URL:

http://download.endpoint.carbonite.com/download/v6.3.7602/CarboniteUpgrade-pro-client.exe

Full analysis: https://app.any.run/tasks/63ee7e1d-496e-4b73-bbc0-75cf06918125
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 05, 2023, 22:50:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
SHA1:

8F602E802BE960C3044B5783C9764CDA2883AA95

SHA256:

1AA79F4737614D4163E0F785CE88A5EA41D61442C645DB45DEAC9C4CCF0B8E95

SSDEEP:

3:N1KaKElhMlQQunKLqLSTVX94vME2uGBJn:Ca5hMlmK2mv4MuG/n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CarboniteUpgrade-pro-client.exe (PID: 1556)
      • CarboniteUpgrade-pro-client.exe (PID: 3124)
  • SUSPICIOUS

    • Reads the Internet Settings

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Reads Microsoft Outlook installation path

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Reads Internet Explorer settings

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Reads settings of System Certificates

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Adds/modifies Windows certificates

      • iexplore.exe (PID: 1488)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3832)
      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1488)
      • iexplore.exe (PID: 3656)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3832)
      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3832)
      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Application launched itself

      • iexplore.exe (PID: 1488)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1488)
    • Creates files in the program directory

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Create files in a temporary directory

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Checks proxy server information

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Creates files or folders in the user directory

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
    • Process checks are UAC notifies on

      • CarboniteUpgrade-pro-client.exe (PID: 3124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe carboniteupgrade-pro-client.exe no specs carboniteupgrade-pro-client.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1488"C:\Program Files\Internet Explorer\iexplore.exe" "http://download.endpoint.carbonite.com/download/v6.3.7602/CarboniteUpgrade-pro-client.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
1556"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exeiexplore.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
MEDIUM
Description:
Carbonite Setup
Exit code:
3221226540
Version:
6.3.3 build 7602 (Feb-02-2018)
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\carboniteupgrade-pro-client.exe
c:\windows\system32\ntdll.dll
3124"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exe
iexplore.exe
User:
admin
Company:
Carbonite, Inc.
Integrity Level:
HIGH
Description:
Carbonite Setup
Exit code:
0
Version:
6.3.3 build 7602 (Feb-02-2018)
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\carboniteupgrade-pro-client.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
3656"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1488 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3832"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
13 689
Read events
13 597
Write events
87
Delete events
5

Modification events

(PID) Process:(3832) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4FD4C5B5-3ADE-42F3-930E-E46E409B41EE}\{AFD3766B-3A85-400A-8AC7-F6159BBBEBD0}
Operation:delete keyName:(default)
Value:
(PID) Process:(3832) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4FD4C5B5-3ADE-42F3-930E-E46E409B41EE}
Operation:delete keyName:(default)
Value:
(PID) Process:(3832) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{BE032C21-AD49-413C-B1FC-9D07019A5544}
Operation:delete keyName:(default)
Value:
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
3
Suspicious files
30
Text files
843
Unknown types
0

Dropped files

PID
Process
Filename
Type
1488iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFCBAAA9B46715041F.TMPbinary
MD5:7D841B5E7DA40BB88A41A66366EDB1E2
SHA256:359956DF89CC10B4556FCA5A275881A75A58921CBCFAE73D8468BA620564D956
1488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exe.bih8jaq.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3656iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CarboniteUpgrade-pro-client[1].exeexecutable
MD5:3ED08374E28658338671539FCE8AC5FB
SHA256:DDADA126E644A43F62EA47A1F5DA0E8E642B246E6F9BCFD6A17B5384839C31A4
1488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{8A68A4D7-63D1-11EE-B150-12A9866C77DE}.datbinary
MD5:86AC2D093871E69F0ADB4E3490039537
SHA256:A5BB5A44FC6E73486A16960DD529CFBD8EE6CE966A7FB91A0B99678FF27BBE47
1488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\CarboniteUpgrade-pro-client.exeexecutable
MD5:4537EDEED370D3FA9AC1302FC4D5BDCC
SHA256:96D885133B7D26786B617ABC9B87895D9E78A061F12FDD9F176694F11EF287D4
3124CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645\css\kermit\images\ui-bg_glass_50_829a39_1x400.pngimage
MD5:E6C3763CE9D6885C843F50271DE92690
SHA256:CBAD22BAB026FDDF634085B65BCB773F3EE1CF09733AA5B07C429DA47D2B34CB
3124CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645\css\kermit\images\ui-bg_glass_55_fff9d7_1x400.pngimage
MD5:B6FDC0B6F4890F09FBC0F1C7BC96DB21
SHA256:CD6B1E5FBBF2355D6491430C3FFDAC3DB803BE1DFC8A2CD84B8DB5A670DBDF2A
3124CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645\css\kermit\images\ui-bg_flat_95_fef1ec_40x100.pngimage
MD5:952E00271F260843DE98780F181587D4
SHA256:E163E903808496D8CED19C1144D363BAD94DB913A59732A583B5CC077C8D11CC
3124CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645.tmpcompressed
MD5:0EFE92F32D996023E70F640150D15E8C
SHA256:8AD431A9F558D8B95054AD61515550E1B52CF7C9186E9660A4511658E0607C55
3124CarboniteUpgrade-pro-client.exeC:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645\css\kermit\images\ui-bg_flat_75_ffffff_40x100.pngimage
MD5:8692E6EFDDF882ACBFF144C38EA7DFDF
SHA256:39AB7CCD9F4E82579DA78A9241265DF288D8EB65DBBD7CF48AED2D0129887DF5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
16
DNS requests
7
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
iexplore.exe
GET
200
13.32.99.44:80
http://download.endpoint.carbonite.com/download/v6.3.7602/CarboniteUpgrade-pro-client.exe
unknown
executable
16.4 Mb
unknown
1488
iexplore.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?64814aee7afa5553
unknown
compressed
4.66 Kb
unknown
1488
iexplore.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?745e703ce198182f
unknown
compressed
4.66 Kb
unknown
1488
iexplore.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3544c346198c6411
unknown
compressed
4.66 Kb
unknown
3124
CarboniteUpgrade-pro-client.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?edbb2a38b5051301
unknown
compressed
61.6 Kb
unknown
3124
CarboniteUpgrade-pro-client.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5265e199e142ad92
unknown
compressed
61.6 Kb
unknown
1488
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3656
iexplore.exe
13.32.99.44:80
AMAZON-02
US
unknown
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1488
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
1488
iexplore.exe
178.79.242.0:80
ctldl.windowsupdate.com
LLNW
DE
whitelisted
1488
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3124
CarboniteUpgrade-pro-client.exe
76.76.21.142:443
www.carbonite.com
AMAZON-02
US
unknown
3124
CarboniteUpgrade-pro-client.exe
143.204.98.3:443
zna7usvzk4.execute-api.us-east-1.amazonaws.com
AMAZON-02
US
whitelisted
3124
CarboniteUpgrade-pro-client.exe
178.79.242.0:80
ctldl.windowsupdate.com
LLNW
DE
whitelisted

DNS requests

Domain
IP
Reputation
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 178.79.242.0
  • 178.79.242.128
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.carbonite.com
  • 76.76.21.142
  • 76.76.21.98
unknown
zna7usvzk4.execute-api.us-east-1.amazonaws.com
  • 143.204.98.3
  • 143.204.98.115
  • 143.204.98.120
  • 143.204.98.60
unknown
account.carbonite.com
  • 45.60.155.109
unknown

Threats

PID
Process
Class
Message
3656
iexplore.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
3656
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
CarboniteUpgrade-pro-client.exe
LogMsg is not open.
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.74+00:00 E 3996:ERROR: Localizer::Load C:\Users\admin\Desktop\skin\CarboniteSetup.strings(failed open) 3 2023-10-05T23:50:35.74+00:00 E 3996:ERROR: Localizer::String 86 cannot be localized - not found
CarboniteUpgrade-pro-client.exe
LogMsg is not open.
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.74+00:00 > 3996:CarboniteSetup(6.3.3 build 7602 (Feb-02-2018)) 32-bit starting. Command Line:"c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\carboniteupgrade-pro-client.exe"
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.77+00:00 @ [BrowserControl] 3996:carbonite::BrowserControl::SetClientSite(1) Config.SetISM is 1
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.82+00:00 W 3720:Warning: `anonymous-namespace'::GetMaxAutoRetryCount(Could not open reg key: SOFTWARE\Carbonite\CarboniteSetup)
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.82+00:00 # 3720:Unzip: C:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645.tmp to C:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645. Msg=74, Retry=0
CarboniteUpgrade-pro-client.exe
failed to change date on .\ in C:\Users\admin\AppData\Local\Temp\Crb-{7889AB0F-830B-4D97-85F1-E5CC3A8C3F52}\Crb6645 - 3
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.88+00:00 @ 3996:carbonite::CrbInternetSecurityManager::ProcessUrlAction - processing URL res://ieframe.dll/unknownprotocol.htm, action is 9984
CarboniteUpgrade-pro-client.exe
2023-10-05T23:50:35.88+00:00 @ 3996:carbonite::CrbInternetSecurityManager::ProcessUrlAction - processing URL res://ieframe.dll/unknownprotocol.htm, action is 9984