URL:

https://skrinshoter.ru

Full analysis: https://app.any.run/tasks/6d0568ba-07a6-43e1-99cb-d483c985df2f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: August 06, 2021, 17:08:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
phishing
loader
Indicators:
MD5:

86223507B5D25D75AF6E6AB048E3BB47

SHA1:

A815A950B4B68A066395E244E1C0D1C961766E5E

SHA256:

1B51567425C865B6176577AF5442C114F20F4C6310C12400DD66F0065F86E5C8

SSDEEP:

3:N8D6KbbA:2GKb8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • LauncherSRF.exe (PID: 3404)
      • LauncherSRF.exe (PID: 2668)
      • skrinshoter.exe (PID: 3668)
      • downloader.exe (PID: 3884)
      • skrinshoter.exe (PID: 2796)
      • curl.exe (PID: 908)
      • curl.exe (PID: 2456)
      • curl.exe (PID: 696)
      • downloader.exe (PID: 3496)
      • YandexPackSetup.exe (PID: 3776)
      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
      • YandexPackSetup.exe (PID: 3704)
      • downloader.exe (PID: 2740)
      • downloader.exe (PID: 2068)
      • lite_installer.exe (PID: 1040)
      • sender.exe (PID: 3016)
      • Yandex.exe (PID: 3596)
      • seederexe.exe (PID: 3000)
      • MBlauncher.exe (PID: 772)
      • BrowserManager.exe (PID: 2452)
      • u2-ctrl.exe (PID: 3264)
      • u2-ctrl.exe (PID: 2712)
      • yupdate-exec.exe (PID: 1900)
      • YandexPackSetup.exe (PID: 2280)
      • yupdate-exec.exe (PID: 4044)
      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • curl.exe (PID: 668)
      • curl.exe (PID: 3968)
      • curl.exe (PID: 3704)
      • curl.exe (PID: 2632)
      • curl.exe (PID: 1420)
      • curl.exe (PID: 4036)
      • curl.exe (PID: 3304)
      • curl.exe (PID: 2208)
      • curl.exe (PID: 2180)
      • curl.exe (PID: 2328)
      • iexplore.exe (PID: 3232)
    • Drops executable file immediately after starts

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • MsiExec.exe (PID: 2008)
      • Yandex.exe (PID: 3596)
      • YandexPackSetup.exe (PID: 3704)
      • YandexPackSetup.exe (PID: 2280)
    • Loads dropped or rewritten executable

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • skrinshoter.exe (PID: 2796)
      • MBlauncher.exe (PID: 772)
      • BrowserManager.exe (PID: 2452)
      • YandexPackSetup.exe (PID: 2280)
    • Changes the autorun value in the registry

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • YandexPackSetup.exe (PID: 2280)
      • BrowserManager.exe (PID: 2452)
    • Changes settings of System certificates

      • msiexec.exe (PID: 928)
    • Actions looks like stealing of personal data

      • seederexe.exe (PID: 3000)
      • lite_installer.exe (PID: 1040)
      • BrowserManager.exe (PID: 2452)
    • Steals credentials from Web Browsers

      • seederexe.exe (PID: 3000)
      • BrowserManager.exe (PID: 2452)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • skrinshoter.exe (PID: 2796)
      • iexplore.exe (PID: 3232)
    • Executed via COM

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2868)
      • u2-ctrl.exe (PID: 2712)
    • Reads the computer name

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2868)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • LauncherSRF.exe (PID: 3404)
      • downloader.exe (PID: 3884)
      • skrinshoter.exe (PID: 2796)
      • curl.exe (PID: 908)
      • curl.exe (PID: 2456)
      • curl.exe (PID: 696)
      • YandexPackSetup.exe (PID: 3776)
      • lite_installer.exe (PID: 1040)
      • seederexe.exe (PID: 3000)
      • downloader.exe (PID: 2740)
      • downloader.exe (PID: 3496)
      • Yandex.exe (PID: 3596)
      • sender.exe (PID: 3016)
      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
      • YandexPackSetup.exe (PID: 2280)
      • MBlauncher.exe (PID: 772)
      • u2-ctrl.exe (PID: 3264)
      • downloader.exe (PID: 2068)
      • BrowserManager.exe (PID: 2452)
      • u2-ctrl.exe (PID: 2712)
      • yupdate-exec.exe (PID: 1900)
      • yupdate-exec.exe (PID: 4044)
      • curl.exe (PID: 668)
      • curl.exe (PID: 3968)
      • curl.exe (PID: 3704)
      • curl.exe (PID: 2632)
      • curl.exe (PID: 1420)
      • curl.exe (PID: 4036)
      • curl.exe (PID: 3304)
      • curl.exe (PID: 2208)
      • curl.exe (PID: 2180)
      • curl.exe (PID: 2328)
    • Checks supported languages

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2868)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • LauncherSRF.exe (PID: 3404)
      • LauncherSRF.exe (PID: 2668)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • downloader.exe (PID: 3884)
      • curl.exe (PID: 908)
      • skrinshoter.exe (PID: 2796)
      • curl.exe (PID: 2456)
      • curl.exe (PID: 696)
      • downloader.exe (PID: 3496)
      • YandexPackSetup.exe (PID: 3776)
      • lite_installer.exe (PID: 1040)
      • seederexe.exe (PID: 3000)
      • downloader.exe (PID: 2740)
      • Yandex.exe (PID: 3596)
      • sender.exe (PID: 3016)
      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
      • YandexPackSetup.exe (PID: 3704)
      • downloader.exe (PID: 2068)
      • YandexPackSetup.exe (PID: 2280)
      • u2-ctrl.exe (PID: 3264)
      • MBlauncher.exe (PID: 772)
      • BrowserManager.exe (PID: 2452)
      • u2-ctrl.exe (PID: 2712)
      • yupdate-exec.exe (PID: 1900)
      • yupdate-exec.exe (PID: 4044)
      • curl.exe (PID: 668)
      • curl.exe (PID: 3968)
      • curl.exe (PID: 3704)
      • curl.exe (PID: 2632)
      • curl.exe (PID: 3304)
      • curl.exe (PID: 4036)
      • curl.exe (PID: 2208)
      • curl.exe (PID: 2180)
      • curl.exe (PID: 2328)
      • curl.exe (PID: 1420)
    • Creates files in the user directory

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2868)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • MsiExec.exe (PID: 2008)
      • seederexe.exe (PID: 3000)
      • Yandex.exe (PID: 3596)
      • msiexec.exe (PID: 928)
      • BrowserManager.exe (PID: 2452)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 3568)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • downloader.exe (PID: 3884)
      • MsiExec.exe (PID: 2008)
      • msiexec.exe (PID: 928)
      • Yandex.exe (PID: 3596)
      • lite_installer.exe (PID: 1040)
      • downloader.exe (PID: 2740)
      • YandexPackSetup.exe (PID: 3704)
      • YandexPackSetup.exe (PID: 2280)
      • BrowserManager.exe (PID: 2452)
    • Drops a file that was compiled in debug mode

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • downloader.exe (PID: 3884)
      • msiexec.exe (PID: 928)
      • MsiExec.exe (PID: 2008)
      • downloader.exe (PID: 2740)
      • lite_installer.exe (PID: 1040)
      • Yandex.exe (PID: 3596)
      • YandexPackSetup.exe (PID: 3704)
      • YandexPackSetup.exe (PID: 2280)
      • BrowserManager.exe (PID: 2452)
    • Application launched itself

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 3264)
      • downloader.exe (PID: 3884)
      • msiexec.exe (PID: 928)
      • downloader.exe (PID: 2740)
    • Creates files in the Windows directory

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
    • Creates a directory in Program Files

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
    • Creates files in the program directory

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • skrinshoter.exe (PID: 2796)
    • Drops a file with too old compile date

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
    • Drops a file with a compile date too recent

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • lite_installer.exe (PID: 1040)
    • Creates a software uninstall entry

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
      • Yandex.exe (PID: 3596)
      • YandexPackSetup.exe (PID: 2280)
      • msiexec.exe (PID: 928)
    • Changes default file association

      • SkrinshoterSetup_v3.10.2.12.exe (PID: 4072)
    • Reads internet explorer settings

      • skrinshoter.exe (PID: 2796)
    • Executed as Windows Service

      • msiexec.exe (PID: 928)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 928)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 928)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 928)
    • Reads Environment values

      • MsiExec.exe (PID: 2008)
      • MsiExec.exe (PID: 3056)
      • BrowserManager.exe (PID: 2452)
    • Searches for installed software

      • seederexe.exe (PID: 3000)
      • YandexPackSetup.exe (PID: 2280)
    • Changes the started page of IE

      • seederexe.exe (PID: 3000)
    • Reads default file associations for system extensions

      • Yandex.exe (PID: 3596)
    • Reads the date of Windows installation

      • Yandex.exe (PID: 3596)
    • Uses TASKKILL.EXE to kill process

      • MsiExec.exe (PID: 3056)
    • Reads the cookies of Google Chrome

      • BrowserManager.exe (PID: 2452)
    • Reads the cookies of Mozilla Firefox

      • BrowserManager.exe (PID: 2452)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • msiexec.exe (PID: 928)
      • MsiExec.exe (PID: 2008)
      • MsiExec.exe (PID: 3056)
      • taskkill.exe (PID: 3272)
      • taskkill.exe (PID: 2712)
      • taskkill.exe (PID: 2968)
      • taskkill.exe (PID: 3332)
      • iexplore.exe (PID: 3232)
    • Checks supported languages

      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • msiexec.exe (PID: 928)
      • MsiExec.exe (PID: 2008)
      • MsiExec.exe (PID: 3056)
      • taskkill.exe (PID: 2968)
      • taskkill.exe (PID: 3332)
      • taskkill.exe (PID: 3272)
      • taskkill.exe (PID: 2712)
      • iexplore.exe (PID: 3232)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 2976)
      • downloader.exe (PID: 3884)
      • msiexec.exe (PID: 928)
      • lite_installer.exe (PID: 1040)
      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
      • downloader.exe (PID: 2740)
      • BrowserManager.exe (PID: 2452)
      • iexplore.exe (PID: 3232)
    • Changes internet zones settings

      • iexplore.exe (PID: 3568)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 2976)
      • downloader.exe (PID: 3884)
      • msiexec.exe (PID: 928)
      • lite_installer.exe (PID: 1040)
      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
      • downloader.exe (PID: 2740)
      • BrowserManager.exe (PID: 2452)
      • iexplore.exe (PID: 3232)
    • Application launched itself

      • iexplore.exe (PID: 3568)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • iexplore.exe (PID: 3232)
    • Reads CPU info

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
    • Creates files in the user directory

      • iexplore.exe (PID: 2988)
      • iexplore.exe (PID: 2976)
      • iexplore.exe (PID: 3568)
      • iexplore.exe (PID: 3232)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3568)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3568)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3568)
    • Manual execution by user

      • {CDEE1DDA-B9F9-4E66-929E-D0A60144500F}.exe (PID: 2084)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 928)
      • BrowserManager.exe (PID: 2452)
    • Reads the hosts file

      • BrowserManager.exe (PID: 2452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
113
Monitored processes
49
Malicious processes
20
Suspicious processes
15

