| File name: | 8530cd14c7c177121220fd578b7455e3bc36019e |
| Full analysis: | https://app.any.run/tasks/4e04e3ab-cdac-4370-8bc0-d5ad51921cb7 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | January 07, 2025, 13:56:26 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 4AC02CA07D0B03751AF4B167B16711C5 |
| SHA1: | 8530CD14C7C177121220FD578B7455E3BC36019E |
| SHA256: | 2B178449B53A5702522F58AEBF3CDCE477B652100EBD6406A3DB229D1341A257 |
| SSDEEP: | 6144:bQWYT+yVvtVUpVHIW7evtGsZLpxyJWFSLteS+WnCEXLyvaCD0Mdu:QT+yVvtV+VHl7+tFLpkU+tN+L0YX05 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:02 03:20:13+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x312a |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.1.7 |
| ProductVersionNumber: | 1.0.1.7 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Teruten |
| FileDescription: | TGService |
| FileVersion: | 1.0.1.7 |
| LegalCopyright: | Teruten. All rights reserved. |
| ProductName: | TGService |
| ProductVersion: | 1.0.1.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2136 | "C:\Users\admin\AppData\Local\Temp\8530cd14c7c177121220fd578b7455e3bc36019e.exe" | C:\Users\admin\AppData\Local\Temp\8530cd14c7c177121220fd578b7455e3bc36019e.exe | — | explorer.exe | |||||||||||
User: admin Company: Teruten Integrity Level: MEDIUM Description: TGService Exit code: 3221226540 Version: 1.0.1.7 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\AppData\Local\Temp\8530cd14c7c177121220fd578b7455e3bc36019e.exe" | C:\Users\admin\AppData\Local\Temp\8530cd14c7c177121220fd578b7455e3bc36019e.exe | explorer.exe | ||||||||||||
User: admin Company: Teruten Integrity Level: HIGH Description: TGService Exit code: 0 Version: 1.0.1.7 Modules
| |||||||||||||||
| 6696 | "C:\Program Files (x86)\Teruten\TGService\TGService.exe" | C:\Program Files (x86)\Teruten\TGService\TGService.exe | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | ||||||||||||
User: admin Company: Teruten Integrity Level: HIGH Description: TGService Exit code: 0 Version: 1, 0, 1, 7 Modules
| |||||||||||||||
| 6720 | C:\WINDOWS\SysWOW64\TGService.exe | C:\Windows\SysWOW64\TGService.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Teruten Integrity Level: SYSTEM Description: TGService Version: 1, 0, 1, 7 Modules
| |||||||||||||||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server |
| Operation: | write | Name: | DisabledByDefault |
Value: 0 | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 |
| Operation: | write | Name: | 1406 |
Value: 0 | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome |
| Operation: | write | Name: | InsecurePrivateNetworkRequestsAllowed |
Value: 1 | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge |
| Operation: | write | Name: | InsecurePrivateNetworkRequestsAllowed |
Value: 1 | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TGService |
| Operation: | write | Name: | DisplayName |
Value: TGService 1.0.1.7 | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TGService |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files (x86)\Teruten\TGService\uninstall.exe | |||
| (PID) Process: | (2136) 8530cd14c7c177121220fd578b7455e3bc36019e.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TGService |
| Operation: | write | Name: | DisplayVersion |
Value: 1.0.1.7 | |||
| (PID) Process: | (6696) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | C6FA1C665820C0E2467A134648038B13743F738F |
Value: | |||
| (PID) Process: | (6696) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\C6FA1C665820C0E2467A134648038B13743F738F |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000C6FA1C665820C0E2467A134648038B13743F738F0200000001000000CC0000001C0000006C00000001000000200000000000000000000000010000007B00440037003900320046004300430039002D0046003600350036002D0034003100380030002D0041003300350044002D004300420037003600330035004400430030004500320043007D00000000004D006900630072006F0073006F0066007400200045006E00680061006E006300650064002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E0030000000000020000000010000008D0300003082038930820271A003020102020900E027DADFAFD114DC300D06092A864886F70D01010B05003074310B3009060355040613024B52310E300C06035504080C0553656F756C310E300C06035504070C0553656F756C3110300E060355040A0C075465727574656E3112301006035504030C093132372E302E302E31311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D301E170D3137303432353032343434325A170D3437303431383032343434325A3074310B3009060355040613024B52310E300C06035504080C0553656F756C310E300C06035504070C0553656F756C3110300E060355040A0C075465727574656E3112301006035504030C093132372E302E302E31311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D30820122300D06092A864886F70D01010105000382010F003082010A0282010100E62F089A41DEB9C78F02C004F29CBF208F7E9D0A595B23ABB60A9E50911B26EF9734C1F9FF0884FCE744D61DBFFA478E1CA112ADADA636308122E96E12370BDB69FA48CF8C3BC774081A197293D2EBA89F9122705BC04ED62E32F8B6D28A1B5AFF073A66919A35794641D9DB3DC54E5ECA2951E75EA0A5508B0A6A80D062784324362EF4E0FBC3AE895EBA2BD3410ABA603B08085E0A7FE97624D903486136EFA2841074D09F8F3E4D867CA84AC2004C26EE496DEC8C90FC40A56754451806FE6076D3149C6F0D31FFA5641CAA1ACAF8E00518AD02DCCA1760637AB5C2A9735E21788E5920D87FE66ED3CE4EEBA814815DE63A252C3CC3692E5F0BDAB69692870203010001A31E301C301A0603551D110413301182093132372E302E302E3187047F000001300D06092A864886F70D01010B05000382010100D99EB40CAEF5584D7AC008817F0E6802B192C7D9C3F41EBB55646FD4D50C4ECF129EEC7CC5C0C751506C1CCFB618BA0EEF780BDEAC19EB7005DBB7762EFB0042192F5C17467F3EB2D0003744EC3F07B6128788DA6B0AAC6D5B39BC966A21728CF7619ACC8A1BE3EEEC3723B9D5184FE194F9935030F4CCC07091A36A5DB9FB9A62CD5ED311741AB35EE18391DAEED20CDDB4A961CFBE04A219E0217E374EA3C3F4BB262001C08FA7B03E741CF7F2B19476269E9C4F5BA336044DB9309EFE3C280BC2D7933D3998825EB59A11194D41C5E2E539DF909CA124F42CA89032E1E9932596B59CC2A9BF43A440357A1FDD582C82C6C02E2B01C338A9BE3EC871254444 | |||
| (PID) Process: | (6696) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | EFB5F1A7B75E83154865CE030FD40A4C1C169800 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Users\admin\AppData\Local\Temp\nst549C.tmp\InstallOptions.dll | executable | |
MD5:D753362649AECD60FF434ADF171A4E7F | SHA256:8F24C6CF0B06D18F3C07E7BFCA4E92AFCE71834663746CFAA9DDF52A25D5C586 | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Program Files (x86)\Teruten\TGService\TGF.exe | executable | |
MD5:A48332D2262E7C9C724B5ABE0D078A45 | SHA256:5F5B2399D48FFBDB04C6952A0AD11320DA138F73C94CC9D5D470FF9157D7041C | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Program Files (x86)\Teruten\TGService\uninstall.exe | executable | |
MD5:A62D112B115264F58A300D96A6763A8A | SHA256:E527F1EB72FEA8EC37E05A4E0AA2C5FB52DED59FF5EE266EA2B87050F56A686C | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Program Files (x86)\Teruten\TGService\TerutenLocal.p12 | binary | |
MD5:8BC7CB37D2221D80E810654B5EBF5B3D | SHA256:6188EC543932F61D3FF8DCC3EE825AFAAA83BBB0274A3E10CEF683D7332032FB | |||
| 6696 | TGService.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert_override.txt | text | |
MD5:2E1AEA9A2EFD2CC7EB73ACDA252B096C | SHA256:B2369F71D5BCCD1A0F09E1597BABDC18E2E4FA9A15EF5FC7286143BA611D4D69 | |||
| 6696 | TGService.exe | C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\437ff13825171de2079634c61d982455_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:8B501EC67CC7D7A0557B8A2290B89D00 | SHA256:273284607B99C4C62796C9DC954EA8AE61B8AC832CBA498E2E563A2300BD7537 | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Users\admin\AppData\Local\Temp\nst549C.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Users\admin\AppData\Local\Temp\nst549C.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 2136 | 8530cd14c7c177121220fd578b7455e3bc36019e.exe | C:\Program Files (x86)\Teruten\TGService\TGService.exe | executable | |
MD5:601E4D00216FBFCE76A6103745D420AF | SHA256:52A7163907D181EB65F581290E554FC678D32D9134E35C67BC5B66DC03FEF2DE | |||
| 6696 | TGService.exe | C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c12d183ea663869cc6558f8fe365e7e3_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:710F22A8BB79411F6C1471FB82D54AFB | SHA256:1FD1AF92ADE8870528CE889D56F9F2D4812DE4F319EFC47CA0C97F45263249E7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.230.103:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.24:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
7000 | SIHClient.exe | GET | 200 | 184.30.230.103:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6200 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7000 | SIHClient.exe | GET | 200 | 184.30.230.103:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3700 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 2.16.164.24:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 184.30.230.103:80 | www.microsoft.com | AKAMAI-AS | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.23.227.198:443 | www.bing.com | Ooredoo Q.S.C. | QA | unknown |
1176 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| unknown |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |