File name:

eset_smart_security_premium_live_installer.exe

Full analysis: https://app.any.run/tasks/0da0d335-be2a-4d34-ab3d-4dc367e1a248
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 09, 2024, 23:42:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

90269B072F33779FC479718A2B312E3F

SHA1:

5149127DBBD50C53F8B500331CE77F7DEA8FE05F

SHA256:

4034B408B96A69ADF63D0965D16C1E37D35400316D71FB6204AA75900DC3036E

SSDEEP:

98304:2BWsucxxx5SEVdtuhcd9cOakgHxCd9t2rsJuc4BWVPZQY9q6GRnRgQhsmzBYzHHO:NtsL7g8f573n3F0ttGxDrY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 6712)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Reads the date of Windows installation

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Executable content was dropped or overwritten

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Connects to unusual port

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • ekrn.exe (PID: 776)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6712)
    • The process verifies whether the antivirus software is installed

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • InstHelper.exe (PID: 5952)
      • msiexec.exe (PID: 1440)
      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • msiexec.exe (PID: 6712)
      • eComServer.exe (PID: 2056)
      • drvinst.exe (PID: 6212)
      • eguiProxy.exe (PID: 4104)
      • egui.exe (PID: 3948)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 1440)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6712)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6712)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 1440)
      • ekrn.exe (PID: 776)
    • Executes as Windows Service

      • ekrn.exe (PID: 776)
      • efwd.exe (PID: 6504)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6712)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Creates or modifies Windows services

      • ekrn.exe (PID: 776)
  • INFO

    • Checks supported languages

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • BootHelper.exe (PID: 3748)
      • msiexec.exe (PID: 1440)
      • msiexec.exe (PID: 7068)
      • InstHelper.exe (PID: 5952)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6440)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
      • eComServer.exe (PID: 2056)
      • eguiProxy.exe (PID: 4104)
      • InstHelper.exe (PID: 5968)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
      • egui.exe (PID: 3948)
    • Reads the computer name

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 1440)
      • msiexec.exe (PID: 7068)
      • InstHelper.exe (PID: 5952)
      • ekrn.exe (PID: 776)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • eComServer.exe (PID: 2056)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 6212)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
      • eguiProxy.exe (PID: 4104)
      • egui.exe (PID: 3948)
    • Process checks computer location settings

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Create files in a temporary directory

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
    • Dropped object may contain TOR URL's

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
    • Reads the machine GUID from the registry

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • InstHelper.exe (PID: 5952)
      • drvinst.exe (PID: 6440)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 1272)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Reads the software policy settings

      • msiexec.exe (PID: 6712)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • slui.exe (PID: 4400)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
      • slui.exe (PID: 3584)
      • ekrn.exe (PID: 776)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6712)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • ekrn.exe (PID: 776)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
    • Checks proxy server information

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • slui.exe (PID: 3584)
    • Application launched itself

      • msiexec.exe (PID: 6712)
    • Reads Environment values

      • msiexec.exe (PID: 7068)
    • Creates files in the program directory

      • ekrn.exe (PID: 776)
    • Reads Microsoft Office registry keys

      • ekrn.exe (PID: 776)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 1440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:21 06:41:39+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.39
CodeSize: 329216
InitializedDataSize: 9999872
UninitializedDataSize: -
EntryPoint: 0x2c230
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.46.7.0
ProductVersionNumber: 17.2.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: ESET
FileDescription: ESET Live Installer
FileVersion: 10.46.7.0
InternalName: Bootstrapper.exe
LegalCopyright: Copyright (c) ESET, spol. s r.o. 1992-2024. All rights reserved.
LegalTrademarks: NOD, NOD32, AMON, ESET are registered trademarks of ESET.
OriginalFileName: Bootstrapper.exe
ProductName: ESET Security
ProductVersion: 17.2.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
30
Malicious processes
17
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eset_smart_security_premium_live_installer.exe eset_smart_security_premium_live_installer.exe boothelper.exe no specs sppextcomobj.exe no specs slui.exe slui.exe msiexec.exe msiexec.exe msiexec.exe taskkill.exe no specs conhost.exe no specs insthelper.exe no specs conhost.exe no specs ekrn.exe drvinst.exe efwd.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe ecomserver.exe no specs drvinst.exe insthelper.exe no specs conhost.exe no specs insthelper.exe no specs conhost.exe no specs boothelper.exe eguiproxy.exe no specs egui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstHelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
776"C:\Program Files\ESET\ESET Security\ekrn.exe"C:\Program Files\ESET\ESET Security\ekrn.exe
services.exe
User:
SYSTEM
Company:
ESET
Integrity Level:
SYSTEM
Description:
ESET Service
Version:
10.46.9.0
Modules
Images
c:\program files\eset\eset security\ekrn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\user32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
1272DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv\ehdrv.inf" "9" "446a2f407" "00000000000001E4" "Service-0x0-3e7$\Default" "00000000000001E8" "208" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1440C:\Windows\System32\MsiExec.exe -Embedding 36D2DC31E2AE0CFA1A79120CE16A03EE E Global\MSI0000C:\Windows\System32\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1784"C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exe" -sd "C:\WINDOWS\Temp\eset\bts.stats" "ESET Security" "17.2.7.0" "13322"C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exemsiexec.exe
User:
admin
Company:
ESET
Integrity Level:
HIGH
Description:
ESET Install Helper
Exit code:
0
Version:
10.46.9.0
Modules
Images
c:\users\admin\appdata\local\temp\eset.temp\{02d83bbe-2abe-c9a2-54c4-0dcded3c8ae2}\insthelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2056"C:\Program Files\ESET\ESET Security\eComServer.exe" /RegServerC:\Program Files\ESET\ESET Security\eComServer.exeekrn.exe
User:
SYSTEM
Company:
ESET
Integrity Level:
SYSTEM
Description:
ESET COM Server
Exit code:
0
Version:
10.46.9.0
Modules
Images
c:\program files\eset\eset security\ecomserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2060DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt\ekbdflt.inf" "9" "4f39970b7" "00000000000001E8" "Service-0x0-3e7$\Default" "0000000000000200" "208" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2216DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\eamonm\eamonm.inf" "9" "4d14d0413" "000000000000021C" "Service-0x0-3e7$\Default" "0000000000000224" "208" "C:\Program Files\ESET\ESET Security\Drivers\eamonm"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2648"C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe" --bts-container 3968 "C:\Users\admin\Desktop\eset_smart_security_premium_live_installer.exe" C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe
eset_smart_security_premium_live_installer.exe
User:
admin
Company:
ESET
Integrity Level:
HIGH
Description:
ESET Live Installer
Exit code:
0
Version:
10.46.7.0
Modules
Images
c:\users\admin\appdata\local\temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
2808\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstHelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
52 134
Read events
51 260
Write events
844
Delete events
30

Modification events

(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ESET\ESET Security\CurrentVersion\Plugins\01000400\settings
Operation:writeName:LastUpdateCertTimestamp
Value:
F996765100000000
(PID) Process:(3584) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CAError
Value:
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CADuration
Value:
(PID) Process:(7068) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:writeName:CAError
Value:
InstSupp!caLoadInstallIni=1627;CA|
(PID) Process:(7068) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CAError
Value:
InstSupp!caLoadInstallIni=1627;CA|
Executable files
282
Suspicious files
123
Text files
118
Unknown types
17

Dropped files

PID
Process
Filename
Type
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l1.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l2.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l1.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l2.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\plgInstaller.dllexecutable
MD5:9AA52A652578DB9EC5519DD59F6EC5F0
SHA256:7D3CB4DCB93FA7F99A2CDE9248875A2F35BA10EC96A8C9A4D2813797A05FFDCA
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\sciter-x.dllexecutable
MD5:DBC44FBEEEEE77146D0DF69D6CAB0719
SHA256:A4E88C2BB1884D95F7DB62B8FEE3B6F397C2509D69AF6FFE4F5F0590032A7D65
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em024_32_l2.dll.nupbinary
MD5:5D9D3D99466999C9143AF77E8101CFED
SHA256:18B1951FC8E89A7431164F93A1F25DBD7CAC26DFA41EAE49A069F6D3CCFC22C7
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em024_32_l1.dll.nupbinary
MD5:9220A1EEFB490142F73EE008F23267C3
SHA256:CEC28BDA6F47C9BFFF188A3B389AB212DC87585622402A733A83BA788B0D489B
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\acstest.exeexecutable
MD5:0E78E89C9F55AD01B72F5BE795B18795
SHA256:B33C79EE3B195AD49128806A19EAA3721D61CB337481265E0E7294864EE74259
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l0.dll.nupbinary
MD5:A79E1E307328378CE988DE58D95A13FD
SHA256:52D4A21F65EE7C4B38EBDE80D30FD95538FDE052792BF6DDB4871281F5AECA9F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
101
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repository.eset.com/v1/connectivity_check
unknown
unknown
4392
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repositorynocdn.eset.com/v1/com/eset/apps/home/security/windows/metadata3.default
unknown
unknown
4392
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
302
91.228.166.23:80
http://repository.eset.com/v1/com/eset/apps/home/security/windows/metadata3
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repository.eset.com/v1/com/eset/apps/home/security/windows/v17/17.2.7.0/ehs_nt64.msi.eula/manifest.erm
unknown
unknown
3540
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
780
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repository.eset.com/v1/com/eset/eulas/product/lg/ehsw/metadata3
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4392
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
2204
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3676
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2648
eset_smart_security_premium_live_installer.exe
91.228.166.23:80
repository.eset.com
ESET, spol. s r.o.
SK
unknown
2648
eset_smart_security_premium_live_installer.exe
138.91.165.201:443
iploc.eset.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4392
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4392
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4392
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
repository.eset.com
  • 91.228.166.23
unknown
iploc.eset.com
  • 138.91.165.201
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 52.137.106.217
  • 51.124.78.146
whitelisted
repositorynocdn.eset.com
  • 91.228.166.23
unknown
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.140
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.72
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 2.19.105.250
whitelisted

Threats

No threats detected
No debug info