File name:

EndpointBasecamp (4).exe

Full analysis: https://app.any.run/tasks/47a7851b-ddae-4d2f-b9d5-ad4612094671
Verdict: Malicious activity
Analysis date: January 18, 2024, 14:47:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

2BBB0B9282989DBE447F6AE7B73BD092

SHA1:

E1B08D9EC3DD11BCFF3BC70DF0E43309E368E5AA

SHA256:

348E3B0E0FB454E840DFF7395DDD07BF461A1DFA70C32B3FFA12B9D04C1D39C9

SSDEEP:

98304:auHwdMBKHiEUEnByICOyjYUt9e41pD2GFrk22Crno+WnSOMHZGOWfUzkdy/U:C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • EndpointBasecamp (4).exe (PID: 2408)
      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • WSCommunicator.exe (PID: 2468)
  • SUSPICIOUS

    • The process verifies whether the antivirus software is installed

      • EndpointBasecamp (4).exe (PID: 2408)
      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • EndpointBasecamp.exe (PID: 1784)
      • EndpointBasecamp.exe (PID: 1560)
      • WSCommunicator.exe (PID: 2468)
      • WSCommunicator.exe (PID: 1528)
      • EndpointBasecamp.exe (PID: 2808)
      • CETASvc.exe (PID: 1636)
    • Reads settings of System Certificates

      • EndpointBasecamp (4).exe (PID: 2408)
    • Reads the Internet Settings

      • EndpointBasecamp (4).exe (PID: 2408)
    • Executes as Windows Service

      • EndpointBasecamp.exe (PID: 784)
      • CETASvc.exe (PID: 1636)
      • WSCommunicator.exe (PID: 1528)
    • Executable content was dropped or overwritten

      • EndpointBasecamp (4).exe (PID: 2408)
      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • WSCommunicator.exe (PID: 2468)
    • Adds/modifies Windows certificates

      • EndpointBasecamp (4).exe (PID: 2408)
    • Checks Windows Trust Settings

      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • EndpointBasecamp.exe (PID: 1784)
      • CETASvc.exe (PID: 1636)
      • EndpointBasecamp.exe (PID: 1560)
      • WSCommunicator.exe (PID: 2468)
      • WSCommunicator.exe (PID: 1528)
      • EndpointBasecamp.exe (PID: 2808)
  • INFO

    • Checks supported languages

      • EndpointBasecamp (4).exe (PID: 2408)
      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • EndpointBasecamp.exe (PID: 1784)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • CETASvc.exe (PID: 1636)
      • EndpointBasecamp.exe (PID: 1560)
      • WSCommunicator.exe (PID: 2468)
      • WSCommunicator.exe (PID: 1528)
      • EndpointBasecamp.exe (PID: 2808)
    • Creates files in the program directory

      • EndpointBasecamp (4).exe (PID: 2408)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • SupportConnector.exe (PID: 1236)
      • CETASvc.exe (PID: 1636)
      • WSCommunicator.exe (PID: 2468)
    • Reads the computer name

      • EndpointBasecamp (4).exe (PID: 2408)
      • EndpointBasecamp.exe (PID: 784)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • EndpointBasecamp.exe (PID: 1784)
      • CETASvc.exe (PID: 1636)
      • EndpointBasecamp.exe (PID: 1560)
      • WSCommunicator.exe (PID: 1528)
      • EndpointBasecamp.exe (PID: 2808)
      • WSCommunicator.exe (PID: 2468)
    • Reads the machine GUID from the registry

      • EndpointBasecamp.exe (PID: 784)
      • EndpointBasecamp (4).exe (PID: 2408)
      • SupportConnector.exe (PID: 1236)
      • TelemetryAgentServiceWebInstaller.exe (PID: 696)
      • EndpointBasecamp.exe (PID: 1784)
      • CETASvc.exe (PID: 1636)
      • EndpointBasecamp.exe (PID: 1560)
      • WSCommunicator.exe (PID: 2468)
      • WSCommunicator.exe (PID: 1528)
      • EndpointBasecamp.exe (PID: 2808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:02 10:51:01+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2985472
InitializedDataSize: 936448
UninitializedDataSize: -
EntryPoint: 0x254812
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.1.0.3970
ProductVersionNumber: 1.1.0.3970
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Trend Micro Endpoint Basecamp
FileVersion: 1.1.0.3970
ProductVersion: 1.1
ProductName: Trend Micro Endpoint Basecamp
CompanyName: Trend Micro Inc.
LegalCopyright: Copyright (C) 2023 Trend Micro Incorporated. All rights reserved.
LegalTrademarks: Copyright (C) Trend Micro Inc.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start endpointbasecamp (4).exe endpointbasecamp.exe supportconnector.exe telemetryagentservicewebinstaller.exe endpointbasecamp.exe no specs cetasvc.exe no specs endpointbasecamp.exe no specs wscommunicator.exe wscommunicator.exe endpointbasecamp.exe no specs endpointbasecamp (4).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Windows\temp\D1DHYWGjbne\mxDnSVbjmRz\TelemetryAgentServiceWebInstaller.exe" --install --env prod --region us1 --install-path "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta" --log-path "C:\Program Files\Trend Micro\Endpoint Basecamp\log"C:\Windows\Temp\D1DHYWGjbne\mxDnSVbjmRz\TelemetryAgentServiceWebInstaller.exe
EndpointBasecamp.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Cloud Endpoint Telemetry Service Web Installer
Exit code:
0
Version:
1.1.0.1120
Modules
Images
c:\windows\temp\d1dhywgjbne\mxdnsvbjmrz\telemetryagentservicewebinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
784"C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\EndpointBasecamp.exe" /serviceC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe
services.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1236"C:\Windows\temp\LY5idYpfjSU\j2yXKE8ztw4\SupportConnector.exe" /xbc_install hgff9q.manage.trendmicro.com ea4e1b13-11da-48c2-a2c1-de5aea692cf8C:\Windows\Temp\LY5idYpfjSU\j2yXKE8ztw4\SupportConnector.exe
EndpointBasecamp.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Support Connector
Exit code:
0
Version:
14.0.0.9379
Modules
Images
c:\windows\temp\ly5idypfjsu\j2yxke8ztw4\supportconnector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
1528"C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\modules\\wsc\\WSCommunicator.exe" /serviceC:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc\WSCommunicator.exe
services.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Facilitates communication between endpoints and Trend Micro web servers
Exit code:
0
Version:
1.1.0.3590
Modules
Images
c:\program files\trend micro\endpoint basecamp\modules\wsc\wscommunicator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1560"C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk g0piblEfZrYO9YSO3gCbC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeCETASvc.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1636"C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exe" --service --env="prod" --region="us1" --log-path="C:\Program Files\Trend Micro\Endpoint Basecamp\log"C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exeservices.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Telemetry Agent Service
Exit code:
0
Version:
1.1.0.1120
Modules
Images
c:\program files\trend micro\endpoint basecamp\modules\ceta\cetasvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1784"C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk PVzd3GYbO6HJsl5XdWNJC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeTelemetryAgentServiceWebInstaller.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2044"C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (4).exe" C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (4).exeexplorer.exe
User:
admin
Company:
Trend Micro Inc.
Integrity Level:
MEDIUM
Description:
Trend Micro Endpoint Basecamp
Exit code:
3221226540
Version:
1.1.0.3970
Modules
Images
c:\users\admin\appdata\local\temp\endpointbasecamp (4).exe
c:\windows\system32\ntdll.dll
2408"C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (4).exe" C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (4).exe
explorer.exe
User:
admin
Company:
Trend Micro Inc.
Integrity Level:
HIGH
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\users\admin\appdata\local\temp\endpointbasecamp (4).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2468"C:\Windows\temp\zSU3otFZP2W\aYJYcLApUvu\WSCommunicator.exe" /install "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc"C:\Windows\Temp\zSU3otFZP2W\aYJYcLApUvu\WSCommunicator.exe
EndpointBasecamp.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Facilitates communication between endpoints and Trend Micro web servers
Exit code:
4294967295
Version:
1.1.0.3590
Modules
Images
c:\windows\temp\zsu3otfzp2w\ayjyclapuvu\wscommunicator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
45 828
Read events
45 671
Write events
157
Delete events
0

Modification events

(PID) Process:(2408) EndpointBasecamp (4).exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2408) EndpointBasecamp (4).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
7E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703072000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(2408) EndpointBasecamp (4).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:device_id
Value:
7dde2b9b-e8b3-4fa1-8d70-b42fc93728d2
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys
Operation:writeName:proxy_username
Value:
DER+xA==
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys
Operation:writeName:proxy_password
Value:
c1Hg4Q==
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:sg_proxy_source
Value:
0
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:gcs_source
Value:
0
(PID) Process:(784) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:gcs_allow_fallback
Value:
1
Executable files
11
Suspicious files
7
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408EndpointBasecamp (4).exeC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeexecutable
MD5:2BBB0B9282989DBE447F6AE7B73BD092
SHA256:348E3B0E0FB454E840DFF7395DDD07BF461A1DFA70C32B3FFA12B9D04C1D39C9
784EndpointBasecamp.exeC:\Windows\temp\D1DHYWGjbne\uGfOWJOPYqW.zipcompressed
MD5:7D495E7B1829EF5E231A83C9C2F22781
SHA256:1D4DEE1F5F8CF9446DC4DDE3FD5581D9D06D13BED80524B0CB58F2E096BDF902
2408EndpointBasecamp (4).exeC:\Program Files\Trend Micro\Endpoint Basecamp\log\EndpointBasecamp.logtext
MD5:735202C596652026F55AA6D4E8AEC4CA
SHA256:BC461DA3167FEFDFEFA9C2A843E4F9518FA8AD72D1BAFA95FA52A53A16EFDE69
784EndpointBasecamp.exeC:\Windows\Temp\zSU3otFZP2W\aYJYcLApUvu\WSCommunicator.exeexecutable
MD5:97B91FF671D7B5E8B8D1DFF9B2BA9F5D
SHA256:0D38AE62A521F541A1DE07601A424E9DDAF6E4D64A1CBA2F3167E50A7C111BD7
696TelemetryAgentServiceWebInstaller.exeC:\Windows\Temp\D1DHYWGjbne\mxDnSVbjmRz\CETASvc.zipcompressed
MD5:917FDA9CAEEE2FE9B84248A72C19BC82
SHA256:A456E34721ACA7772D31F707F13CB22902B74FF40156D5BBAFBD2721B094FD0F
696TelemetryAgentServiceWebInstaller.exeC:\Windows\Temp\D1DHYWGjbne\mxDnSVbjmRz\Telemetry Agent\CETASvc.exeexecutable
MD5:6B7BC6D69732719E31C6D798BC453F2D
SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D
1236SupportConnector.exeC:\Windows\Tasks\Trend Micro Apex One Security Services Support Connector.jobbinary
MD5:E0A418ADCDFA062E67A8F91A81B620B9
SHA256:F006D6CEB6C5B0B888D6C2FA4F8F8E8F31C2998ADE3D9CA2FDCFD4F4C81FCDBC
696TelemetryAgentServiceWebInstaller.exeC:\Windows\Temp\D1DHYWGjbne\mxDnSVbjmRz\Telemetry Agent\dllXbcSdk.dllexecutable
MD5:3DFB22ED3A8F325762BFE5C4D5E8E5AF
SHA256:7B6733744E775AE89802F2C78548CE45C7F165B6F28B1D4145A67F00B77C7790
696TelemetryAgentServiceWebInstaller.exeC:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\dllXbcSdk.dllexecutable
MD5:3DFB22ED3A8F325762BFE5C4D5E8E5AF
SHA256:7B6733744E775AE89802F2C78548CE45C7F165B6F28B1D4145A67F00B77C7790
696TelemetryAgentServiceWebInstaller.exeC:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exeexecutable
MD5:6B7BC6D69732719E31C6D798BC453F2D
SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
18
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2408
EndpointBasecamp (4).exe
52.44.26.109:443
api-us1.xbc.trendmicro.com
AMAZON-AES
US
unknown
784
EndpointBasecamp.exe
52.44.26.109:443
api-us1.xbc.trendmicro.com
AMAZON-AES
US
unknown
784
EndpointBasecamp.exe
99.84.88.96:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown
784
EndpointBasecamp.exe
13.107.246.67:443
supportconnectorpacks.manage.trendmicro.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1236
SupportConnector.exe
104.43.140.101:443
support-connector-service.manage.trendmicro.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
696
TelemetryAgentServiceWebInstaller.exe
99.84.88.24:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown
784
EndpointBasecamp.exe
99.84.88.24:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
api-us1.xbc.trendmicro.com
  • 52.44.26.109
  • 52.73.7.70
  • 52.2.135.226
  • 52.72.212.192
  • 52.71.96.108
  • 52.5.49.0
  • 54.157.75.226
  • 52.7.162.122
unknown
release-us1.mgcp.trendmicro.com
  • 99.84.88.96
  • 99.84.88.73
  • 99.84.88.94
  • 99.84.88.24
unknown
supportconnectorpacks.manage.trendmicro.com
  • 13.107.246.67
  • 13.107.213.67
unknown
support-connector-service.manage.trendmicro.com
  • 104.43.140.101
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info