| File name: | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe |
| Full analysis: | https://app.any.run/tasks/c9a3f998-e728-425c-acea-6c568ab513e2 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | January 15, 2025, 02:31:22 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 4AC02CA07D0B03751AF4B167B16711C5 |
| SHA1: | 8530CD14C7C177121220FD578B7455E3BC36019E |
| SHA256: | 2B178449B53A5702522F58AEBF3CDCE477B652100EBD6406A3DB229D1341A257 |
| SSDEEP: | 6144:bQWYT+yVvtVUpVHIW7evtGsZLpxyJWFSLteS+WnCEXLyvaCD0Mdu:QT+yVvtV+VHl7+tFLpkU+tN+L0YX05 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:02 03:20:13+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x312a |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.1.7 |
| ProductVersionNumber: | 1.0.1.7 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Teruten |
| FileDescription: | TGService |
| FileVersion: | 1.0.1.7 |
| LegalCopyright: | Teruten. All rights reserved. |
| ProductName: | TGService |
| ProductVersion: | 1.0.1.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6272 | "C:\Users\admin\AppData\Local\Temp\2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe" | C:\Users\admin\AppData\Local\Temp\2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | — | explorer.exe | |||||||||||
User: admin Company: Teruten Integrity Level: MEDIUM Description: TGService Exit code: 3221226540 Version: 1.0.1.7 Modules
| |||||||||||||||
| 6412 | "C:\Users\admin\AppData\Local\Temp\2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe" | C:\Users\admin\AppData\Local\Temp\2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | explorer.exe | ||||||||||||
User: admin Company: Teruten Integrity Level: HIGH Description: TGService Exit code: 0 Version: 1.0.1.7 Modules
| |||||||||||||||
| 6748 | "C:\Program Files (x86)\Teruten\TGService\TGService.exe" | C:\Program Files (x86)\Teruten\TGService\TGService.exe | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | ||||||||||||
User: admin Company: Teruten Integrity Level: HIGH Description: TGService Exit code: 0 Version: 1, 0, 1, 7 Modules
| |||||||||||||||
| 6780 | C:\WINDOWS\SysWOW64\TGService.exe | C:\Windows\SysWOW64\TGService.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Teruten Integrity Level: SYSTEM Description: TGService Version: 1, 0, 1, 7 Modules
| |||||||||||||||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server |
| Operation: | write | Name: | DisabledByDefault |
Value: 0 | |||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 |
| Operation: | write | Name: | 1406 |
Value: 0 | |||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome |
| Operation: | write | Name: | InsecurePrivateNetworkRequestsAllowed |
Value: 1 | |||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge |
| Operation: | write | Name: | InsecurePrivateNetworkRequestsAllowed |
Value: 1 | |||
| (PID) Process: | (6748) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | C6FA1C665820C0E2467A134648038B13743F738F |
Value: | |||
| (PID) Process: | (6748) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\C6FA1C665820C0E2467A134648038B13743F738F |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000C6FA1C665820C0E2467A134648038B13743F738F0200000001000000CC0000001C0000006C00000001000000200000000000000000000000010000007B00440033004500450044003300410037002D0041003200440036002D0034004300410032002D0042004200380034002D003400310036003900370036003700390044004400320030007D00000000004D006900630072006F0073006F0066007400200045006E00680061006E006300650064002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E0030000000000020000000010000008D0300003082038930820271A003020102020900E027DADFAFD114DC300D06092A864886F70D01010B05003074310B3009060355040613024B52310E300C06035504080C0553656F756C310E300C06035504070C0553656F756C3110300E060355040A0C075465727574656E3112301006035504030C093132372E302E302E31311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D301E170D3137303432353032343434325A170D3437303431383032343434325A3074310B3009060355040613024B52310E300C06035504080C0553656F756C310E300C06035504070C0553656F756C3110300E060355040A0C075465727574656E3112301006035504030C093132372E302E302E31311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D30820122300D06092A864886F70D01010105000382010F003082010A0282010100E62F089A41DEB9C78F02C004F29CBF208F7E9D0A595B23ABB60A9E50911B26EF9734C1F9FF0884FCE744D61DBFFA478E1CA112ADADA636308122E96E12370BDB69FA48CF8C3BC774081A197293D2EBA89F9122705BC04ED62E32F8B6D28A1B5AFF073A66919A35794641D9DB3DC54E5ECA2951E75EA0A5508B0A6A80D062784324362EF4E0FBC3AE895EBA2BD3410ABA603B08085E0A7FE97624D903486136EFA2841074D09F8F3E4D867CA84AC2004C26EE496DEC8C90FC40A56754451806FE6076D3149C6F0D31FFA5641CAA1ACAF8E00518AD02DCCA1760637AB5C2A9735E21788E5920D87FE66ED3CE4EEBA814815DE63A252C3CC3692E5F0BDAB69692870203010001A31E301C301A0603551D110413301182093132372E302E302E3187047F000001300D06092A864886F70D01010B05000382010100D99EB40CAEF5584D7AC008817F0E6802B192C7D9C3F41EBB55646FD4D50C4ECF129EEC7CC5C0C751506C1CCFB618BA0EEF780BDEAC19EB7005DBB7762EFB0042192F5C17467F3EB2D0003744EC3F07B6128788DA6B0AAC6D5B39BC966A21728CF7619ACC8A1BE3EEEC3723B9D5184FE194F9935030F4CCC07091A36A5DB9FB9A62CD5ED311741AB35EE18391DAEED20CDDB4A961CFBE04A219E0217E374EA3C3F4BB262001C08FA7B03E741CF7F2B19476269E9C4F5BA336044DB9309EFE3C280BC2D7933D3998825EB59A11194D41C5E2E539DF909CA124F42CA89032E1E9932596B59CC2A9BF43A440357A1FDD582C82C6C02E2B01C338A9BE3EC871254444 | |||
| (PID) Process: | (6748) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | EFB5F1A7B75E83154865CE030FD40A4C1C169800 |
Value: | |||
| (PID) Process: | (6748) TGService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\EFB5F1A7B75E83154865CE030FD40A4C1C169800 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000EFB5F1A7B75E83154865CE030FD40A4C1C1698000200000001000000C40000001C000000740000000100000020000000000000000000000002000000500076006B0054006D0070003A00630034003400300038006200340032002D0061006500660036002D0034003800660032002D0038003200380061002D0038006600620064003400320063003300620035003900370000004D006900630072006F0073006F006600740020005300740072006F006E0067002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072000000200000000100000098030000308203943082027CA00302010202106B20130C8089078946A2CCDB07704766300D06092A864886F70D01010D05003047311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D31123010060355040313093132372E302E302E313110300E060355040A13075465727574656E301E170D3137303330383031333434335A170D3339313233313233353935395A3047311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D31123010060355040313093132372E302E302E313110300E060355040A13075465727574656E30820122300D06092A864886F70D01010105000382010F003082010A0282010100BCF70B60E8F04C9F1707C330B5F844294E74AC8304B344A7EF9E4CE2FFAD44900E65FA9BCC0234E8599ECCD22C5D8DEB9B1A74A1EB817D9AA35BAA4DB75CF5031B60911B161C688988B6B5BF7A9E3C2E146BFE78CB38C7F8C97C32FD6F9F11BDAA97261C9760D4F3A70310D7CC25F6F1C442D15C94674230BA595BBC724CC9FD130CA9CB5E550E9444ECB274BC62725F2CCE71DFB0CB0DBF1600B3A57B8988087F1427C38BDBD3DE56B805B5A16BC282EB4AFD5592139A91C5CE544F90921E9E6419271FCC91718C97BFCAB58A34F9F0E915C46E0F8D1E5283F258CCB83DA64FCDC9526BFAE853714B3F90349E3A63BDF4A3A8D1E57E79600B8EDDF5BA5E8C0D0203010001A37C307A30780603551D010471306F80103C97A44981D8F18250B0991A4E9F9570A1493047311F301D06092A864886F70D010901161063756265407465727574656E2E636F6D31123010060355040313093132372E302E302E313110300E060355040A13075465727574656E82106B20130C8089078946A2CCDB07704766300D06092A864886F70D01010D05000382010100028C2FC4C0B7CDEE80A87AA91691698EED8EF81D3DE66C112E76CB3AF5E49CB64F9945581CA9232498E1E0C629F5A391BE5C6D953DAA2142241FA6F525542D87B6AE53C504217CF5B71FA63F57A34D071CCFE7DF71370F54335D94A3F0C61320ED5AFFD629280D44F75BB8CF3D606A90637331FE72F025D0406A19B5B3CF166FCDA33595B44976843E2415D1810636E931B38BCD2573B76F0986746BE6DF5108AE2C87B492B31C9FFFC83F8280FF1842FD02394C8E6F62C4F08DA2D127A62446BD68B537CC466A1C04AA822B293E05744F707B240CF60C742C5AA6AFFDAACE9C6FA668266C292A0850038EEFB2750398C6ADCCBE2394BF4F9AFDDD9086E36071 | |||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TGService |
| Operation: | write | Name: | DisplayName |
Value: TGService 1.0.1.7 | |||
| (PID) Process: | (6412) 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TGService |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files (x86)\Teruten\TGService\uninstall.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6748 | TGService.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert_override.txt | text | |
MD5:2E1AEA9A2EFD2CC7EB73ACDA252B096C | SHA256:B2369F71D5BCCD1A0F09E1597BABDC18E2E4FA9A15EF5FC7286143BA611D4D69 | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Users\admin\AppData\Local\Temp\nsz5690.tmp\LangDLL.dll | executable | |
MD5:E447E49175C0DB1F27888AEDE301084F | SHA256:FD26EF21D72797FEDECD3D15F2001CEA793383ACEB3CEE19A5AE2A3D30E197B6 | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Users\admin\AppData\Local\Temp\nsz5690.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Program Files (x86)\Teruten\TGService\TerutenLocal.p12 | binary | |
MD5:8BC7CB37D2221D80E810654B5EBF5B3D | SHA256:6188EC543932F61D3FF8DCC3EE825AFAAA83BBB0274A3E10CEF683D7332032FB | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Program Files (x86)\Teruten\TGService\uninstall.exe | executable | |
MD5:A62D112B115264F58A300D96A6763A8A | SHA256:E527F1EB72FEA8EC37E05A4E0AA2C5FB52DED59FF5EE266EA2B87050F56A686C | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Program Files (x86)\Teruten\TGService\TerutenLocal_xp.pfx | binary | |
MD5:77E7D15404323CED7D772923B972BE58 | SHA256:6611185EB0B9AE05BA126EE70B65CA0B455F0778A6271922192D1A1B05F5D287 | |||
| 6748 | TGService.exe | C:\Windows\SysWOW64\TGService.exe | executable | |
MD5:601E4D00216FBFCE76A6103745D420AF | SHA256:52A7163907D181EB65F581290E554FC678D32D9134E35C67BC5B66DC03FEF2DE | |||
| 6748 | TGService.exe | C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6fa1d9c1450770fbf788a25c4acff30_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:4D7F2A52DCDD9C8E74FCEC75BF5BA963 | SHA256:3147A148586BE28D9D1D799E46FD9AEECAA27CF57F70744928C15E0C2AAE6B62 | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Program Files (x86)\Teruten\TGService\TGF.exe | executable | |
MD5:A48332D2262E7C9C724B5ABE0D078A45 | SHA256:5F5B2399D48FFBDB04C6952A0AD11320DA138F73C94CC9D5D470FF9157D7041C | |||
| 6412 | 2b178449b53a5702522f58aebf3cdce477b652100ebd6406a3db229d1341a257.exe | C:\Users\admin\AppData\Local\Temp\nsz5690.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1016 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1016 | svchost.exe | GET | 200 | 23.218.209.163:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3840 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
3840 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7000 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1016 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
524 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1016 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1016 | svchost.exe | 23.218.209.163:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.137:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
1176 | svchost.exe | 20.190.160.22:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |