| File name: | CryptoTabSetup_EQkJqEX.exe |
| Full analysis: | https://app.any.run/tasks/92fcd5c4-ab2c-47b9-97fb-8984e335c102 |
| Verdict: | Malicious activity |
| Analysis date: | April 25, 2019, 18:17:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C335E3FD6218D622BDAD4F9B1FA3BAC6 |
| SHA1: | E06CE4C13E3ABA92CFC007CDC928A7F020082496 |
| SHA256: | 3C63D911E4F911F2BA6F411E93BA850091AAC9C6C4C962EEE914358AC1AC8E0C |
| SSDEEP: | 24576:31llZmeB0lj3wVOtpjxC+8biFk9ePHSQNzpPWdtJWgO0lS3r33jyNRD4:FllZmeB0egt98rayQNFPWjJW3RbcJ4 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:17 14:15:25+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 139264 |
| InitializedDataSize: | 1283584 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xf6ea |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.99.31 |
| ProductVersionNumber: | 1.3.99.31 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | CRYPTOCOMPANY OU |
| FileDescription: | CryptoTab Update Setup |
| FileVersion: | 1.3.99.31 |
| InternalName: | CryptoTab Update Setup |
| LegalCopyright: | Copyright 2018 CRYPTOCOMPANY OU |
| OriginalFileName: | CryptoTabUpdateSetup.exe |
| ProductName: | CryptoTab Update |
| ProductVersion: | 1.3.99.31 |
| LanguageId: | en |
| PrivateBuild: | - |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 17-Apr-2019 12:15:25 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | CRYPTOCOMPANY OU |
| FileDescription: | CryptoTab Update Setup |
| FileVersion: | 1.3.99.31 |
| InternalName: | CryptoTab Update Setup |
| LegalCopyright: | Copyright 2018 CRYPTOCOMPANY OU |
| OriginalFilename: | CryptoTabUpdateSetup.exe |
| ProductName: | CryptoTab Update |
| ProductVersion: | 1.3.99.31 |
| LanguageId: | en |
| PrivateBuild: | - |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000110 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 17-Apr-2019 12:15:25 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00021E1D | 0x00022000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65987 |
.rdata | 0x00023000 | 0x0000EA3C | 0x0000EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.65476 |
.data | 0x00032000 | 0x0000254C | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.58118 |
.gfids | 0x00035000 | 0x0000014C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.70705 |
.rsrc | 0x00036000 | 0x00127794 | 0x00127800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.97883 |
.reloc | 0x0015E000 | 0x00002250 | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52868 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.24273 | 1196 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 3.39591 | 5160 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.09921 | 11560 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 7.96819 | 14145 | Latin 1 / Western European | English - United States | RT_ICON |
101 | 2.49052 | 62 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
102 | 7.99987 | 1153997 | Latin 1 / Western European | UNKNOWN | B |
1321 | 3.75362 | 446 | Latin 1 / Western European | Serbian - Serbia (Cyrillic) | RT_STRING |
ADVAPI32.dll |
KERNEL32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 992 | "C:\Users\admin\AppData\Local\Temp\CR_4BE70.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_4BE70.tmp\CHROME.PACKED.7Z" --verbose-logging --system-level | C:\Users\admin\AppData\Local\Temp\CR_4BE70.tmp\setup.exe | mini_installer2_1_6_86.exe | ||||||||||||
User: admin Company: The Chromium and CryptoTab Browser Authors Integrity Level: HIGH Description: CryptoTab Browser Installer Exit code: 0 Version: 73.0.3683.103 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe" /regsvc | C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe | — | CryptoTabUpdate.exe | |||||||||||
User: admin Company: CRYPTOCOMPANY OU Integrity Level: HIGH Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 1688 | "C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe" /svc | C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: CRYPTOCOMPANY OU Integrity Level: SYSTEM Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 1848 | "C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe" /regserver | C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe | — | CryptoTabUpdate.exe | |||||||||||
User: admin Company: CRYPTOCOMPANY OU Integrity Level: HIGH Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 1868 | "C:\Program Files\CryptoCompany\Update\Install\{9F426FA9-3D90-4BA7-9CBC-54003981EC4A}\mini_installer2_1_6_86.exe" --verbose-logging --system-level | C:\Program Files\CryptoCompany\Update\Install\{9F426FA9-3D90-4BA7-9CBC-54003981EC4A}\mini_installer2_1_6_86.exe | CryptoTabUpdate.exe | ||||||||||||
User: admin Company: The Chromium and CryptoTab Browser Authors Integrity Level: HIGH Description: CryptoTab Browser Installer Exit code: 0 Version: 73.0.3683.103 Modules
| |||||||||||||||
| 2844 | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdate.exe /installsource taggedmi /install "appguid={F6D86D47-6571-4577-B35B-64318B8D2258}&appname=CryptoTabBrowser&usagestats=1&ap=release&needsadmin=prefers" | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdate.exe | — | CryptoTabSetup_EQkJqEX.exe | |||||||||||
User: admin Company: CRYPTOCOMPANY OU Integrity Level: MEDIUM Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 3364 | C:\Users\admin\AppData\Local\Temp\CR_4BE70.tmp\setup.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Windows\TEMP\Crashpad --annotation=plat=Win32 "--annotation=prod=CryptoTab Browser" --annotation=ver=73.0.3683.103 --initial-client-data=0x100,0x104,0x108,0xfc,0x10c,0x3d50e0,0x3d50f0,0x3d50fc | C:\Users\admin\AppData\Local\Temp\CR_4BE70.tmp\setup.exe | — | setup.exe | |||||||||||
User: admin Company: The Chromium and CryptoTab Browser Authors Integrity Level: HIGH Description: CryptoTab Browser Installer Exit code: 0 Version: 73.0.3683.103 Modules
| |||||||||||||||
| 3640 | "C:\Users\admin\AppData\Local\Temp\CryptoTabSetup_EQkJqEX.exe" | C:\Users\admin\AppData\Local\Temp\CryptoTabSetup_EQkJqEX.exe | explorer.exe | ||||||||||||
User: admin Company: CRYPTOCOMPANY OU Integrity Level: MEDIUM Description: CryptoTab Update Setup Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 3664 | "C:\Program Files\GUM6F40.tmp\CryptoTabUpdate.exe" /installsource taggedmi /install "appguid={F6D86D47-6571-4577-B35B-64318B8D2258}&appname=CryptoTabBrowser&usagestats=1&ap=release&needsadmin=prefers" /installelevated | C:\Program Files\GUM6F40.tmp\CryptoTabUpdate.exe | CryptoTabUpdateSetup.exe | ||||||||||||
User: admin Company: CRYPTOCOMPANY OU Integrity Level: HIGH Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| 3816 | "C:\Program Files\CryptoCompany\Update\1.3.99.31\CryptoTabCrashHandler.exe" | C:\Program Files\CryptoCompany\Update\1.3.99.31\CryptoTabCrashHandler.exe | — | CryptoTabUpdate.exe | |||||||||||
User: SYSTEM Company: CRYPTOCOMPANY OU Integrity Level: SYSTEM Description: CryptoTab Update Exit code: 0 Version: 1.3.99.31 Modules
| |||||||||||||||
| (PID) Process: | (3640) CryptoTabSetup_EQkJqEX.exe | Key: | HKEY_CURRENT_USER\Software\CryptoTab Browser |
| Operation: | write | Name: | referer |
Value: EQkJqEX | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\ClientState\{F6D86D47-6571-4577-B35B-64318B8D2258} |
| Operation: | write | Name: | usagestats |
Value: 1 | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files\CryptoCompany\Update\CryptoTabUpdate.exe" /uninstall | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\ClientState\{F6D86D47-6571-4577-B35B-64318B8D2258} |
| Operation: | write | Name: | ap |
Value: release | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\ClientState\{CA66CCBE-7980-49AB-B53C-E74F5918ECCC} |
| Operation: | write | Name: | ap |
Value: release | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\Clients\{CA66CCBE-7980-49AB-B53C-E74F5918ECCC} |
| Operation: | write | Name: | pv |
Value: 1.3.99.31 | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\Clients\{CA66CCBE-7980-49AB-B53C-E74F5918ECCC} |
| Operation: | write | Name: | name |
Value: CryptoTab Update | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CryptoCompany\Update\ClientState\{CA66CCBE-7980-49AB-B53C-E74F5918ECCC} |
| Operation: | write | Name: | pv |
Value: 1.3.99.31 | |||
| (PID) Process: | (3664) CryptoTabUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CryptoTabUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\npCryptoTabUpdate3.dll | executable | |
MD5:CA08A4C56CCDBF4B3EA23AA8DD76BB6E | SHA256:521789FCF4C376F9E4F956BE13D7046257E95202E463D007551CB35A9936AC3D | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdateBroker.exe | executable | |
MD5:10C55051EBB21196C6E87F08D05DC06C | SHA256:991F501A8BD1DE504479373E5D7A1B0AD969197CB74F9AE0B1C682C171F225D5 | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdateOnDemand.exe | executable | |
MD5:DBB427983F95C4BDA31A44F3B414FDF1 | SHA256:3CB68CF5F78F875EBC80F3BE237E9A16EE0F91A57B6FE88EDF1C181F677FFA3A | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdateHelper.msi | executable | |
MD5:646671B5840B214E79BAC5A3D103C1AF | SHA256:A175C29C116C7814A22DDA2FC542D2A0E1B0CA43C0B95AA56B37AECE4C18C20F | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabCrashHandler.exe | executable | |
MD5:81C35692D40D0A69B6F428C43D384011 | SHA256:3EA849677412B3FC97BC101BECD3215D84408CD2499787A96A10A30D945B696F | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\CryptoTabUpdateCore.exe | executable | |
MD5:59BC38A77B63717278DEF56649B49165 | SHA256:2A6CDB32C6824C602D323E69911F8B26A1A77AC38302ED259218430C81B5D35E | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\goopdateres_bg.dll | executable | |
MD5:65BE52DC4F3B587DEFEE67DD497C47D6 | SHA256:26E770EEF7B5E7DDE3D4177C8418446F2166D7F5768B40BE9DF42273913EE70F | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\goopdateres_ar.dll | executable | |
MD5:FB9FA972DD40A9C5A7910AB03BF3C46B | SHA256:574761E232358066B792F1701A8CC5C4FBA71E8CC211BBE432C10ED2C38B9406 | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\goopdateres_ca.dll | executable | |
MD5:248528B0C84C92630AB41EA3B24919D1 | SHA256:15B02325EC7540E1D2D8BE12C900425C7075621C956E96F33C483C7F88D5155F | |||
| 3640 | CryptoTabSetup_EQkJqEX.exe | C:\Users\admin\AppData\Local\Temp\GUM65F9.tmp\goopdateres_bn.dll | executable | |
MD5:2DF2E05AD66CEAD0D190BEAC1A1EDEB8 | SHA256:2F29DED1146695C18DC541B4866984D23E80695958486B80F0E4C48B2FB09EC9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3860 | CryptoTabUpdate.exe | 190.2.148.55:443 | download.cryptobrowser.today | Scarlet B.V. | CW | malicious |
1688 | CryptoTabUpdate.exe | 190.2.148.55:443 | download.cryptobrowser.today | Scarlet B.V. | CW | malicious |
— | — | 104.25.211.116:443 | cdn.cryptobrowser.today | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
download.cryptobrowser.today |
| malicious |
cdn.cryptobrowser.today |
| suspicious |