| File name: | freeu.exe |
| Full analysis: | https://app.any.run/tasks/1d13e015-a2e5-4b47-a6c4-992200f5dd5d |
| Verdict: | Malicious activity |
| Analysis date: | October 23, 2020, 11:43:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | EFAB586BE5B52A0BC495DB458054AA9B |
| SHA1: | 4B381358B5A34613E67366768E8C8AEA32E5528A |
| SHA256: | 3A2DA22B71BB8CC5923076DE4896F7E38C3DBCB00C3232E105D2FCED1CE63C84 |
| SSDEEP: | 6144:0Dw/7Dl19Dcqguv73GM694so0f6I7AOZY81vBvsIxJ9l:aKX4qguvTGMtMfFo81R79l |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:06:22 17:44:16+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 197120 |
| InitializedDataSize: | 215040 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11221 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.0.9 |
| ProductVersionNumber: | 2.1.0.9 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Dilane Limited |
| FileDescription: | FreeU |
| FileVersion: | 2.1.0.9 |
| InternalName: | FreeU |
| LegalCopyright: | Copyright 2017 |
| OriginalFileName: | FreeU |
| ProductName: | FreeU Browser |
| ProductVersion: | 2.1.0.9 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 22-Jun-2017 15:44:16 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Dilane Limited |
| FileDescription: | FreeU |
| FileVersion: | 2.1.0.9 |
| InternalName: | FreeU |
| LegalCopyright: | Copyright 2017 |
| OriginalFilename: | FreeU |
| ProductName: | FreeU Browser |
| ProductVersion: | 2.1.0.9 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000118 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 7 |
| Time date stamp: | 22-Jun-2017 15:44:16 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00030105 | 0x00030200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64592 |
.rdata | 0x00032000 | 0x0001190A | 0x00011A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.46024 |
.data | 0x00044000 | 0x00002034 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.70322 |
.gfids | 0x00047000 | 0x000001EC | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.77673 |
.tls | 0x00048000 | 0x00000009 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0203931 |
.rsrc | 0x00049000 | 0x0001D810 | 0x0001DA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.34584 |
.reloc | 0x00067000 | 0x00002C98 | 0x00002E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58226 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.07176 | 640 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 2.37221 | 4264 | UNKNOWN | Russian - Russia | RT_ICON |
3 | 2.11873 | 9640 | UNKNOWN | Russian - Russia | RT_ICON |
4 | 1.99748 | 16936 | UNKNOWN | Russian - Russia | RT_ICON |
5 | 1.83294 | 67624 | UNKNOWN | Russian - Russia | RT_ICON |
6 | 7.86823 | 6429 | UNKNOWN | Russian - Russia | RT_ICON |
114 | 6.14555 | 1120 | UNKNOWN | Russian - Russia | PNG |
115 | 6.23979 | 1173 | UNKNOWN | Russian - Russia | PNG |
124 | 6.20234 | 1151 | UNKNOWN | Russian - Russia | PNG |
126 | 5.86375 | 1032 | UNKNOWN | Russian - Russia | PNG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
VERSION.dll |
WININET.dll |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --type=renderer --field-trial-handle=1968,9011922438776290444,15253633181588332600,131072 --service-pipe-token=70CDADE5ADF2490E53F72F23153833B6 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-checker-imaging --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=70CDADE5ADF2490E53F72F23153833B6 --renderer-client-id=20 --mojo-platform-channel-handle=3276 /prefetch:1 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: LOW Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 464 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --type=utility --field-trial-handle=1968,9011922438776290444,15253633181588332600,131072 --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir2156_21768" --service-request-channel-token=D7A23C31F8DB76B84F6F95311CD0D005 --mojo-platform-channel-handle=3004 --ignored=" --type=renderer " /prefetch:8 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: LOW Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --type=utility --field-trial-handle=1968,9011922438776290444,15253633181588332600,131072 --lang=en-US --no-sandbox --service-request-channel-token=69C945C188C9B6A5D80AC0898BB9C518 --mojo-platform-channel-handle=3532 /prefetch:8 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: MEDIUM Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --type=utility --field-trial-handle=1968,9011922438776290444,15253633181588332600,131072 --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir2156_30005" --service-request-channel-token=B0326BDE1BDA48A82036833BDF87977F --mojo-platform-channel-handle=3508 --ignored=" --type=renderer " /prefetch:8 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: LOW Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 584 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe --type=crashpad-handler /prefetch:7 --monitor-self --monitor-self-argument=--type=crashpad-handler --monitor-self-argument=/prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\FreeU\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\FreeU\User Data" --url=https://webrowser.amigo.mail.ru/amcr --annotation=ProductName=FreeU --annotation=Version=61.0.3163.69 --annotation=bid={68F998FD-C758-4E02-A0E9-9AFA24028E29} --annotation=plat=Win32 --initial-client-data=0x6c,0x70,0x74,0x68,0x78,0x6ed272bc,0x6ed272cc,0x6ed272dc | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: MEDIUM Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 916 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe --type=crashpad-handler /prefetch:7 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\FreeU\User Data\Crashpad" --url=https://webrowser.amigo.mail.ru/amcr --annotation=ProductName=FreeU --annotation=Version=61.0.3163.69 --annotation=bid={68F998FD-C758-4E02-A0E9-9AFA24028E29} --annotation=plat=Win32 --initial-client-data=0x90,0x94,0x98,0x88,0x9c,0x104db34,0x104db44,0x104db54 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: MEDIUM Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 948 | C:\Users\admin\AppData\Local\FreeU\Application\61.0.3163.69\Installer\setup.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\FreeU\User Data\Crashpad" --url=https://webrowser.amigo.mail.ru/amcr --annotation=ProductName=FreeU --annotation=Version=61.0.3163.69 --annotation=bid={68F998FD-C758-4E02-A0E9-9AFA24028E29} --annotation=plat=Win32 --initial-client-data=0x104,0x108,0x10c,0xf0,0x110,0x146bde8,0x146bdf8,0x146be08 | C:\Users\admin\AppData\Local\FreeU\Application\61.0.3163.69\Installer\setup.exe | — | setup.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: HIGH Description: FreeU Installer Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 996 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\FreeU\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\FreeU\User Data" --url=https://webrowser.amigo.mail.ru/amcr --annotation=ProductName=FreeU --annotation=Version=61.0.3163.69 --annotation=bid={68F998FD-C758-4E02-A0E9-9AFA24028E29} --annotation=plat=Win32 --initial-client-data=0x6c,0x70,0x74,0x68,0x78,0x6ed272bc,0x6ed272cc,0x6ed272dc | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: MEDIUM Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 1072 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --type=utility --field-trial-handle=1968,9011922438776290444,15253633181588332600,131072 --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir2156_15032" --service-request-channel-token=F3D3CE2F7F0892E407EB2AF197618D19 --mojo-platform-channel-handle=3224 --ignored=" --type=renderer " /prefetch:8 | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | freeu.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: LOW Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| 1176 | "C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe" --profile-directory=Default --app-id=jbhbhflenehimkngcjnpeleogniobpnn | C:\Users\admin\AppData\Local\FreeU\Application\freeu.exe | — | explorer.exe | |||||||||||
User: admin Company: Dilane Limited Integrity Level: MEDIUM Description: FreeU Exit code: 0 Version: 61.0.3163.69 Modules
| |||||||||||||||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Mail.Ru\FreeuInstaller |
| Operation: | write | Name: | LOADERGUID |
Value: {68F998FD-C758-4E02-A0E9-9AFA24028E29} | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2400) freeu.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2544) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | |"7 |
Value: 7C223700F0090000010000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2400 | freeu.exe | C:\Users\admin\AppData\Local\Temp\Cab4626.tmp | — | |
MD5:— | SHA256:— | |||
| 2400 | freeu.exe | C:\Users\admin\AppData\Local\Temp\Tar4627.tmp | — | |
MD5:— | SHA256:— | |||
| 2544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA2DC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{002F5645-0D4A-4E59-8041-DBA7FB152FA6}.tmp | — | |
MD5:— | SHA256:— | |||
| 2544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{ED0DCCDF-F5D4-4D66-A6D7-89D00D90A03F}.tmp | — | |
MD5:— | SHA256:— | |||
| 2544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{EF44A8A3-E444-4463-818D-399CEB74D21F}.tmp | — | |
MD5:— | SHA256:— | |||
| 2464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRFF15.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{440F4DFE-7505-4B8C-B464-C6ABFE94C130}.tmp | — | |
MD5:— | SHA256:— | |||
| 2464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5515738A-0361-44F1-9AA3-1471A2B97A47}.tmp | — | |
MD5:— | SHA256:— | |||
| 2464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{6E752838-069A-4AEF-8633-35D34465ECDC}.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2400 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/freeu/update/2/version.txt?GUID={68F998FD-C758-4E02-A0E9-9AFA24028E29}&os=6.1&type=freeu_loader_fb_error&newrfr=901001&system_code=0&exit_code=1111&host=freeu.distribcdn.com | RU | — | — | malicious |
2400 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/freeu/update/2/version.txt?GUID={68F998FD-C758-4E02-A0E9-9AFA24028E29}&os=6.1&type=freeu_loader_run&newrfr=901001 | RU | — | — | malicious |
2400 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/freeu/update/2/version.txt?GUID={68F998FD-C758-4E02-A0E9-9AFA24028E29}&os=6.1&type=freeu_loader_fb_error&newrfr=901001&system_code=0&exit_code=1111&host=update.svbrwsr.com | RU | — | — | malicious |
2584 | setup.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/update/2/version.txt?old_mr1lad=5f92c1ac5e271408-300-300-&BID=%7B68F998FD-C758-4E02-A0E9-9AFA24028E29%7D&attr=901001chsg&ds=m&kind=freeu&osa=x86&osn=Windows%20NT&osv=6.1.7601%20SP1&psi=901001&rfr=901001&type=install&ver=61.0.3163.69&wi=1 | RU | — | — | malicious |
2400 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/freeu/update/2/version.txt?GUID={68F998FD-C758-4E02-A0E9-9AFA24028E29}&os=6.1&type=freeu_loader_downloaded&newrfr=901001 | RU | — | — | malicious |
2584 | setup.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/update/2/version.txt?old_mr1lad=5f92c1ac5e271408-300-300-&BID=%7B68F998FD-C758-4E02-A0E9-9AFA24028E29%7D&attr=901001chsg&ds=m&kind=freeu&osa=x86&osn=Windows%20NT&osv=6.1.7601%20SP1&psi=901001&rfr=901001&status=first_install&type=install_finished&ver=61.0.3163.69&wi=1 | RU | — | — | malicious |
2400 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/freeu/update/2/version.txt?GUID={68F998FD-C758-4E02-A0E9-9AFA24028E29}&os=6.1&type=freeu_loader_finished&system_code=0&exit_code=0&rfr=901001&attr=901001chsg&newrfr=901001 | RU | — | — | malicious |
2584 | setup.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/update/2/version.txt?old_mr1lad=5f92c1ac5e271408-300-300-&BID=%7B68F998FD-C758-4E02-A0E9-9AFA24028E29%7D&attr=901001chsg&ds=m&kind=freeu&osa=x86&osn=Windows%20NT&osv=6.1.7601%20SP1&psi=901001&rfr=901001&status=started&type=install_started&ver=61.0.3163.69&wi=1 | RU | — | — | malicious |
2156 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/update/2/version.txt?BID=%7B68F998FD-C758-4E02-A0E9-9AFA24028E29%7D&attr=901001chsg&ds=m&kind=freeu&label=started&osa=x86&osn=Windows%20NT&osv=6.1.7601%20SP1&rfr=901001&slides=thankyou%3Bvk%3Bok%3B&type=onboarding&ver=61.0.3163.69&wi=1 | RU | — | — | malicious |
2156 | freeu.exe | GET | 204 | 95.163.144.13:80 | http://freeubs.com/update/2/version.txt?old_mr1lad=5f92c1ac5e271408-300-300-&BID=%7B68F998FD-C758-4E02-A0E9-9AFA24028E29%7D&attr=901001chsg&ds=m&kind=freeu&osa=x86&osn=Windows%20NT&osv=6.1.7601%20SP1&rfr=901001&type=first_online&ver=61.0.3163.69&wi=1 | RU | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2156 | freeu.exe | 217.20.147.1:443 | ok.ru | Limited liability company Mail.Ru | RU | unknown |
2400 | freeu.exe | 95.163.144.13:80 | freeubs.com | Mrgroup Investments Limited | RU | malicious |
2400 | freeu.exe | 104.18.20.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
2400 | freeu.exe | 185.30.176.248:443 | freeu.distribcdn.com | MRG Hosting B.V. | NL | unknown |
2400 | freeu.exe | 104.18.21.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
2584 | setup.exe | 95.163.144.13:80 | freeubs.com | Mrgroup Investments Limited | RU | malicious |
2156 | freeu.exe | 217.69.139.252:443 | data.amigo.mail.ru | Limited liability company Mail.Ru | RU | suspicious |
2156 | freeu.exe | 95.163.144.13:80 | freeubs.com | Mrgroup Investments Limited | RU | malicious |
2156 | freeu.exe | 172.217.22.74:443 | translate.googleapis.com | Google Inc. | US | whitelisted |
2156 | freeu.exe | 172.217.22.35:443 | www.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
freeubs.com |
| malicious |
freeu.distribcdn.com |
| unknown |
ocsp.globalsign.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |
update.svbrwsr.com |
| unknown |
www.google.com |
| malicious |
data.amigo.mail.ru |
| suspicious |
translate.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
frpxa.com |
| unknown |