| File name: | eset_smart_security_premium_live_installer.exe |
| Full analysis: | https://app.any.run/tasks/0da0d335-be2a-4d34-ab3d-4dc367e1a248 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | July 09, 2024, 23:42:13 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 90269B072F33779FC479718A2B312E3F |
| SHA1: | 5149127DBBD50C53F8B500331CE77F7DEA8FE05F |
| SHA256: | 4034B408B96A69ADF63D0965D16C1E37D35400316D71FB6204AA75900DC3036E |
| SSDEEP: | 98304:2BWsucxxx5SEVdtuhcd9cOakgHxCd9t2rsJuc4BWVPZQY9q6GRnRgQhsmzBYzHHO:NtsL7g8f573n3F0ttGxDrY |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:21 06:41:39+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 329216 |
| InitializedDataSize: | 9999872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2c230 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.46.7.0 |
| ProductVersionNumber: | 17.2.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | ESET |
| FileDescription: | ESET Live Installer |
| FileVersion: | 10.46.7.0 |
| InternalName: | Bootstrapper.exe |
| LegalCopyright: | Copyright (c) ESET, spol. s r.o. 1992-2024. All rights reserved. |
| LegalTrademarks: | NOD, NOD32, AMON, ESET are registered trademarks of ESET. |
| OriginalFileName: | Bootstrapper.exe |
| ProductName: | ESET Security |
| ProductVersion: | 17.2.1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | InstHelper.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 776 | "C:\Program Files\ESET\ESET Security\ekrn.exe" | C:\Program Files\ESET\ESET Security\ekrn.exe | services.exe | ||||||||||||
User: SYSTEM Company: ESET Integrity Level: SYSTEM Description: ESET Service Version: 10.46.9.0 Modules
| |||||||||||||||
| 1272 | DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv\ehdrv.inf" "9" "446a2f407" "00000000000001E4" "Service-0x0-3e7$\Default" "00000000000001E8" "208" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1440 | C:\Windows\System32\MsiExec.exe -Embedding 36D2DC31E2AE0CFA1A79120CE16A03EE E Global\MSI0000 | C:\Windows\System32\msiexec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1784 | "C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exe" -sd "C:\WINDOWS\Temp\eset\bts.stats" "ESET Security" "17.2.7.0" "13322" | C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exe | — | msiexec.exe | |||||||||||
User: admin Company: ESET Integrity Level: HIGH Description: ESET Install Helper Exit code: 0 Version: 10.46.9.0 Modules
| |||||||||||||||
| 2056 | "C:\Program Files\ESET\ESET Security\eComServer.exe" /RegServer | C:\Program Files\ESET\ESET Security\eComServer.exe | — | ekrn.exe | |||||||||||
User: SYSTEM Company: ESET Integrity Level: SYSTEM Description: ESET COM Server Exit code: 0 Version: 10.46.9.0 Modules
| |||||||||||||||
| 2060 | DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt\ekbdflt.inf" "9" "4f39970b7" "00000000000001E8" "Service-0x0-3e7$\Default" "0000000000000200" "208" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2216 | DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\eamonm\eamonm.inf" "9" "4d14d0413" "000000000000021C" "Service-0x0-3e7$\Default" "0000000000000224" "208" "C:\Program Files\ESET\ESET Security\Drivers\eamonm" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2648 | "C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe" --bts-container 3968 "C:\Users\admin\Desktop\eset_smart_security_premium_live_installer.exe" | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe | eset_smart_security_premium_live_installer.exe | ||||||||||||
User: admin Company: ESET Integrity Level: HIGH Description: ESET Live Installer Exit code: 0 Version: 10.46.7.0 Modules
| |||||||||||||||
| 2808 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | InstHelper.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3968) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3968) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3968) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3968) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2648) eset_smart_security_premium_live_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ESET\ESET Security\CurrentVersion\Plugins\01000400\settings |
| Operation: | write | Name: | LastUpdateCertTimestamp |
Value: F996765100000000 | |||
| (PID) Process: | (3584) slui.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\sppcomapi.dll,-3200 |
Value: Software Licensing | |||
| (PID) Process: | (2648) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ESET\Setup |
| Operation: | delete value | Name: | CAError |
Value: | |||
| (PID) Process: | (2648) eset_smart_security_premium_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ESET\Setup |
| Operation: | delete value | Name: | CADuration |
Value: | |||
| (PID) Process: | (7068) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ESET\Setup |
| Operation: | write | Name: | CAError |
Value: InstSupp!caLoadInstallIni=1627;CA| | |||
| (PID) Process: | (7068) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ESET\Setup |
| Operation: | delete value | Name: | CAError |
Value: InstSupp!caLoadInstallIni=1627;CA| | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l1.dll.nup | — | |
MD5:— | SHA256:— | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l2.dll.nup | — | |
MD5:— | SHA256:— | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l1.dll.nup | — | |
MD5:— | SHA256:— | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l2.dll.nup | — | |
MD5:— | SHA256:— | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\sciter-x.dll | executable | |
MD5:DBC44FBEEEEE77146D0DF69D6CAB0719 | SHA256:A4E88C2BB1884D95F7DB62B8FEE3B6F397C2509D69AF6FFE4F5F0590032A7D65 | |||
| 3968 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe | executable | |
MD5:E153DA862353C9674277F78F237A6125 | SHA256:3FB5984FC68C755A70D3ECBA65D4D236A3BF2AC6467CB9BF426B61DE085BB1AC | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\updater.dll | executable | |
MD5:F0DF17D9812FDFC8E4FA27C8E2D7F2E9 | SHA256:50B234A43D10AB6D1744CB1CABC752467435C352C40F0C648EB2572A3D4A7456 | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eguiActivation.dll | executable | |
MD5:7BDADCF008F23AD60DE94D504001D6A8 | SHA256:53ADF956388C1FF291BF9346D4B500F8F0ECDC0C2380A7641030E461AAFCBEB7 | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\.erm\epi-base.zip | compressed | |
MD5:F79345477E645F60197C1C0F631BE822 | SHA256:5F678A620694E3BC47DC3C46CB229096376380D531169741D3C0177AE5CD0F74 | |||
| 2648 | eset_smart_security_premium_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eguiActivationLang.dll | executable | |
MD5:747739AC01C410790893CC9A9C95CE7D | SHA256:6131BD39CD4342621573EB837A9DF252901AE7D99FD4EC62A60CFC7D589F9116 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3040 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
2648 | eset_smart_security_premium_live_installer.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAkO6MXeW%2Fpi0q4v9wl8SFc%3D | unknown | — | — | unknown |
2648 | eset_smart_security_premium_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repository.eset.com/v1/connectivity_check | unknown | — | — | unknown |
2648 | eset_smart_security_premium_live_installer.exe | GET | 302 | 91.228.166.23:80 | http://repository.eset.com/v1/com/eset/apps/home/security/windows/metadata3 | unknown | — | — | unknown |
4392 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
2648 | eset_smart_security_premium_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repositorynocdn.eset.com/v1/com/eset/apps/home/security/windows/metadata3.default | unknown | — | — | unknown |
4392 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | unknown |
2648 | eset_smart_security_premium_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repository.eset.com/v1/com/eset/apps/home/security/windows/v17/17.2.7.0/ehs_nt64.msi.eula/manifest.erm | unknown | — | — | unknown |
3540 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4392 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2204 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3676 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2648 | eset_smart_security_premium_live_installer.exe | 91.228.166.23:80 | repository.eset.com | ESET, spol. s r.o. | SK | unknown |
2648 | eset_smart_security_premium_live_installer.exe | 138.91.165.201:443 | iploc.eset.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4392 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4392 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
4392 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
repository.eset.com |
| unknown |
iploc.eset.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
repositorynocdn.eset.com |
| unknown |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |