| URL: | http://download.aweray.com/awesun/windows/AweSun_1.5.0.30116.exe |
| Full analysis: | https://app.any.run/tasks/ac7423bb-2ef9-479b-82a9-20c84211aeae |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | August 18, 2020, 06:15:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | FB5935FA0466519216515232E4F43A49 |
| SHA1: | 671328D452B4B6046FCF372D13BFC94D715CD07A |
| SHA256: | 27C229F1DAAF0F8B9A0A245AD6A97A5ED02798AB57DB47D9802F1A3AD0673456 |
| SSDEEP: | 3:N1KaKEl+EwVBKIQ77AC:Ca5iBKf |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 848 | "C:\Program Files\Aweray\AweSun\AweSun.exe" --mod=service | C:\Program Files\Aweray\AweSun\AweSun.exe | services.exe | ||||||||||||
User: SYSTEM Company: AweRay Limited Integrity Level: SYSTEM Description: AweSun Exit code: 0 Version: 1.5.0.30116 Modules
| |||||||||||||||
| 1344 | cmd /c netsh advfirewall firewall add rule name="AweSun" dir=in action=allow program="C:\Program Files\Aweray\AweSun\AweSun.exe" protocol=udp enable=yes profile=public | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1424 | netsh advfirewall firewall delete rule name="AweSun" | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1496 | "C:\Program Files\Aweray\AweSun\AweSun.exe" --mod=watch --pid=848 | C:\Program Files\Aweray\AweSun\AweSun.exe | AweSun.exe | ||||||||||||
User: SYSTEM Company: AweRay Limited Integrity Level: SYSTEM Description: AweSun Exit code: 0 Version: 1.5.0.30116 Modules
| |||||||||||||||
| 1708 | cmd /c netsh advfirewall firewall add rule name="AweSun" dir=in action=allow program="C:\Program Files\Aweray\AweSun\AweSun.exe" protocol=tcp enable=yes profile=private | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2288 | netsh advfirewall firewall add rule name="AweSun" dir=in action=allow program="C:\Program Files\Aweray\AweSun\AweSun.exe" protocol=tcp enable=yes profile=domain | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2292 | C:\Windows\system32\cmd.exe /c ver | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2300 | netsh advfirewall firewall add rule name="AweSun" dir=in action=allow program="C:\Program Files\Aweray\AweSun\AweSun.exe" protocol=udp enable=yes profile=public | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2324 | cmd /c netsh advfirewall firewall add rule name="AweSun" dir=in action=allow program="C:\Program Files\Aweray\AweSun\AweSun.exe" protocol=udp enable=yes profile=domain | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2380 | "C:\Windows\System32\cmd.exe" cmd.exe /c TASKKILL /PID 0 /PID 0 /F | C:\Windows\System32\cmd.exe | — | AweSun_1.5.0.30116.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 316624844 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30831911 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2664) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2532 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\AweSun_1.5.0.30116[1].exe | — | |
MD5:— | SHA256:— | |||
| 2664 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF304DD26BE72160E0.TMP | — | |
MD5:— | SHA256:— | |||
| 2664 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AweSun_1.5.0.30116.exe.282zger.partial:Zone.Identifier | — | |
MD5:— | SHA256:— | |||
| 2664 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AweSun_1.5.0.30116.exe:Zone.Identifier | — | |
MD5:— | SHA256:— | |||
| 2940 | AweSun_1.5.0.30116.exe | C:\Program Files\Aweray\AweSun\SunloginClient_Test.zip | — | |
MD5:— | SHA256:— | |||
| 2940 | AweSun_1.5.0.30116.exe | C:\ProgramData\AweSun\sensors\distinct | binary | |
MD5:— | SHA256:— | |||
| 2664 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{3E9BEA8D-E11A-11EA-BF40-12A9866C77DE}.dat | binary | |
MD5:— | SHA256:— | |||
| 2940 | AweSun_1.5.0.30116.exe | C:\Program Files\Aweray\AweSun\AweSun.exe | executable | |
MD5:9D6843B934B83FD41911F1FC354B796E | SHA256:013EB8326BD27ED1AF680F15600EA4E6FC4061F012F88E0FDE344326A89C2DE8 | |||
| 2664 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AweSun_1.5.0.30116.exe | executable | |
MD5:9D6843B934B83FD41911F1FC354B796E | SHA256:013EB8326BD27ED1AF680F15600EA4E6FC4061F012F88E0FDE344326A89C2DE8 | |||
| 2940 | AweSun_1.5.0.30116.exe | C:\Program Files\Aweray\AweSun\driver\DpmsMonitor\oraydpmsx86.cat | cat | |
MD5:A6F9DFFA6DC0257349DE76355A22D87E | SHA256:8A4504DBCBEB53421314A6F4E15C1994CEFE0C8FC881EB5A2C9D70A3596E5817 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
2532 | iexplore.exe | GET | 200 | 13.35.254.51:80 | http://download.aweray.com/awesun/windows/AweSun_1.5.0.30116.exe | US | executable | 7.14 Mb | malicious |
2664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2532 | iexplore.exe | 13.35.254.51:80 | download.aweray.com | — | US | suspicious |
2940 | AweSun_1.5.0.30116.exe | 216.58.212.142:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
2940 | AweSun_1.5.0.30116.exe | 34.85.64.198:443 | asapi.aweray.net | — | US | suspicious |
848 | AweSun.exe | 34.85.64.198:443 | asapi.aweray.net | — | US | suspicious |
2460 | AweSun.exe | 35.230.49.123:443 | client-api.aweray.com | — | US | suspicious |
848 | AweSun.exe | 34.90.103.244:443 | asapi-eu.aweray.net | — | US | unknown |
848 | AweSun.exe | 34.90.137.31:443 | as01-eu-std.aweray.com | — | US | unknown |
2664 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2664 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.aweray.com |
| malicious |
www.google-analytics.com |
| whitelisted |
sl-tk.aweray.com |
| unknown |
asapi.aweray.net |
| suspicious |
client-api.aweray.com |
| suspicious |
asapi-eu.aweray.net |
| unknown |
as01-eu-std.aweray.com |
| unknown |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2532 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:52.730 = Debug = [monitor]PRIMARY, left=0, top=0
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:53.855 = Debug = [monitor]PRIMARY, left=0, top=0
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.001 - Info - [mac] local ip:192.168.100.164
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.001 = Debug = get_default_interface_ip ok with 192.168.100.164
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.002 - Info - [mac] mac address:12:A9:86:6C:77:DE
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.003 - Info - [http call3] new call id:1, url:https://asapi.aweray.net/feedback/install
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.004 - Info - [http call3] id:1 create new connection : https://asapi.aweray.net:443
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.004 - Info - [async dns] start resolve dns asapi.aweray.net
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.017 - Info - attempt to connect server asapi.aweray.net:443(34.85.64.198:443)
|
AweSun_1.5.0.30116.exe | 2020-08-18 07:15:57.112 - Info - [Install] Create new you write info
|