| File name: | MobiOffice_Setup.exe |
| Full analysis: | https://app.any.run/tasks/42480ddc-cda8-4e6f-8996-106742f43d2d |
| Verdict: | Malicious activity |
| Analysis date: | November 19, 2024, 10:14:08 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | 36D6B3F4A79580DE3539D835A1D70E29 |
| SHA1: | E8B9357E1CA41A805DFAD58AE2D33534463F34C2 |
| SHA256: | 3743CB04F7E6F121F266ED25EB9194B8924E8BBB99B36FE67329C9D212F1B807 |
| SSDEEP: | 49152:1YFMWBhdGWc9vYdWGmynfJStlJRmNNXbU6wbMmkq4sjB1xnBgHk5a4aut+a4ANqz:Cy6GWcNYdWGmcctOw6bmkH01ZCRR7aYz |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2073:12:23 07:58:23+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 1570304 |
| InitializedDataSize: | 155136 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x18149e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.10.8510.1 |
| ProductVersionNumber: | 10.10.58510.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | MobiSystems Inc. |
| FileDescription: | MobiOffice |
| FileVersion: | 10.10.8510.1 |
| InternalName: | MobiOffice_Setup.exe |
| LegalCopyright: | © 2015-2024 MobiSystems Inc. All rights reserved. |
| OriginalFileName: | MobiOffice_Setup.exe |
| ProductName: | MobiOffice |
| ProductVersion: | 10.10.58510.0+c60e948e942b5124dc36350cad57b0ead2433d03 |
| AssemblyVersion: | 10.10.8510.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1992 | "C:\Program Files\WindowsApps\MobiSystems.MobiInstaller_1.1.58510.0_x64__bvgb55c3tfatp\MobiInstaller\MobiInstaller.exe" mobisystems-appcenter-protocol:--bootstrap_launch_type=1 --bootstrap_tracking_id=605286cc-4039-431f-a8f8-d1377d963bd8 | C:\Program Files\WindowsApps\MobiSystems.MobiInstaller_1.1.58510.0_x64__bvgb55c3tfatp\MobiInstaller\MobiInstaller.exe | MobiOffice_Setup.exe | ||||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: Version: 10.10.8510.1 Modules
| |||||||||||||||
| 2628 | C:\WINDOWS\splwow64.exe 8192 | C:\Windows\splwow64.exe | — | MobiDocs.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Print driver host for applications Version: 10.0.19041.3636 (WinBuild.160101.0800) | |||||||||||||||
| 4128 | C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4444 | "C:\Users\admin\MobiOffice_Setup.exe" | C:\Users\admin\MobiOffice_Setup.exe | explorer.exe | ||||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: MobiOffice Exit code: 0 Version: 10.10.8510.1 Modules
| |||||||||||||||
| 6216 | "C:\Program Files\WindowsApps\MobiSystems.MobiOffice_10.10.58510.0_x64__bvgb55c3tfatp\MobiOffice\MobiOffice.ServiceHost.exe" mobioffice-servicehost-protocol: | C:\Program Files\WindowsApps\MobiSystems.MobiOffice_10.10.58510.0_x64__bvgb55c3tfatp\MobiOffice\MobiOffice.ServiceHost.exe | — | MobiInstaller.exe | |||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: Version: 10.10.8510.1 | |||||||||||||||
| 6244 | "C:\Program Files\WindowsApps\MobiSystems.MobiOffice.MobiDocs_10.10.58510.0_x64__bvgb55c3tfatp\Documents\MobiDocs.exe" mobidocs-protocol: | C:\Program Files\WindowsApps\MobiSystems.MobiOffice.MobiDocs_10.10.58510.0_x64__bvgb55c3tfatp\Documents\MobiDocs.exe | — | MobiInstaller.exe | |||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: MobiOffice MobiDocs Version: 10.10.8510.1 | |||||||||||||||
| 6644 | "C:\Program Files\WindowsApps\MobiSystems.MobiInstaller_1.1.58510.0_x64__bvgb55c3tfatp\MobiInstaller\MobiInstaller.ServiceHost.exe" appcenter-servicehost-protocol: | C:\Program Files\WindowsApps\MobiSystems.MobiInstaller_1.1.58510.0_x64__bvgb55c3tfatp\MobiInstaller\MobiInstaller.ServiceHost.exe | MobiInstaller.exe | ||||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: Version: 10.10.8510.1 Modules
| |||||||||||||||
| 6648 | "C:\Program Files\WindowsApps\MobiSystems.MobiOffice_10.10.58510.0_x64__bvgb55c3tfatp\MobiOffice\MobiOffice.Notifier.exe" mobioffice-notifier-protocol: | C:\Program Files\WindowsApps\MobiSystems.MobiOffice_10.10.58510.0_x64__bvgb55c3tfatp\MobiOffice\MobiOffice.Notifier.exe | — | MobiOffice.ServiceHost.exe | |||||||||||
User: admin Company: MobiSystems Inc. Integrity Level: MEDIUM Description: Version: 10.10.8510.1 | |||||||||||||||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (4444) MobiOffice_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MobiOffice_Setup_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4444 | MobiOffice_Setup.exe | C:\Users\admin\.mobisystems\logs\MobiSystems.AppCenter.Bootstrapper\2024-11-19_10-14-19.log | text | |
MD5:B4B8B74838445E739B740304717591E2 | SHA256:AB235898C0D829B9ACE55291FA1FD10FE4C8C4A7AFD62072B4C512E923CAE799 | |||
| 1992 | MobiInstaller.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiInstaller_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\AppCenter\SessionId.txt | text | |
MD5:F086FACCA07F729F922E961135C79110 | SHA256:16A366F68C9412901B6BEB47D19BF642F665EABD1F4F881232D56E46267795AD | |||
| 4444 | MobiOffice_Setup.exe | C:\Users\admin\.mobisystems\device-id | binary | |
MD5:4EFFE62108BD88BCE88F1EB9BFFA489E | SHA256:2F6BE03610419E119D1E50EB922620350381BAFD1CE5EF87290427D20D1FA410 | |||
| 6244 | MobiDocs.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\documents-settings.dat-journal | binary | |
MD5:050B7573D93D68741ABE64C2B3917839 | SHA256:6A321A19BDFDE49CD79FE6F4C643F2E205A90EB133FF8F26EBD08FB633382E8E | |||
| 6244 | MobiDocs.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\shared-settings.dat | sqlite | |
MD5:A8E75ACC11904CB877E15A0D0DE03941 | SHA256:D78C40FEBE1BA7EC83660B78E3F6AB7BC45AB822B8F21B03B16B9CB4F3B3A259 | |||
| 6648 | MobiOffice.Notifier.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\Logs\log_2024.11.19.10.18.51.9295_MobiOffice.Notifier_pid6648.txt | text | |
MD5:FBF472AE6B603D07187EF7B2DE710EB6 | SHA256:F941C353C658BA275A2C8FCABD87A1FD0D675B09B6B3EF733887B50099A9AB79 | |||
| 6648 | MobiOffice.Notifier.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\Logs\service-host.log.txt | text | |
MD5:ACDC06D29D2C947E333803E60EE29746 | SHA256:6A3652CEA2E3647E5765944A870C5B9ABD1103E7BD021E99A008F600566C8D27 | |||
| 6648 | MobiOffice.Notifier.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\Logs\package-updater-service.log.txt | text | |
MD5:CA70D1B2E6547E58C31889A22208F9A3 | SHA256:A7B8D785FB707AE811353272914A7BA3DF9A0CAD048762719A009F4E2DFBB953 | |||
| 6648 | MobiOffice.Notifier.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\shared-settings.dat-shm | binary | |
MD5:AA4A739A3F8CD48DE8647608E8F263F3 | SHA256:8CE98A15005650DC2621830F4BF0C652701CEBA86BC9B0EF438D35A86F645F13 | |||
| 6648 | MobiOffice.Notifier.exe | C:\Users\admin\AppData\Local\Packages\MobiSystems.MobiOffice_bvgb55c3tfatp\LocalCache\Local\MobiSystemsSideLoading\MobiOffice\Logs\windows-10-package-shortcuts-polyfill-service.log.txt | text | |
MD5:2B3754A99A6964DC78AE2491A82CEB82 | SHA256:525C467470E47A070BAC050D4C08F9795C3110A0BFEE54901673F43D321C37A2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6720 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3884 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEA%2B4p0C5FY0DUUO8WdnwQCk%3D | unknown | — | — | whitelisted |
968 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3884 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSE67Nbq3jfQQg8yXEpbmqLTNn7XwQUm1%2BwNrqdBq4ZJ73AoCLAi4s4d%2B0CEAfG54THoNIGfCYXCstrJHY%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 172.217.18.19:80 | http://checkout.mobisystems.com/api/prices?inAppIds=mobistore.mobidocs-premium.win.yearly.29.88.notrial,mobistore.mobioffice-premium.win.yearly.91.42.7d.trial,mobistore.mobioffice-multiuser.win.yearly.59.88.notrial&app=com.mobisystems.windows.appx.mobioffice&version=10.10.58510.0&decodeCurrencySign=1&additionalInfo=1®ion=US®ionalFormat=en-US | unknown | — | — | whitelisted |
6720 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2876 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.16.110.177:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.52.120.96:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4932 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 216.239.36.178:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
— | — | 172.67.26.143:443 | cfg.mobisystems.com | CLOUDFLARENET | US | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
cfg.mobisystems.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
geo.prod.do.dsp.mp.microsoft.com |
| whitelisted |
sentry.mobisystems.com |
| unknown |
kv801.prod.do.dsp.mp.microsoft.com |
| whitelisted |