| File name: | misaca_vCSP_v1_mgr_update.exe |
| Full analysis: | https://app.any.run/tasks/ace76d59-66f3-4c3c-997d-be570011e5e9 |
| Verdict: | Malicious activity |
| Analysis date: | April 10, 2020, 13:45:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | C6A8A228D1AF3CAA0E4FCE33B25AE67B |
| SHA1: | B9A78DB48382311C07E88944803B785E7B0E1A27 |
| SHA256: | 3EEF75DBDA332373058C53A19D8B625F373C3447D8EA056AF6E5A405922AB7B8 |
| SSDEEP: | 98304:zxzLfyWLQUZe8JVYfaDOv5sjuCTHW1FsrdMxeGihQn0hH23FZdVhHP4q9dDHfHhL:NSNUZe2Vsaahu86W0IV33xzPL1 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 23:24:32+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3328 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.20.410 |
| ProductVersionNumber: | 2.0.20.410 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | MOBILE-ID TECHNOLOGIES AND SERVICES JOINT STOCK COMPANY |
| FileDescription: | MISA-CA vCSP Manager v1.0 |
| FileVersion: | 2.0.20.0410 |
| InternalName: | misaca_vCSP_v1_mgr_update.exe |
| LegalCopyRight: | Copyright (c) 2019-2020 MISA-CA |
| ProductName: | vCSP Manager |
| ProductVersion: | 2.0.20.0410 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 15-Dec-2018 22:24:32 |
| Detected languages: |
|
| CompanyName: | MOBILE-ID TECHNOLOGIES AND SERVICES JOINT STOCK COMPANY |
| FileDescription: | MISA-CA vCSP Manager v1.0 |
| FileVersion: | 2.0.20.0410 |
| InternalName: | misaca_vCSP_v1_mgr_update.exe |
| LegalCopyRight: | Copyright (c) 2019-2020 MISA-CA |
| ProductName: | vCSP Manager |
| ProductVersion: | 2.0.20.0410 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 15-Dec-2018 22:24:32 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006077 | 0x00006200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.40386 |
.rdata | 0x00008000 | 0x00001250 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04481 |
.data | 0x0000A000 | 0x0001A838 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.22445 |
.ndata | 0x00025000 | 0x00013000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00038000 | 0x00002DF8 | 0x00002E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.23293 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.28794 | 1070 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 1.51664 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.73893 | 514 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.91148 | 248 | UNKNOWN | English - United States | RT_DIALOG |
107 | 2.52183 | 160 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.89887 | 238 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Users\admin\AppData\Local\Temp\misaca_vCSP_v1_mgr_update.exe" | C:\Users\admin\AppData\Local\Temp\misaca_vCSP_v1_mgr_update.exe | — | explorer.exe | |||||||||||
User: admin Company: MOBILE-ID TECHNOLOGIES AND SERVICES JOINT STOCK COMPANY Integrity Level: MEDIUM Description: MISA-CA vCSP Manager v1.0 Exit code: 3221226540 Version: 2.0.20.0410 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\MISA-CA\vCSP Manager v1.0\regFirefox.exe" /init /cert "C:\Users\admin\AppData\Local\Temp\MIC.crt" "C:\Users\admin\AppData\Local\Temp\VNRoot.cer" "C:\Users\admin\AppData\Local\Temp\MobileID.crt" "C:\Users\admin\AppData\Local\Temp\BKAVSHA1.cer" "C:\Users\admin\AppData\Local\Temp\CA2SHA1.cer" "C:\Users\admin\AppData\Local\Temp\EFYSHA1.crt" "C:\Users\admin\AppData\Local\Temp\FTPSHA1.cer" "C:\Users\admin\AppData\Local\Temp\NewtelSHA1.cer" "C:\Users\admin\AppData\Local\Temp\SAFESHA1.cer" "C:\Users\admin\AppData\Local\Temp\SmartSignSHA1.cer" "C:\Users\admin\AppData\Local\Temp\TrustCASHA1.cer" "C:\Users\admin\AppData\Local\Temp\TrustCASHA256.cer" "C:\Users\admin\AppData\Local\Temp\ViettelSHA1.cer" "C:\Users\admin\AppData\Local\Temp\VNPTSHA1.cer" "C:\Users\admin\AppData\Local\Temp\MISA_CA_SHA2.cer""C:\Users\admin\AppData\Local\Temp\NC_CA_SHA2.crt" "C:\Users\admin\AppData\Local\Temp\FAKE_MIC.crt" "C:\Users\admin\AppData\Local\Temp\FAKE_MISACA1.cer" /uninit | C:\Program Files\MISA-CA\vCSP Manager v1.0\regFirefox.exe | misaca_vCSP_v1_mgr_update.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3 Modules
| |||||||||||||||
| 3052 | "C:\Program Files\MISA-CA\vCSP Manager v1.0\misaca_vCSP_v1_mgr.exe" | C:\Program Files\MISA-CA\vCSP Manager v1.0\misaca_vCSP_v1_mgr.exe | misaca_vCSP_v1_mgr_update.exe | ||||||||||||
User: admin Company: MOBILE-ID TECHNOLOGIES AND SERVICES JOINT STOCK COMPANY Integrity Level: HIGH Description: vCSPManager Exit code: 0 Version: 2.0.20.410 Modules
| |||||||||||||||
| 3384 | "C:\Users\admin\AppData\Local\Temp\misaca_vCSP_v1_mgr_update.exe" | C:\Users\admin\AppData\Local\Temp\misaca_vCSP_v1_mgr_update.exe | explorer.exe | ||||||||||||
User: admin Company: MOBILE-ID TECHNOLOGIES AND SERVICES JOINT STOCK COMPANY Integrity Level: HIGH Description: MISA-CA vCSP Manager v1.0 Exit code: 0 Version: 2.0.20.0410 Modules
| |||||||||||||||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | csp_MISACAv1 |
Value: C:\Program Files\MISA-CA\vCSP Manager v1.0\misaca_vCSP_v1_mgr.exe | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MISA-CA\vCSP Manager v1.0 |
| Operation: | write | Name: | Path |
Value: C:\Program Files\MISA-CA\vCSP Manager v1.0 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MISA-CA\vCSP Manager v1.0 |
| Operation: | write | Name: | PathData |
Value: C:\ProgramData\Microsoft\Crypto\RemoteSigningKSP\MISA-CA\vCSP Manager v1.0 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Remote Signing MISA-CA CSP v1.0 |
| Operation: | write | Name: | Image Path |
Value: C:\Windows\System32\misaca_csp11_v1.dll | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Remote Signing MISA-CA CSP v1.0 |
| Operation: | write | Name: | Type |
Value: 1 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\42843BC401476CDA242034B945BBF409A6BDD5C7 |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000042843BC401476CDA242034B945BBF409A6BDD5C72000000001000000DB030000308203D7308202BFA00302010202101BE4738A1F3EC08F479FA6CF35C59822300D06092A864886F70D0101050500307E310B300906035504061302564E31333031060355040A132A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73311B3019060355040B13124E6174696F6E616C2043412043656E746572311D301B060355040313144D4943204E6174696F6E616C20526F6F74204341301E170D3038303531363031313234395A170D3430303531363031323033325A307E310B300906035504061302564E31333031060355040A132A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73311B3019060355040B13124E6174696F6E616C2043412043656E746572311D301B060355040313144D4943204E6174696F6E616C20526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100A13F59510EFE30FF61DB9678148BDB433C36BE61AFDCB53F601ED30D0141ADF8C98A428EC8ED328647C5FEB5F7EAD644371012C348085150BAE557E9CE35C98E1C730985334CE1BB38AC8EADB713042E6681572DCCFB1AFD2E9C8BFD0940F060179B71456D7DE3DB2AD2BB9ADDEBCC5EE400DFD56C30859BBD577F2DD424D380FBE02851BEB0D66107CCE5A047E7916D2F8758E8B4ADC1B146B3DC5A1D3809D9FBB527989E5EFCF1F448FFE8A13BFF5033D926ABB299629DCC7BC8524D9E5C428B6F747EFC9413DE0AD2F0B56AF8964C509CE6218EC1E597014ECD9FB040197C1B596F5C38199A37DAD181391632EF81ADB0216B1197C2C108BD6F235C040FD30203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414CD6271E461BDFE3DECB24060D38175DD3AAC6BC6301006092B06010401823715010403020100300D06092A864886F70D010105050003820101004C9DCD7E2320801C28CFF0F1C9DF11CAB26953A3F25F0CB3659C2F54E11C502AE05517C417BEA8935146AA86ED24642F4F138EB0B4149C7C43BE2D4E63526CDBD6701759475BA25AB3C7967AB60DF52D0DD9643AAFD0543AD11368B6FA380E05EBE0FC30F74C9B5FE2EE677BF862EA74AF72544CD4FA5E8BECEBB827812C988EF7CAA0519673C61789F9F453973F57C3DB552849734F4A372A6784C513BEC6C9EE094762BFA8B2EA7CE55F24DB3BB87435B0E1858F8A97488EE7786789CBE5A402EC5B57A1B9C796B7C1E9E55D8E99A6A7259A1DB0CED63B6B33F2BE49E12DD68781B976AEA7FCCDB3C67632AF4D50526C2D0DB2BDD750E5D375639F5DCD0A99 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8EA95975898EFEF73B5CA92BF03F712BFBC7615F |
| Operation: | write | Name: | Blob |
Value: 0300000001000000140000008EA95975898EFEF73B5CA92BF03F712BFBC7615F200000000100000000070000308206FC308204E4A0030201020211009592BB8CEEAD5A24A6B8F71D7D323B5A300D06092A864886F70D01010B05003081A3310B300906035504061302564E31333031060355040A0C2A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73313C303A060355040B0C334E6174696F6E616C2043656E747265206F66204469676974616C205369676E61747572652041757468656E7469636174696F6E3121301F06035504030C18566965746E616D204E6174696F6E616C20526F6F74204341301E170D3134303431353136323932305A170D3339303431353136323932305A3081A3310B300906035504061302564E31333031060355040A0C2A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73313C303A060355040B0C334E6174696F6E616C2043656E747265206F66204469676974616C205369676E61747572652041757468656E7469636174696F6E3121301F06035504030C18566965746E616D204E6174696F6E616C20526F6F7420434130820222300D06092A864886F70D01010105000382020F003082020A0282020100B8AC5A7B0830D9707A69F51FE337954E140397F1BDC63E7A5284FEF0A6D6EC17888E451EBF095498AE7F8F81D0688B8D83B83DA2241A5361ADED633F7D347CA7F3E4413EF2CEE634B8BCD2C543B777C2F1067151873FF956793A71F59CB19530084814FCB1EB9D5B918C862C7DF75CDD80E050991C6E79F146AEB34C5F411B6C47DDFDC2EBC0B8637C8445A7B9302BA4A4D10B5E1E8672D451D859128457884F325465282E084249023E6A616DEB6A426E7785E314556032797AFBBF0F631BE5000F28150AD46C0CB05AAE8BCE7EB3729A3E399B967C5ECD155184700B43B8DD68CAFB2DF87EBC7FA822678F9D288E1D05CAC591827EA6D7FDF3E0DEBFF223EA89E338B815804FFA2F0A6B0C8558ED7D2F76A186ECD6E1EA069EBA0086E7F998B485641E1C0F2BE29C4CF1136192436314F7AD421A85A621D50A7E2DF1035D3248D9718A7B2F6506498581D1A9658EB9A77C6FAD85BE34771C6ED3EC47EB3072EB86455ED43FF9DD9915F4F0689A3137CAAE447B57946F7DEAC3890FEF7B37EADA10CF1E2CC56AAC6D2264D4BBCC05BD719BA35D61B2BA8B09A290C594E8A27629EC40956050EE7AE2FB13A529E1C5E57ABD6A2EFA77C3E419551E2BE7C20ABF156BB4769189952C6C36B7DF97409568E068923C4166781CE1D564B423AD7F899230CF253307371B8C124125AC2485DEB5EA50A67F24CBEA29E635EA3403687D0203010001A382012730820123300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E041604147EF087EDB1B89DFB08836FA416FDF1B8AC629B013081E00603551D230481D83081D580147EF087EDB1B89DFB08836FA416FDF1B8AC629B01A181A9A481A63081A3310B300906035504061302564E31333031060355040A0C2A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73313C303A060355040B0C334E6174696F6E616C2043656E747265206F66204469676974616C205369676E61747572652041757468656E7469636174696F6E3121301F06035504030C18566965746E616D204E6174696F6E616C20526F6F742043418211009592BB8CEEAD5A24A6B8F71D7D323B5A300D06092A864886F70D01010B050003820201004D36E9D72AF62F6B1CE038F6CAB2624B67582A1E925E1F34FBE08CC11C3829F1B81B2C3B6A1FE3D957EC3B0F0BDF643F31B85290273F6FE530E9CFF098C2B840F8152CC7231BCD2E8ABF594D6B8D896BADC1944435000558F995F79856D5BA6395E3790B420CD06B260A3E896AD68ED0C73DE5DB3833860E28E37E957DE93C2EB87F59C3F97B3C82F13B7B5426943A5FDFB926823D8BD96D5EDB670FC4CA3E312B5B9DED4AB63A9E78BD24DE828874F995B6F12404807E3D063CA3413BF9EAC4D1A25599E16C5B1ED6C12704E3EEF96292C79BBEF963A11628F70836F40B98FC0AF0DCD3614F221B5053BBE5CA2569A17C8BEE5A02F98F4337C893D9B56F32B5E553A4F2DF109D5F22E08E368C32DB5736D91506476CB2FC823F8B4C755973DB1F2A67E1907D870EC9E06FA52F283B961C1E7E5D0E50A128B219527431E518A213C8E9C8216576C87E51C6CAC7BD85B01133B51BAE2B1FFCFFFF1432E527750BEFE68B224F5FC3A9FB5B2D1672037E4318DF77150CF55482C7BD39FAE5FF68DE32D20E4B30D0A10CECE9058520EAC9A6F00D16D8B200330D10F54F532E71CEF0EBF0DE292E3B9ADF4D25B06D89B2B75E4DB05A7C2CCFD0D0DBBD42A68C34DCB6DD86D065995F168AE623D8A8584A630DB5AA53D6321FAA07A468EC05B4A84781B4214B1FC5A0DD137097231E3CA51A2549D75E6B2BD1E6C74EB0DAE124E005C2 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\50DBA3431A4F63B6BCD16C0270E31289F7B69395 |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000050DBA3431A4F63B6BCD16C0270E31289F7B69395200000000100000048060000308206443082042CA003020102020455F00F21300D06092A864886F70D01010B05003081C8310B300906035504061302564E311430120603550408130B486F20436869204D696E68311430120603550407130B486F20436869204D696E683140303E060355040A13374D6F62696C652D494420546563686E6F6C6F6769657320616E64205365727669636573204A6F696E742053746F636B20436F6D70616E7931273025060355040B131E4D6F62696C652D494420546563686E6963616C204465706172746D656E7431223020060355040313194D6F62696C652D49442054727573746564204E6574776F726B3020170D3137303432313032353035315A180F32313137303332383032353035315A3081C8310B300906035504061302564E311430120603550408130B486F20436869204D696E68311430120603550407130B486F20436869204D696E683140303E060355040A13374D6F62696C652D494420546563686E6F6C6F6769657320616E64205365727669636573204A6F696E742053746F636B20436F6D70616E7931273025060355040B131E4D6F62696C652D494420546563686E6963616C204465706172746D656E7431223020060355040313194D6F62696C652D49442054727573746564204E6574776F726B30820222300D06092A864886F70D01010105000382020F003082020A02820201008ED1C96CA4547D53C4DEFAFB4A344E2E04183B56D38BE5A02229D2B0B9FD5C68FB8233B8731F1E8ECF48F081ABC76AB95B372B71ABE2E67C51CE829B3BC115911F85EBD531805E787BC35F7BBEA2DEFF0119393CBE7829BD0AE774DF2E13A62243F1B4B3984B8BF8197DF7DC31394C42B97061D46910C867EA736817AEF9C69681935E7E7A96BB4A35DB806BC2900D02911F922AF85DE299CC391676FE3A50BCB1B90D023340B0290265877287B11714E03F3BB0DAA8629D63CED3B5FF1F9A73E5D0002A17E5238E75386D8F642968644A3595E9A6B299B76B3165698CE46CB3C8F86B15EB53C1FC040420AABDB572C2BB261BA5762A3A56C53FC2D81B27EE99D3B04B6FCB14AC0718B01D9687C2188D1E329FDDB1AF9A2FE332F11AAFD12D0F84295C9EF0DA48221804F0E0239C16E2EFECAF75B3E67E5FE19DE4E6F262D0653C97416BA0DB0508DF0439CFEF33EC209BE52897BE05AC4A342E94FC4D45A1EF51D4176F6C071B4443C670E58A543024DC3EE06C551C2E2C619A7BC54AA4F7388C4C291A6BE81A3F1C7D2DAAA0430D3ED46718CDCAB7EAB7F732E80E4FBA2A6AF9A22F1755F66689B5D1B4DBEB8B1323EA30049BFDD56A0F55750E1247E405C2924E708381B57F660E76A65E7047585A8652A39453DFFACB8A7C076A3744313F59E896B54EBA81065AB258BA4C96F446936863F5F25C71A7F89D2077D1035E7D0203010001A3323030300F0603551D130101FF040530030101FF301D0603551D0E04160414F364327DB23C5DE52EE0497CB4EA621594782EAB300D06092A864886F70D01010B050003820201008DE1053CDE77566D0E1E43BDD89D489A064415C9436E18DD58F13DB7A52CDC6766260289221084BECA22398364E050270AA507158EB1AA3B3EE45AA217407034368C899E888026911693714599801FBE22E4B5B5AD355CC700129FED6901231CA8F002BDB62082CD564F73D163557F93DDF4D58CBB8945AB0102A4A4C99D3A08A8419555672A000BA9193EB82D0FC27FEFE81290ED9116956B3163EE86F54718E5E6198EC4CC0D1D6F3044F72AF20960FB6E93A7D8EA71AC37D9F85F9D43C31C176861C53F5613248017985C61D33C7A77D8A8F897F4315A7C58D08BC2872ABE41AA350F5F4AE4F6C9407E40E5B41BC2A801B4C8A1B1DAC64ABF5527B2ED36605CFBC74D721AA2DAE5ECDEBCA4F21B4396E67AD3258AF3D7913B535AB41DAD8832E1E62C1E8C946278EA3243722AF26FC88ED1094ECEDE856247B621A3D94FED969556D9F4ACCE8CF44DB2B15D03D0FDD18D983A2BAAB33FD16118EA590D129EEA6D7075537EFC3C550A161D6521D95F36B82812F62DD1778831B5E7F9F52407C9AE9CFD1B092889A97EE02BED85B99A9F034DFC25FBB0C4306BF12BE492F64EAB252030F00F4694028E616B66032B8A51D4A246482F9F82CF8A9AC447F7B37C4E472F82B8F328BAC7EB38AA5D7FA8C58E7C83F1CAF8133E1B3007A43E0E05E09274587A4E7214A50CFE5AE7B71BEA61D8BCE17CCA04A86C00F235E4358E48E0 | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CB4E506D370E62E9336267EAA7059BCF4B7F7AE7 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000CB4E506D370E62E9336267EAA7059BCF4B7F7AE72000000001000000ED030000308203E9308202D1A0030201020210540101125472094A9A964684CDF44064300D06092A864886F70D01010B0500307E310B300906035504061302564E31333031060355040A0C2A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73311B3019060355040B0C124E6174696F6E616C2043412043656E746572311D301B06035504030C144D4943204E6174696F6E616C20526F6F74204341301E170D3230303130343033303731345A170D3339313233303033303731345A307E310B300906035504061302564E31333031060355040A0C2A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73311B3019060355040B0C124E6174696F6E616C2043412043656E746572311D301B06035504030C144D4943204E6174696F6E616C20526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AA42D28B30B59A92B88DA5BE1495E6C84DD7C91471CAE920CB1DE3F1EE9CDEAA9085C7A82E65DABEA8175A090D5295B64664626660C7C762D11D0ADBD1D8153E341D73DC3BB2F9C83AFFA3EC7C7867E18A072905CB2D76C0A8AB327AF27526A5AF4807CB1C444A88CE3578CAB8EBF29938F0E45737F26D6A78165C86A4F1AFD3BD184BA40F77F811B03C133119AA35B80F0ABF428F652DF57D21E2B871A2C2DDD636464EFA7616F42387D46FC7B9C4DE80BA67A326D89C6F974A38C9FED87DE2826A57FFE59D9ED6F2939BE8799003EF8D5A6C0C5431980EE9CFFF4F704D18B1D236562710BA86922EBACB0F7A113FB913F6905366687ED981E3AE425B6818110203010001A3633061300F0603551D130101FF040530030101FF301F0603551D23041830168014B9E1290686AABAA20AF14EA4E643969397C5DAF4301D0603551D0E04160414B9E1290686AABAA20AF14EA4E643969397C5DAF4300E0603551D0F0101FF040403020186300D06092A864886F70D01010B050003820101000EBF000A3E3D46E870CB6523C861E4ACE53E6B41954A31E0AAC41A06ADD57B1D33E1781F2451AE88B46E502DCD790A093D7F45FE53EC0B8D4352B00C1209AB2C1206C64A761FE2DAA101E5F11F98317547609F1B91249F656D2FA1A491046929A6D324833D7C2B502314E8E5DB9BF5E8EAAB32F2CB0C8E963B8FB801B77924BC6ADE9328487DE8228A4A4032000B25E5EE703C5EEC6481821DAC3A66196923A7AB683D9E8F33440584DED0F168153A3EC9E7B47182D5DD2C8AB6AE0B6F871B9DCAC46BDAC0EF96983427B16E02B5D6B766C0960064C58FD00B82A0F8F86A1923844FFCCE92E8F05D684E2693844BA85F51E8A0E573F0D4C606A273DBE0E144BB | |||
| (PID) Process: | (3384) misaca_vCSP_v1_mgr_update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\B4ACE2818F955776DD675EF360EEC8DE9043C345 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000B4ACE2818F955776DD675EF360EEC8DE9043C34520000000010000003B040000308204373082031FA003020102020A611FA4D4000000000011300D06092A864886F70D0101050500307E310B300906035504061302564E31333031060355040A132A4D696E6973747279206F6620496E666F726D6174696F6E20616E6420436F6D6D756E69636174696F6E73311B3019060355040B13124E6174696F6E616C2043412043656E746572311D301B060355040313144D4943204E6174696F6E616C20526F6F74204341301E170D3139303531303037353330375A170D3234303531303038303330375A3049310B300906035504061302564E310E300C0603550407130548616E6F6931193017060355040A1310426B617620436F72706F726174696F6E310F300D06035504031306426B6176434130820122300D06092A864886F70D01010105000382010F003082010A0282010100C38D8CB6073A39AF7DEF970613A7BAB15B1E1DA5FA62CDA7FA790EB1CC40CF79140D8E6996EBF445837775B6FF24712596C7A2A1BA620BCF365DBDF1115CC910A531AE7AAAB7E731BB77D194964988543C9C438570BE8C6AF4C4D6367AD0B189FF011AA2C75B84D193AC627C9CDDC7128B4ACA66480EAF20465D47649AECC73B55CC93C20637600B860D08AF4958F837429B8B5E79AB1BD2C61D71B503C0724FB60D641097B54F69974B060234706FECB83B8A70BE0117F1A02D0095A1DA6543F31C70665ADC89476587C2E6290CC138466F0D26ED287C6EC1F8D9D982AD6CD9A18A5E6E1CC7813DE713C99EF2B77BAC278F1680E7FDD70996BF1964250512350203010001A381EB3081E830120603551D130101FF040830060101FF020100300B0603551D0F040403020186301D0603551D0E041604141EB00F4897DFD0C367A746843B583B880D539486301F0603551D23041830168014CD6271E461BDFE3DECB24060D38175DD3AAC6BC6303C0603551D1F043530333031A02FA02D862B687474703A2F2F7075626C69632E726F6F7463612E676F762E766E2F63726C2F6D69636E7263612E63726C304706082B06010505070101043B3039303706082B06010505073002862B687474703A2F2F7075626C69632E726F6F7463612E676F762E766E2F6372742F6D69636E7263612E637274300D06092A864886F70D0101050500038201010044828B865C5F73997AC91A80B13F75C26AABAE29A1569EE2B52BA6AFA0F933432AE8ABD8FB510AF6571353A40266763479BD06873C45632C4818687CFDAC71A4FF0BBC53CABADF2ACF5E6EB5CFE5BF5C19DBF680D55B1D34BFCD5EF116C3EC2BDB209C7BC5991372666A026C6C1AE37CA85D65B134F1B1BE25FE8AD7BC5A9AEA048676AF37713DDDEC3F6EFC017D8EACF2317669519EB071067E94410E0DE588AE97869077C066E7786B934771A23B6A5F4017078F5D255E29FA8DEE0940D1858125AB20F0762AEC3A8CFB83B968D5D2D10A4F347178001C5FCBA2D52384839CBBF0F3CFB77E6A9EC0BEC8665EFA9999D7A190586C8FB0FE27856CAEF374A567 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Users\admin\AppData\Local\Temp\nsjEAD7.tmp\System.dll | — | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Users\admin\AppData\Local\Temp\nsjEAD7.tmp\AccessControl.dll | — | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\nssFirefox.dll | executable | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\ProgramData\Microsoft\Crypto\RemoteSigningKSP\MISA-CA\vCSP Manager v1.0\vCSPManager.cfg | text | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\regFirefox.exe | executable | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\regFirefox64.exe | executable | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\lang\vcspmgr_EN.lng | text | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\lang\vcspmgr_VI.lng | text | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\nssFirefox64.dll | executable | |
MD5:— | SHA256:— | |||
| 3384 | misaca_vCSP_v1_mgr_update.exe | C:\Program Files\MISA-CA\vCSP Manager v1.0\misaca_vCSP_v1_uninstaller.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3052 | misaca_vCSP_v1_mgr.exe | GET | — | 14.225.10.71:80 | http://product.misa.com.vn/misasoftware/esign/vcsp/misaca_vCSP_v1_mgr.ini | VN | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3052 | misaca_vCSP_v1_mgr.exe | 14.225.10.71:80 | product.misa.com.vn | VIETNAM POSTS AND TELECOMMUNICATIONS GROUP | VN | malicious |
Domain | IP | Reputation |
|---|---|---|
product.misa.com.vn |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3052 | misaca_vCSP_v1_mgr.exe | A Network Trojan was detected | ET MALWARE Suspicious User Agent (Autoupdate) |