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe flashutil32_32_0_0_453_activex.exe no specs skrinshotersetup_v3.10.2.12.exe launchersrf.exe no specs skrinshotersetup_v3.10.2.12.exe launchersrf.exe no specs skrinshoter.exe no specs skrinshoter.exe downloader.exe iexplore.exe curl.exe curl.exe curl.exe yandexpacksetup.exe downloader.exe msiexec.exe msiexec.exe lite_installer.exe seederexe.exe downloader.exe yandex.exe sender.exe {cdee1dda-b9f9-4e66-929e-d0a60144500f}.exe yandexpacksetup.exe downloader.exe yandexpacksetup.exe msiexec.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs u2-ctrl.exe no specs mblauncher.exe no specs browsermanager.exe u2-ctrl.exe no specs yupdate-exec.exe no specs yupdate-exec.exe no specs curl.exe curl.exe curl.exe curl.exe curl.exe curl.exe curl.exe curl.exe curl.exe curl.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
668-s -S -A SkrinshoterWin/3.10.2.12 --insecure -d "v=1&t=event&tid=UA-17620704-15&cid=A57393D5-EBB8-4C38-A006-4028E0923D1C&ec=Settings&ea=Open Tab Pro&an=SkrinshoterWin&av=3.10.2.12" -X POST https://www.google-analytics.com/collect -w"%{http_code}"C:\Program Files\Skrinshoter\curl.exe
skrinshoter.exe
User:
admin
Company:
curl, https://curl.haxx.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.68.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\skrinshoter\curl.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
696-s -S -A SkrinshoterWin/3.10.2.12 --insecure -d "v=1&t=event&tid=UA-17620704-15&cid=A57393D5-EBB8-4C38-A006-4028E0923D1C&ec=Settings&ea=WriteJsonFileOk-2&an=SkrinshoterWin&av=3.10.2.12" -X POST https://www.google-analytics.com/collect -w"%{http_code}"C:\Program Files\Skrinshoter\curl.exe
skrinshoter.exe
User:
admin
Company:
curl, https://curl.haxx.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.68.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\skrinshoter\curl.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
772"C:\Users\admin\AppData\Local\Yandex\BrowserManager\MBlauncher.exe" /firstrunC:\Users\admin\AppData\Local\Yandex\BrowserManager\MBlauncher.exemsiexec.exe
User:
admin
Company:
Yandex LLC
Integrity Level:
MEDIUM
Description:
Launcher ??? ????????? ?????????
Exit code:
0
Version:
3.0.5.827
Modules
Images
c:\users\admin\appdata\local\yandex\browsermanager\mblauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
908-s -S -A SkrinshoterWin/3.10.2.12 --insecure -d "v=1&t=event&tid=UA-17620704-15&cid=A57393D5-EBB8-4C38-A006-4028E0923D1C&ec=Application&ea=Launch&el=OS[6.1.7601],Up-0, 1 displays[1280x720], Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz, 4 cores, 4 Gb, {gdi}&an=SkrinshoterWin&av=3.10.2.12" -X POST https://www.google-analytics.com/collect -w"%{http_code}"C:\Program Files\Skrinshoter\curl.exe
skrinshoter.exe
User:
admin
Company:
curl, https://curl.haxx.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.68.0
Modules
Images
c:\program files\skrinshoter\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
928C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1040"C:\Users\admin\AppData\Local\Temp\28D12CEE-B8C4-4B4F-94FE-D5C9774BD5D0\lite_installer.exe" --use-user-default-locale --silent --remote-url=http://downloader.yandex.net/downloadable_soft/browser/pseudoportal-ru/Yandex.exe --cumtom-welcome-page=https://browser.yandex.ru/promo/welcome_com/5/ --YABROWSERC:\Users\admin\AppData\Local\Temp\28D12CEE-B8C4-4B4F-94FE-D5C9774BD5D0\lite_installer.exe
MsiExec.exe
User:
admin
Company:
Yandex
Integrity Level:
MEDIUM
Description:
YandexBrowserDownloader
Exit code:
0
Version:
1.0.1.88
Modules
Images
c:\users\admin\appdata\local\temp\28d12cee-b8c4-4b4f-94fe-d5c9774bd5d0\lite_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
1420-s -S -A SkrinshoterWin/3.10.2.12 --insecure -d "v=1&t=event&tid=UA-17620704-15&cid=A57393D5-EBB8-4C38-A006-4028E0923D1C&ec=SelectRegion&ea=Open without Editor&an=SkrinshoterWin&av=3.10.2.12" -X POST https://www.google-analytics.com/collect -w"%{http_code}"C:\Program Files\Skrinshoter\curl.exe
skrinshoter.exe
User:
admin
Company:
curl, https://curl.haxx.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.68.0
Modules
Images
c:\program files\skrinshoter\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
1900C:\Users\admin\AppData\Local\Yandex\Updater2\yupdate-exec.exe --stat-callback 0 --appid bm --job {3ABE1900-B667-43D1-B63F-D31840808283}C:\Users\admin\AppData\Local\Yandex\Updater2\yupdate-exec.exesvchost.exe
User:
admin
Company:
Yandex LLC
Integrity Level:
MEDIUM
Description:
Yandex updater (EU)
Exit code:
0
Version:
1.2.0.1834
Modules
Images
c:\users\admin\appdata\local\yandex\updater2\yupdate-exec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2008C:\Windows\system32\MsiExec.exe -Embedding 52B6FCC1DC272785C73324ED03B220B1C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2068C:\Users\admin\AppData\Local\Temp\6111B9E6-471D-47DA-A46F-9979E0036E07\downloader.exe --stat dwnldr/p=bm-partner-ru/cnt=0/dt=5/ct=0/rt=0 --dh 1448 --st 1628269760C:\Users\admin\AppData\Local\Temp\6111B9E6-471D-47DA-A46F-9979E0036E07\downloader.exe
downloader.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Downloader
Exit code:
0
Version:
0.1.0.32
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\6111b9e6-471d-47da-a46f-9979e0036e07\downloader.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
Total events
74 811
Read events
73 643
Write events
1 126
Delete events
42

Modification events

(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30903013
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30903013
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
106
Suspicious files
121
Text files
322
Unknown types
70

Dropped files

PID
Process
Filename
Type
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\644B8874112055B5E195ECB0E8F243A4binary
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\644B8874112055B5E195ECB0E8F243A4der
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\XD9ERJJ0.htmhtml
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\styles[1].csstext
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\scripts[1].jstext
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:
SHA256:
2988iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
59
TCP/UDP connections
167
DNS requests
64
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCBwXmOUIIn%2FAoAAAAA8rrr
US
der
472 b
whitelisted
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
2988
iexplore.exe
GET
200
2.16.107.89:80
http://crl.identrust.com/DSTROOTCAX3CRL.crl
unknown
der
1.16 Kb
whitelisted
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGq%2BdSta4rCACgAAAADyw3Q%3D
US
der
471 b
whitelisted
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
2988
iexplore.exe
GET
200
2.16.186.232:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDkBUeDDgxkUpdvejVJwN1I
unknown
der
1.54 Kb
whitelisted
2988
iexplore.exe
GET
200
5.45.205.242:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CECosiqdXosrVzE6LrmbYt3c%3D
RU
der
1.48 Kb
whitelisted
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEBtpDEx%2Fx4YJCgAAAADyw4g%3D
US
der
471 b
whitelisted
2988
iexplore.exe
GET
200
2.16.186.232:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
unknown
der
1.50 Kb
whitelisted
2988
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDuuJG5Km9TjgoAAAAA8rro
US
der
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2988
iexplore.exe
23.45.105.185:80
x1.c.lencr.org
Akamai International B.V.
NL
unknown
2988
iexplore.exe
2.16.107.89:80
crl.identrust.com
Akamai International B.V.
suspicious
2988
iexplore.exe
142.250.186.131:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2988
iexplore.exe
142.250.185.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2988
iexplore.exe
142.250.181.238:443
www.google-analytics.com
Google Inc.
US
whitelisted
2988
iexplore.exe
136.243.19.144:443
skrinshoter.ru
Hetzner Online GmbH
DE
suspicious
2988
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2988
iexplore.exe
13.225.81.216:443
thumbs.gfycat.com
US
unknown
2988
iexplore.exe
13.225.84.97:80
o.ss2.us
US
unknown
2988
iexplore.exe
2.16.186.232:80
subca.ocsp-certum.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
skrinshoter.ru
  • 136.243.19.144
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
crl.identrust.com
  • 2.16.107.89
  • 2.16.107.73
whitelisted
x1.c.lencr.org
  • 23.45.105.185
whitelisted
fonts.googleapis.com
  • 142.250.185.106
whitelisted
ocsp.pki.goog
  • 142.250.186.131
whitelisted
www.google-analytics.com
  • 142.250.181.238
  • 142.251.36.174
  • 142.250.186.110
whitelisted
mc.yandex.ru
  • 93.158.134.119
  • 77.88.21.119
  • 87.250.250.119
  • 87.250.251.119
whitelisted
thumbs.gfycat.com
  • 13.225.81.216
whitelisted
fonts.gstatic.com
  • 216.58.212.131
whitelisted

Threats

PID
Process
Class
Message
3884
downloader.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2976
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2796
skrinshoter.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
3568
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
3568
iexplore.exe
Potential Corporate Privacy Violation
ET INFO Lets Encrypt Free SSL Cert Observed with IDN/Punycode Domain - Possible Phishing
2 ETPRO signatures available at the full report
Process
Message
YandexPackSetup.exe
IsAlreadyRun() In
YandexPackSetup.exe
IsAlreadyRun() Out : ret (BOOL) = 0
YandexPackSetup.exe
IsMSISrvFree() In
YandexPackSetup.exe
IsMSISrvFree() : OpenMutex() err ret = 2
YandexPackSetup.exe
IsMSISrvFree() Out ret = 1
YandexPackSetup.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = USER-PC, dwSessionId = 1
YandexPackSetup.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = USER-PC, dwSessionId = 0
YandexPackSetup.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
YandexPackSetup.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1302019708-1500728564-335382590-1000
YandexPackSetup.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = USER-PC, dwSessionId = 1