19C29676744976DCE035C663639A0B00000001000000180000005300650063007400690067006F00200045004300430000006200000001000000200000004FF460D54B9C86DABFBCFC5712E0400D2BED3FBC4D4FBDAA86E06ADCD2A9AD7A53000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030719000000010000001000000076935B5C5A037216DAAF8AAC76DF42C12000000001000000930200003082028F30820215A00302010202105C8B99C55A94C5D27156DECD8980CC26300A06082A8648CE3D040303308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F726974793076301006072A8648CE3D020106052B81040022036200041AAC545AA9F96823E77AD5246F53C65AD84BABC6D5B6D1E67371AEDD9CD60C61FDDBA08903B80514EC57CEEE5D3FE221B3CEF7D48A79E0A3837E2D97D061C4F199DC259163AB7F30A3B470E2C7A1339CF3BF2E5C53B15FB37D327F8A34E37979A3423040301D0603551D0E041604143AE10986D4CF19C29676744976DCE035C663639A300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300A06082A8648CE3D040303036800306502303667A11608DCE49700411D4EBEE16301CF3BAA421164A09D94390211795C7B1DFA64B9EE1642B3BF8AC209C4ECE4B14D023100E92A61478C524A4B4E1870F6D644D66EF583BA6D58BD24D95648EAEFC4A24681886A3A46D1A99B4DC961DAD15D576A18
(PID) Process:(688) mt4setup.exeKey:HKEY_CURRENT_USER\Software\MetaQuotes Software
Operation:writeName:AP.Time
Value:
1606206963
Executable files
2
Suspicious files
171
Text files
849
Unknown types
30

Dropped files

PID
Process
Filename
Type
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4BAD.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar4BAE.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\TBJRT1DC.txt
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\6E8UP5MY.txt
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4EEB.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4EED.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4EEE.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar4EEC.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4EF1.tmp
MD5:
SHA256:
856iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar4EEF.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
79
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2268
iexplore.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
whitelisted
856
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
US
der
315 b
whitelisted
856
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEFD9JNA2QaMtHNTAv5vIOzE%3D
US
der
278 b
whitelisted
856
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEFD9JNA2QaMtHNTAv5vIOzE%3D
US
der
278 b
whitelisted
856
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
US
der
315 b
whitelisted
856
iexplore.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.5 Kb
whitelisted
856
iexplore.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.5 Kb
whitelisted
2584
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
856
iexplore.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.5 Kb
whitelisted
856
iexplore.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.5 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
688
mt4setup.exe
116.202.51.42:443
content.mql5.com
334,Udyog Vihar
IN
unknown
688
mt4setup.exe
206.221.189.58:443
Choopa, LLC
US
unknown
688
mt4setup.exe
52.184.28.1:443
Microsoft Corporation
HK
unknown
688
mt4setup.exe
64.120.89.44:443
Nobis Technology Group, LLC
US
unknown
688
mt4setup.exe
156.38.206.18:443
HETZNER
ZA
suspicious
688
mt4setup.exe
47.91.110.137:443
Alibaba (China) Technology Co., Ltd.
US
unknown
688
mt4setup.exe
177.154.156.125:443
EQUINIX BRASIL SP
BR
suspicious
688
mt4setup.exe
88.212.244.84:443
Servers.com, Inc.
RU
unknown
688
mt4setup.exe
139.99.68.28:443
api10.mql5.net
OVH SAS
SG
unknown
688
mt4setup.exe
138.201.201.91:443
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
content.mql5.com
  • 116.202.51.42
  • 78.140.180.86
suspicious
api9.mql5.net
  • 0.0.0.0
suspicious
api1.mql5.net
  • 78.140.180.43
suspicious
ocsp.usertrust.com
  • 151.139.128.14
whitelisted
ocsp.sectigo.com
  • 151.139.128.14
whitelisted
www.mql5.com
  • 78.140.180.100
suspicious
c.mql5.com
  • 78.140.180.54
suspicious
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted

Threats

No threats detected
No debug info