URL:

https://download.expressvpn.xyz/clients/windows/expressvpn_6.7.1.5059.exe

Full analysis: https://app.any.run/tasks/035dee85-2e81-4eb9-8d52-eced2e896253
Verdict: Malicious activity
Analysis date: July 09, 2020, 18:19:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E5AE83362424F0E8B3795D31D1E5DC7F

SHA1:

3B7812BEF7960D602760A86BF4A66A9E2DD997EC

SHA256:

266770F2728D5C93FE4A7DD631C09F65A7A45CFEA88F68177B5CDFDBE921CD2F

SSDEEP:

3:N8SElYXzMmDL/AVgfO5w:2SKYXzMmDL/AV47

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • expressvpn_6.7.1.5059.exe (PID: 3720)
      • rundll32.exe (PID: 2552)
      • rundll32.exe (PID: 1324)
      • rundll32.exe (PID: 2316)
      • rundll32.exe (PID: 2332)
      • xvpnd.exe (PID: 744)
      • XvUtil.exe (PID: 4044)
      • ExpressVPN.exe (PID: 2496)
      • rundll32.exe (PID: 2076)
      • ExpressVPN.exe (PID: 2924)
      • XvUtil.exe (PID: 4036)
      • XvUtil.exe (PID: 1984)
    • Application was dropped or rewritten from another process

      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
      • expressvpn_6.7.1.5059.exe (PID: 3720)
      • expressvpn_6.7.1.5059.exe (PID: 1960)
      • tapinstall.exe (PID: 1908)
      • PsSilent.exe (PID: 2812)
      • xvpnd.exe (PID: 744)
      • XvUtil.exe (PID: 4044)
      • nssm.exe (PID: 3492)
      • ExpressVPN.exe (PID: 2496)
      • ExpressVPN.exe (PID: 2924)
      • XvUtil.exe (PID: 4036)
      • XvUtil.exe (PID: 1984)
    • Changes the autorun value in the registry

      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
    • Changes settings of System certificates

      • msiexec.exe (PID: 3044)
      • tapinstall.exe (PID: 1908)
    • Starts NET.EXE for service management

      • xvpnd.exe (PID: 744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2244)
      • expressvpn_6.7.1.5059.exe (PID: 1960)
      • chrome.exe (PID: 4012)
      • expressvpn_6.7.1.5059.exe (PID: 3720)
      • msiexec.exe (PID: 3044)
      • tapinstall.exe (PID: 1908)
      • DrvInst.exe (PID: 3228)
      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
      • DrvInst.exe (PID: 628)
      • rundll32.exe (PID: 2316)
      • rundll32.exe (PID: 1324)
      • rundll32.exe (PID: 2076)
    • Searches for installed software

      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
    • Creates a software uninstall entry

      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
    • Executed via COM

      • DrvInst.exe (PID: 3228)
      • DrvInst.exe (PID: 628)
    • Creates files in the program directory

      • ExpressVPN_6.7.1.5059.exe (PID: 2680)
      • rundll32.exe (PID: 2332)
      • rundll32.exe (PID: 1324)
      • rundll32.exe (PID: 2316)
    • Starts itself from another location

      • expressvpn_6.7.1.5059.exe (PID: 3720)
    • Executed as Windows Service

      • vssvc.exe (PID: 2296)
      • nssm.exe (PID: 3492)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 3228)
      • MsiExec.exe (PID: 2208)
      • MsiExec.exe (PID: 2592)
    • Creates files in the Windows directory

      • rundll32.exe (PID: 756)
      • DrvInst.exe (PID: 3228)
      • DrvInst.exe (PID: 628)
    • Removes files from Windows directory

      • rundll32.exe (PID: 756)
      • DrvInst.exe (PID: 3228)
      • DrvInst.exe (PID: 628)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 628)
      • DrvInst.exe (PID: 3228)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 3044)
      • tapinstall.exe (PID: 1908)
    • Starts SC.EXE for service management

      • xvpnd.exe (PID: 744)
    • Uses NETSH.EXE for network configuration

      • XvUtil.exe (PID: 4044)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 3044)
    • Creates files in the user directory

      • ExpressVPN.exe (PID: 2496)
      • ExpressVPN.exe (PID: 2924)
    • Reads Environment values

      • ExpressVPN.exe (PID: 2924)
      • ExpressVPN.exe (PID: 2496)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 4012)
      • chrome.exe (PID: 2244)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2244)
    • Application launched itself

      • chrome.exe (PID: 2244)
      • msiexec.exe (PID: 3044)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3044)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2296)
    • Creates files in the program directory

      • msiexec.exe (PID: 3044)
    • Searches for installed software

      • DrvInst.exe (PID: 3228)
    • Reads settings of System Certificates

      • tapinstall.exe (PID: 1908)
      • ExpressVPN.exe (PID: 2496)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2592)
      • MsiExec.exe (PID: 2208)
    • Manual execution by user

      • ExpressVPN.exe (PID: 2924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
41
Malicious processes
22
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
276C:\Windows\system32\net1 start expressvpnsplittunnelC:\Windows\system32\net1.exenet.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
628DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem4.inf" "oemvista.inf:tap0901:tap0901.ndi:9.0.0.21:tap0901" "6d14a44ff" "000005C4" "000005DC" "000005E4"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
744"C:\Program Files\ExpressVPN\xvpnd\xvpnd.exe" --workdir "C:\ProgramData\ExpressVPN\v4\\" --client-version 6.7.1 --client-build 6.7.1.5059 --quiet startC:\Program Files\ExpressVPN\xvpnd\xvpnd.exenssm.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\expressvpn\xvpnd\xvpnd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\expressvpn\xvpnd\libxvclient.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
756rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{7e695791-afa1-1563-f7ca-d9728464066c} Global\{7d68193d-a78d-094f-a9e2-8c420ab0ad14} C:\Windows\System32\DriverStore\Temp\{29ef2d0d-84f8-5a46-5a7b-9c72a1af6315}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{29ef2d0d-84f8-5a46-5a7b-9c72a1af6315}\tap0901.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1200"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,14901292015664511089,18125353695355588538,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=16280490894971409691 --mojo-platform-channel-handle=1172 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1324rundll32.exe "C:\Windows\Installer\MSI3E2D.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1523375 14 ExpressVpn.Client.Setup.CustomActions!ExpressVpn.Client.Setup.CustomActions.CustomActions.CreateChromeExtensionJSONC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1696"netsh" int ip set interface 18 metric=6C:\Windows\system32\netsh.exeXvUtil.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1908"C:\Program Files\ExpressVpn OpenVpn Driver\tapinstall\x86\tapinstall.exe" install "C:\Program Files\ExpressVpn OpenVpn Driver\driver\i386\OemVista.inf" tap0901C:\Program Files\ExpressVpn OpenVpn Driver\tapinstall\x86\tapinstall.exe
PsSilent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 (win7_wdk.100208-1538)
Modules
Images
c:\program files\expressvpn openvpn driver\tapinstall\x86\tapinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1920"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2288 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1960"C:\Users\admin\Downloads\expressvpn_6.7.1.5059.exe" C:\Users\admin\Downloads\expressvpn_6.7.1.5059.exe
chrome.exe
User:
admin
Company:
ExpressVPN
Integrity Level:
MEDIUM
Description:
ExpressVPN
Exit code:
0
Version:
6.7.1.5059
Modules
Images
c:\users\admin\downloads\expressvpn_6.7.1.5059.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 732
Read events
2 839
Write events
2 813
Delete events
80

Modification events

(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1920) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2244-13238792381147125
Value:
259
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2244) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3120-13213713943555664
Value:
0
(PID) Process:(2244) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
106
Suspicious files
54
Text files
443
Unknown types
18

Dropped files

PID
Process
Filename
Type
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5F075FBD-8C4.pma
MD5:
SHA256:
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\f2711bd5-fdc4-4f49-9ea3-5874063df53c.tmp
MD5:
SHA256:
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF15cb87.TMPtext
MD5:A9C81BA506E2A0D898698EAF075EBE5C
SHA256:92FB2125FB5A0B877B76C4E3409B250EFF394804C7F24E236FBE162E1054AF90
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.oldtext
MD5:A9C81BA506E2A0D898698EAF075EBE5C
SHA256:92FB2125FB5A0B877B76C4E3409B250EFF394804C7F24E236FBE162E1054AF90
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.oldtext
MD5:1A9E529CE649AE2E02CAF0C4A7A7486E
SHA256:7AC2E8E32F1478CA41F9B9BDE1E2AC1CE7C4FB5DAD1AEDF81B20EBCE5492A7FF
2724chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pmabinary
MD5:B59113C2DCD2D346F31A64F231162ADA
SHA256:1D97C69AEA85D3B06787458EA47576B192CE5C5DB9940E5EAA514FF977CE2DC2
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF15cafa.TMPtext
MD5:33B05E8AC9C178C58ED3321F496588C0
SHA256:2CDF6A09638A0B563EA2672D6926210771902E0A9203FE15D2857FC4EB954CDE
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2244chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF15ccbf.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
18
DNS requests
9
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4012
chrome.exe
216.58.205.227:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
4012
chrome.exe
216.58.208.36:443
www.google.com
Google Inc.
US
whitelisted
4012
chrome.exe
99.86.1.66:443
download.expressvpn.xyz
AT&T Services, Inc.
US
malicious
4012
chrome.exe
172.217.16.173:443
accounts.google.com
Google Inc.
US
whitelisted
4012
chrome.exe
216.58.207.67:443
ssl.gstatic.com
Google Inc.
US
whitelisted
4012
chrome.exe
99.86.1.119:443
download.expressvpn.xyz
AT&T Services, Inc.
US
unknown
4012
chrome.exe
172.217.23.131:443
www.gstatic.com
Google Inc.
US
whitelisted
4012
chrome.exe
172.217.23.174:443
sb-ssl.google.com
Google Inc.
US
whitelisted
4012
chrome.exe
172.217.18.174:443
clients1.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 216.58.205.227
whitelisted
download.expressvpn.xyz
  • 99.86.1.66
  • 99.86.1.119
  • 99.86.1.42
  • 99.86.1.13
whitelisted
accounts.google.com
  • 172.217.16.173
shared
www.google.com
  • 216.58.208.36
malicious
ssl.gstatic.com
  • 216.58.207.67
whitelisted
sb-ssl.google.com
  • 172.217.23.174
whitelisted
www.gstatic.com
  • 172.217.23.131
whitelisted
clients1.google.com
  • 172.217.18.174
whitelisted

Threats

No threats detected
No debug info