File name:

kindle-for-pc-1.39.65323-installer_63W-br1.exe

Full analysis: https://app.any.run/tasks/a11a753b-1197-4128-9476-dd4db330025a
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 07, 2022, 05:49:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

769D2E2DA3E69C5AA1CAE0F62FF36E5D

SHA1:

2235006F83ACC09EB6EEC545CC0AC9C6B803330E

SHA256:

3D6E6600D11351858063484B6B8453DCDE17246772858545D354BEC0926F87C8

SSDEEP:

24576:U4nXubIQGyxbPV0db26WLzJ0m/K421t0YKbDVfcqOlsoO0drNBuLy1zoHf2MPyd:Uqe3f6WJW5leDlMlsRmpgtfKd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 1580)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 3524)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
    • Application was dropped or rewritten from another process

      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • saBSI.exe (PID: 2880)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
      • sbr.exe (PID: 4048)
    • Loads dropped or rewritten executable

      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Changes the autorun value in the registry

      • instup.exe (PID: 292)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • saBSI.exe (PID: 2880)
    • Drops a file with too old compile date

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
    • Reads the Internet Settings

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • saBSI.exe (PID: 2880)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Reads settings of System Certificates

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • saBSI.exe (PID: 2880)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Reads the Windows owner or organization settings

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
    • Executable content was dropped or overwritten

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 3524)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 1580)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Process requests binary or script from the Internet

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
    • Creates or modifies Windows services

      • instup.exe (PID: 2304)
    • Checks Windows Trust Settings

      • saBSI.exe (PID: 2880)
    • Reads security settings of Internet Explorer

      • saBSI.exe (PID: 2880)
    • Starts itself from another location

      • instup.exe (PID: 2304)
    • Creates a directory in Program Files

      • instup.exe (PID: 292)
    • Check if any antivirus is installed

      • instup.exe (PID: 292)
  • INFO

    • Reads the computer name

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 2420)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • saBSI.exe (PID: 2880)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Checks supported languages

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 1580)
      • kindle-for-pc-1.39.65323-installer_63W-br1.exe (PID: 3524)
      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 2420)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • saBSI.exe (PID: 2880)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
      • sbr.exe (PID: 4048)
    • Application was dropped or rewritten from another process

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 2420)
      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
    • Loads dropped or rewritten executable

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
    • Creates files in the program directory

      • saBSI.exe (PID: 2880)
      • instup.exe (PID: 292)
    • Drops a file that was compiled in debug mode

      • kindle-for-pc-1.39.65323-installer_63W-br1.tmp (PID: 3512)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 1028)
      • avast_free_antivirus_setup_online.exe (PID: 1216)
      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Reads Environment values

      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Checks proxy server information

      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Reads the CPU's name

      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
    • Reads CPU info

      • instup.exe (PID: 2304)
      • instup.exe (PID: 292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2021-Jun-03 08:09:11
Detected languages:
  • English - United States
Comments: This installation was built with Inno Setup.
CompanyName: -
FileDescription: Softoníc International SA
FileVersion: 6.44.1344
LegalCopyright: ©2022 Softoníc International SA
OriginalFileName: -
ProductName: Softoníc International SA
ProductVersion: 6.44.1344

DOS Header

e_magic: MZ
e_cblp: 80
e_cp: 2
e_crlc: -
e_cparhdr: 4
e_minalloc: 15
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: 26
e_oemid: -
e_oeminfo: -
e_lfanew: 256

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 10
TimeDateStamp: 2021-Jun-03 08:09:11
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
734748
735232
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.35606
.itext
741376
5768
6144
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.97275
.data
749568
14244
14336
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.0444
.bss
765952
28136
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.idata
794624
3894
4096
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.8987
.didata
798720
420
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.75636
.edata
802816
154
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.87222
.tls
806912
24
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rdata
811008
93
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.38389
.rsrc
815104
69120
69120
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.71354

Resources

Title
Entropy
Size
Codepage
Language
Type
1
1.74641
2664
UNKNOWN
English - United States
RT_ICON
2
1.98658
1640
UNKNOWN
English - United States
RT_ICON
3
2.01586
744
UNKNOWN
English - United States
RT_ICON
4
2.1704
296
UNKNOWN
English - United States
RT_ICON
5
1.912
5672
UNKNOWN
English - United States
RT_ICON
6
1.8663
3752
UNKNOWN
English - United States
RT_ICON
7
1.49649
2216
UNKNOWN
English - United States
RT_ICON
8
0.972379
1384
UNKNOWN
English - United States
RT_ICON
9
7.68913
4837
UNKNOWN
English - United States
RT_ICON
10
2.03031
16936
UNKNOWN
English - United States
RT_ICON

Imports

advapi32.dll
comctl32.dll
kernel32.dll
kernel32.dll (delay-loaded)
netapi32.dll
oleaut32.dll
user32.dll
version.dll

Exports

Title
Ordinal
Address
dbkFCallWrapperAddr
1
779836
__dbk_fcall_wrapper
2
53408
TMethodImplementationIntercept
3
344160
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start kindle-for-pc-1.39.65323-installer_63w-br1.exe kindle-for-pc-1.39.65323-installer_63w-br1.tmp no specs kindle-for-pc-1.39.65323-installer_63w-br1.exe kindle-for-pc-1.39.65323-installer_63w-br1.tmp cookie_mmm_irs_ppi_005_888_a.exe sabsi.exe avast_free_antivirus_setup_online.exe instup.exe instup.exe sbr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Windows\Temp\asw.350a747577caa5af\New_160c179c\instup.exe" /sfx /sfxstorage:C:\Windows\Temp\asw.350a747577caa5af /edition:1 /prod:ais /guid:b486c346-0552-481e-a5d3-2c436765cd85 /ga_clientid:15de4ba1-7367-449b-a6b8-8626b55e05d7 /silent /ws /psh:2bJ1khPlQPSjoN9bhea86depcS8U09tWmMoCpD6VMdnmVOKIvYnb2n2Z1HiOGnsNEbleiPUYKzZjg /cookie:mmm_irs_ppi_005_888_a /edat_dir:C:\Windows\Temp\asw.27c5c12e13a8d43b /online_installerC:\Windows\Temp\asw.350a747577caa5af\New_160c179c\instup.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
22.12.7758.0
Modules
Images
c:\windows\temp\asw.350a747577caa5af\new_160c179c\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\wininet.dll
1028"C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod0_extract\cookie_mmm_irs_ppi_005_888_a.exe" /silent /ws /psh:2bJ1khPlQPSjoN9bhea86depcS8U09tWmMoCpD6VMdnmVOKIvYnb2n2Z1HiOGnsNEbleiPUYKzZjgC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod0_extract\cookie_mmm_irs_ppi_005_888_a.exe
kindle-for-pc-1.39.65323-installer_63W-br1.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
2.1.1286.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jdpec.tmp\prod0_extract\cookie_mmm_irs_ppi_005_888_a.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1216"C:\Windows\Temp\asw.27c5c12e13a8d43b\avast_free_antivirus_setup_online.exe" /silent /ws /psh:2bJ1khPlQPSjoN9bhea86depcS8U09tWmMoCpD6VMdnmVOKIvYnb2n2Z1HiOGnsNEbleiPUYKzZjg /cookie:mmm_irs_ppi_005_888_a /ga_clientid:15de4ba1-7367-449b-a6b8-8626b55e05d7 /edat_dir:C:\Windows\Temp\asw.27c5c12e13a8d43bC:\Windows\Temp\asw.27c5c12e13a8d43b\avast_free_antivirus_setup_online.exe
cookie_mmm_irs_ppi_005_888_a.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus
Exit code:
0
Version:
22.12.7758.0
Modules
Images
c:\windows\temp\asw.27c5c12e13a8d43b\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
1580"C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe" C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Softoníc International SA
Exit code:
2
Version:
6.44.1344
Modules
Images
c:\users\admin\appdata\local\temp\kindle-for-pc-1.39.65323-installer_63w-br1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2304"C:\Windows\Temp\asw.350a747577caa5af\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.350a747577caa5af /edition:1 /prod:ais /guid:b486c346-0552-481e-a5d3-2c436765cd85 /ga_clientid:15de4ba1-7367-449b-a6b8-8626b55e05d7 /silent /ws /psh:2bJ1khPlQPSjoN9bhea86depcS8U09tWmMoCpD6VMdnmVOKIvYnb2n2Z1HiOGnsNEbleiPUYKzZjg /cookie:mmm_irs_ppi_005_888_a /ga_clientid:15de4ba1-7367-449b-a6b8-8626b55e05d7 /edat_dir:C:\Windows\Temp\asw.27c5c12e13a8d43bC:\Windows\Temp\asw.350a747577caa5af\instup.exe
avast_free_antivirus_setup_online.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
22.12.7758.0
Modules
Images
c:\windows\temp\asw.350a747577caa5af\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2420"C:\Users\admin\AppData\Local\Temp\is-RVMDJ.tmp\kindle-for-pc-1.39.65323-installer_63W-br1.tmp" /SL5="$50198,874175,831488,C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe" C:\Users\admin\AppData\Local\Temp\is-RVMDJ.tmp\kindle-for-pc-1.39.65323-installer_63W-br1.tmpkindle-for-pc-1.39.65323-installer_63W-br1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rvmdj.tmp\kindle-for-pc-1.39.65323-installer_63w-br1.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2880"C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\saBSI.exe" /affid 91082 PaidDistribution=true C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\saBSI.exe
kindle-for-pc-1.39.65323-installer_63W-br1.tmp
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
0
Version:
4,1,1,663
Modules
Images
c:\users\admin\appdata\local\temp\is-jdpec.tmp\prod1_extract\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3512"C:\Users\admin\AppData\Local\Temp\is-2MO3U.tmp\kindle-for-pc-1.39.65323-installer_63W-br1.tmp" /SL5="$6019E,874175,831488,C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe" /SPAWNWND=$501C8 /NOTIFYWND=$50198 C:\Users\admin\AppData\Local\Temp\is-2MO3U.tmp\kindle-for-pc-1.39.65323-installer_63W-br1.tmp
kindle-for-pc-1.39.65323-installer_63W-br1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2mo3u.tmp\kindle-for-pc-1.39.65323-installer_63w-br1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3524"C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe" /SPAWNWND=$501C8 /NOTIFYWND=$50198 C:\Users\admin\AppData\Local\Temp\kindle-for-pc-1.39.65323-installer_63W-br1.exe
kindle-for-pc-1.39.65323-installer_63W-br1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softoníc International SA
Exit code:
2
Version:
6.44.1344
Modules
Images
c:\users\admin\appdata\local\temp\kindle-for-pc-1.39.65323-installer_63w-br1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4048"C:\Windows\Temp\asw.350a747577caa5af\New_160c179c\sbr.exe" 292 "Avast Antivirus setup" "Avast Antivirus is being installed. Do not shut down your computer!"C:\Windows\Temp\asw.350a747577caa5af\New_160c179c\sbr.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Shutdown blocker
Exit code:
0
Version:
22.12.7758.0
Modules
Images
c:\windows\temp\asw.350a747577caa5af\new_160c179c\sbr.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\lpk.dll
Total events
49 540
Read events
45 796
Write events
3 734
Delete events
10

Modification events

(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B80D0000682A72A8FF09D901
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
111AA94C93A762343F43E497AFFEBDCDCC3C91FCD381B263089C3B91E81FAA2D
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
0400000001000000100000001BFE69D191B71933A372A80FE155E5B5090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD9796254830300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0B00000001000000100000005300650063007400690067006F0000001D0000000100000010000000885010358D29A38F059B028559C95F901400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD2190000000100000010000000EA6089055218053DD01E37E1D806EEDF53000000010000004300000030413022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C02000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
5C00000001000000040000000010000053000000010000004300000030413022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000EA6089055218053DD01E37E1D806EEDF620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD21400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB1D0000000100000010000000885010358D29A38F059B028559C95F900B00000001000000100000005300650063007400690067006F0000000300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD979625483090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080400000001000000100000001BFE69D191B71933A372A80FE155E5B52000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349
Operation:writeName:Blob
Value:
040000000100000010000000497904B0EB8719AC47B0BC11519B74D0090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F00000001000000140000003E8E6487F8FD27D322A269A71EDAAC5D57811286030000000100000014000000D1EB23A46D17D68FD92564C2F1F1601764D8E3491D00000001000000100000002E0D6875874A44C820912E85E964CFDB140000000100000014000000A0110A233E96F107ECE2AF29EF82A57FD030A4B40B000000010000001C0000005300650063007400690067006F002000280041004100410029000000620000000100000020000000D7A7A0FB5D7E2731D771E9484EBCDEF71D5F0C3E0A2948782BC83EE0EA699EF41900000001000000100000002AA1C05E2AE606F198C2C5E937C97AA253000000010000004300000030413022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0200000000100000036040000308204323082031AA003020102020101300D06092A864886F70D0101050500307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C18414141204365727469666963617465205365727669636573301E170D3034303130313030303030305A170D3238313233313233353935395A307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C1841414120436572746966696361746520536572766963657330820122300D06092A864886F70D01010105000382010F003082010A0282010100BE409DF46EE1EA76871C4D45448EBE46C883069DC12AFE181F8EE402FAF3AB5D508A16310B9A06D0C57022CD492D5463CCB66E68460B53EACB4C24C0BC724EEAF115AEF4549A120AC37AB23360E2DA8955F32258F3DEDCCFEF8386A28C944F9F68F29890468427C776BFE3CC352C8B5E07646582C048B0A891F9619F762050A891C766B5EB78620356F08A1A13EA31A31EA099FD38F6F62732586F07F56BB8FB142BAFB7AACCD6635F738CDA0599A838A8CB17783651ACE99EF4783A8DCF0FD942E2980CAB2F9F0E01DEEF9F9949F12DDFAC744D1B98B547C5E529D1F99018C7629CBE83C7267B3E8A25C7C0DD9DE6356810209D8FD8DED2C3849C0D5EE82FC90203010001A381C03081BD301D0603551D0E04160414A0110A233E96F107ECE2AF29EF82A57FD030A4B4300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF307B0603551D1F047430723038A036A0348632687474703A2F2F63726C2E636F6D6F646F63612E636F6D2F414141436572746966696361746553657276696365732E63726C3036A034A0328630687474703A2F2F63726C2E636F6D6F646F2E6E65742F414141436572746966696361746553657276696365732E63726C300D06092A864886F70D010105050003820101000856FC02F09BE8FFA4FAD67BC64480CE4FC4C5F60058CCA6B6BC1449680476E8E6EE5DEC020F60D68D50184F264E01E3E6B0A5EEBFBC745441BFFDFC12B8C74F5AF48960057F60B7054AF3F6F1C2BFC4B97486B62D7D6BCCD2F346DD2FC6E06AC3C334032C7D96DD5AC20EA70A99C1058BAB0C2FF35C3ACF6C37550987DE53406C58EFFCB6AB656E04F61BDC3CE05A15C69ED9F15948302165036CECE92173EC9B03A1E037ADA015188FFABA02CEA72CA910132CD4E50826AB229760F8905E74D4A29A53BDF2A968E0A26EC2D76CB1A30F9EBFEB68E756F2AEF2E32B383A0981B56B85D7BE2DED3F1AB7B263E2F5622C82D46A004150F139839F95E93696986E
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349
Operation:writeName:Blob
Value:
5C00000001000000040000000008000053000000010000004300000030413022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C01900000001000000100000002AA1C05E2AE606F198C2C5E937C97AA2620000000100000020000000D7A7A0FB5D7E2731D771E9484EBCDEF71D5F0C3E0A2948782BC83EE0EA699EF40B000000010000001C0000005300650063007400690067006F002000280041004100410029000000140000000100000014000000A0110A233E96F107ECE2AF29EF82A57FD030A4B41D00000001000000100000002E0D6875874A44C820912E85E964CFDB030000000100000014000000D1EB23A46D17D68FD92564C2F1F1601764D8E3490F00000001000000140000003E8E6487F8FD27D322A269A71EDAAC5D57811286090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B06010505070308040000000100000010000000497904B0EB8719AC47B0BC11519B74D0200000000100000036040000308204323082031AA003020102020101300D06092A864886F70D0101050500307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C18414141204365727469666963617465205365727669636573301E170D3034303130313030303030305A170D3238313233313233353935395A307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C1841414120436572746966696361746520536572766963657330820122300D06092A864886F70D01010105000382010F003082010A0282010100BE409DF46EE1EA76871C4D45448EBE46C883069DC12AFE181F8EE402FAF3AB5D508A16310B9A06D0C57022CD492D5463CCB66E68460B53EACB4C24C0BC724EEAF115AEF4549A120AC37AB23360E2DA8955F32258F3DEDCCFEF8386A28C944F9F68F29890468427C776BFE3CC352C8B5E07646582C048B0A891F9619F762050A891C766B5EB78620356F08A1A13EA31A31EA099FD38F6F62732586F07F56BB8FB142BAFB7AACCD6635F738CDA0599A838A8CB17783651ACE99EF4783A8DCF0FD942E2980CAB2F9F0E01DEEF9F9949F12DDFAC744D1B98B547C5E529D1F99018C7629CBE83C7267B3E8A25C7C0DD9DE6356810209D8FD8DED2C3849C0D5EE82FC90203010001A381C03081BD301D0603551D0E04160414A0110A233E96F107ECE2AF29EF82A57FD030A4B4300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF307B0603551D1F047430723038A036A0348632687474703A2F2F63726C2E636F6D6F646F63612E636F6D2F414141436572746966696361746553657276696365732E63726C3036A034A0328630687474703A2F2F63726C2E636F6D6F646F2E6E65742F414141436572746966696361746553657276696365732E63726C300D06092A864886F70D010105050003820101000856FC02F09BE8FFA4FAD67BC64480CE4FC4C5F60058CCA6B6BC1449680476E8E6EE5DEC020F60D68D50184F264E01E3E6B0A5EEBFBC745441BFFDFC12B8C74F5AF48960057F60B7054AF3F6F1C2BFC4B97486B62D7D6BCCD2F346DD2FC6E06AC3C334032C7D96DD5AC20EA70A99C1058BAB0C2FF35C3ACF6C37550987DE53406C58EFFCB6AB656E04F61BDC3CE05A15C69ED9F15948302165036CECE92173EC9B03A1E037ADA015188FFABA02CEA72CA910132CD4E50826AB229760F8905E74D4A29A53BDF2A968E0A26EC2D76CB1A30F9EBFEB68E756F2AEF2E32B383A0981B56B85D7BE2DED3F1AB7B263E2F5622C82D46A004150F139839F95E93696986E
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3512) kindle-for-pc-1.39.65323-installer_63W-br1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
56
Suspicious files
74
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\is-KBA9J.tmp
MD5:
SHA256:
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\is-TU4QL.tmp
MD5:
SHA256:
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\AVAST.pngimage
MD5:096FF7DBB7F5DFB71CF40FCD37A59FD6
SHA256:6197D9AD63A37760E88B7EE53077FAF94D0DEEB9D8740428D2DC76A7242D7843
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod0_extract\cookie_mmm_irs_ppi_005_888_a.exeexecutable
MD5:31208B48ACFE1C6E1D5CD1BCB63CCB4D
SHA256:2F4085CDABD5066BEA81DC18AC026F71D3BF61765D174229DFF39203516E2BF3
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\is-I1QEK.tmpcompressed
MD5:D6BE5546BBCE27020B742C5966838158
SHA256:49082EF6E5B8CEAC180171309611EAC88DAC603684CDE04E3725945A6722BCE2
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\is-AI1EP.tmpimage
MD5:096FF7DBB7F5DFB71CF40FCD37A59FD6
SHA256:6197D9AD63A37760E88B7EE53077FAF94D0DEEB9D8740428D2DC76A7242D7843
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\x_in_black_circle.pngimage
MD5:E473525D62BD16A62C734D3EA62AB2E5
SHA256:17F19ED0D114A60342158E117D4FE76DB1F5B96B239987F623598C681EB797B0
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\v_in_black_circle.pngimage
MD5:31EB10BB3B18E8AEED132CE3F9CCC267
SHA256:B64F4684BEB5DABE885298A64A82C2182E8CB86C755CBA162FC3916D3FB68437
3512kindle-for-pc-1.39.65323-installer_63W-br1.tmpC:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\is-NLB39.tmpcompressed
MD5:C0526C31262A1C5BCC1F0DE4838A65E8
SHA256:4248B397B4ADEE48F749F004B8233FD41ECCEF3A0417CB7655070A875EA0CF74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
55
DNS requests
83
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1028
cookie_mmm_irs_ppi_005_888_a.exe
GET
200
23.48.23.20:80
http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online.exe
US
executable
8.45 Mb
whitelisted
2304
instup.exe
GET
200
184.51.252.162:80
http://d3176133.iavs9x.u.avast.com/iavs9x/offertool_ais-9f5.vpx
US
binary
567 Kb
whitelisted
2304
instup.exe
GET
200
184.51.252.162:80
http://z4055813.iavs9x.u.avast.com/iavs9x/servers.def.vpx
US
binary
2.40 Kb
whitelisted
1028
cookie_mmm_irs_ppi_005_888_a.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
1028
cookie_mmm_irs_ppi_005_888_a.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
2304
instup.exe
GET
200
184.51.252.162:80
http://d3176133.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-9f5.vpx
US
binary
331 Kb
whitelisted
292
instup.exe
GET
200
184.51.252.142:80
http://r4427608.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
US
binary
571 b
whitelisted
2304
instup.exe
GET
200
184.51.252.142:80
http://b8003600.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
US
binary
571 b
whitelisted
292
instup.exe
GET
200
184.51.252.161:80
http://y9830512.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx
US
binary
341 b
suspicious
292
instup.exe
GET
200
184.51.252.161:80
http://y9830512.vps18tiny.u.avcdn.net/vps18tiny/part-vps_windows-22120599.vpx
US
binary
7.00 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3512
kindle-for-pc-1.39.65323-installer_63W-br1.tmp
99.86.1.62:443
ds0ipd79cknej.cloudfront.net
AMAZON-02
US
unknown
1028
cookie_mmm_irs_ppi_005_888_a.exe
23.48.23.20:80
iavs9x.u.avast.com
Akamai International B.V.
DE
suspicious
1216
avast_free_antivirus_setup_online.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
1216
avast_free_antivirus_setup_online.exe
142.250.186.78:80
www.google-analytics.com
GOOGLE
US
whitelisted
2880
saBSI.exe
44.242.98.173:443
apis.mosaic.analytics.awscommon.mcafee.com
AMAZON-02
US
unknown
2880
saBSI.exe
23.35.236.52:443
sadownload.mcafee.com
AKAMAI-AS
DE
suspicious
2304
instup.exe
184.51.252.162:80
b8003600.iavs9x.u.avast.com
Akamai International B.V.
SE
unknown
292
instup.exe
184.51.252.142:80
b8003600.iavs9x.u.avast.com
Akamai International B.V.
SE
suspicious
1028
cookie_mmm_irs_ppi_005_888_a.exe
142.250.186.78:80
www.google-analytics.com
GOOGLE
US
whitelisted
2304
instup.exe
184.51.252.142:80
b8003600.iavs9x.u.avast.com
Akamai International B.V.
SE
suspicious

DNS requests

Domain
IP
Reputation
ds0ipd79cknej.cloudfront.net
  • 18.66.107.32
  • 18.66.107.145
  • 18.66.107.82
  • 18.66.107.117
  • 99.86.1.62
  • 99.86.1.200
  • 99.86.1.20
  • 99.86.1.229
malicious
images.sftcdn.net
  • 184.24.22.189
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
gsf-fl.softonic.com
  • 199.232.194.133
  • 199.232.198.133
whitelisted
iavs9x.u.avast.com
  • 23.48.23.20
  • 23.48.23.6
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.186.78
whitelisted
cu1pehnswad01.servicebus.windows.net
  • 104.208.16.0
whitelisted
apis.mosaic.analytics.awscommon.mcafee.com
  • 44.242.98.173
  • 52.32.175.231
unknown
analytics.ff.avast.com
  • 34.117.223.223
whitelisted

Threats

PID
Process
Class
Message
1028
cookie_mmm_irs_ppi_005_888_a.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2880
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2880
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
Process
Message
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-JDPEC.tmp\prod1_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory