File name:

eset_smart_security_premium_live_installer.exe

Full analysis: https://app.any.run/tasks/0da0d335-be2a-4d34-ab3d-4dc367e1a248
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 09, 2024, 23:42:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

90269B072F33779FC479718A2B312E3F

SHA1:

5149127DBBD50C53F8B500331CE77F7DEA8FE05F

SHA256:

4034B408B96A69ADF63D0965D16C1E37D35400316D71FB6204AA75900DC3036E

SSDEEP:

98304:2BWsucxxx5SEVdtuhcd9cOakgHxCd9t2rsJuc4BWVPZQY9q6GRnRgQhsmzBYzHHO:NtsL7g8f573n3F0ttGxDrY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 6712)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Executable content was dropped or overwritten

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Reads the date of Windows installation

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Connects to unusual port

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • ekrn.exe (PID: 776)
    • The process verifies whether the antivirus software is installed

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 1440)
      • InstHelper.exe (PID: 5952)
      • drvinst.exe (PID: 6440)
      • efwd.exe (PID: 6504)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • eComServer.exe (PID: 2056)
      • drvinst.exe (PID: 6212)
      • eguiProxy.exe (PID: 4104)
      • egui.exe (PID: 3948)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6712)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 1440)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6712)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6712)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6712)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 1440)
      • ekrn.exe (PID: 776)
    • Executes as Windows Service

      • ekrn.exe (PID: 776)
      • efwd.exe (PID: 6504)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6440)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
    • Creates or modifies Windows services

      • ekrn.exe (PID: 776)
  • INFO

    • Reads the computer name

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • InstHelper.exe (PID: 5952)
      • ekrn.exe (PID: 776)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • eComServer.exe (PID: 2056)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 6212)
      • eguiProxy.exe (PID: 4104)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
      • egui.exe (PID: 3948)
    • Checks supported languages

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 6712)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • BootHelper.exe (PID: 3748)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • InstHelper.exe (PID: 5952)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6440)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 6212)
      • eComServer.exe (PID: 2056)
      • InstHelper.exe (PID: 5968)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
      • eguiProxy.exe (PID: 4104)
      • egui.exe (PID: 3948)
    • Process checks computer location settings

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • msiexec.exe (PID: 1440)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
    • Dropped object may contain TOR URL's

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
    • Create files in a temporary directory

      • eset_smart_security_premium_live_installer.exe (PID: 3968)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1440)
      • InstHelper.exe (PID: 1784)
      • BootHelper.exe (PID: 6360)
    • Reads the software policy settings

      • slui.exe (PID: 4400)
      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • drvinst.exe (PID: 6440)
      • drvinst.exe (PID: 1272)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6212)
      • slui.exe (PID: 3584)
    • Reads the machine GUID from the registry

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • InstHelper.exe (PID: 5952)
      • drvinst.exe (PID: 6440)
      • efwd.exe (PID: 6504)
      • drvinst.exe (PID: 1272)
      • ekrn.exe (PID: 776)
      • drvinst.exe (PID: 6800)
      • drvinst.exe (PID: 2060)
      • drvinst.exe (PID: 2216)
      • drvinst.exe (PID: 5504)
      • drvinst.exe (PID: 6212)
    • Checks proxy server information

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • slui.exe (PID: 3584)
    • Creates files or folders in the user directory

      • eset_smart_security_premium_live_installer.exe (PID: 2648)
      • msiexec.exe (PID: 6712)
      • ekrn.exe (PID: 776)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 1440)
      • msiexec.exe (PID: 7068)
    • Application launched itself

      • msiexec.exe (PID: 6712)
    • Reads Environment values

      • msiexec.exe (PID: 7068)
    • Creates files in the program directory

      • ekrn.exe (PID: 776)
    • Reads Microsoft Office registry keys

      • ekrn.exe (PID: 776)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6712)
      • msiexec.exe (PID: 1440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:21 06:41:39+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.39
CodeSize: 329216
InitializedDataSize: 9999872
UninitializedDataSize: -
EntryPoint: 0x2c230
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.46.7.0
ProductVersionNumber: 17.2.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: ESET
FileDescription: ESET Live Installer
FileVersion: 10.46.7.0
InternalName: Bootstrapper.exe
LegalCopyright: Copyright (c) ESET, spol. s r.o. 1992-2024. All rights reserved.
LegalTrademarks: NOD, NOD32, AMON, ESET are registered trademarks of ESET.
OriginalFileName: Bootstrapper.exe
ProductName: ESET Security
ProductVersion: 17.2.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
30
Malicious processes
17
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eset_smart_security_premium_live_installer.exe eset_smart_security_premium_live_installer.exe boothelper.exe no specs sppextcomobj.exe no specs slui.exe slui.exe msiexec.exe msiexec.exe msiexec.exe taskkill.exe no specs conhost.exe no specs insthelper.exe no specs conhost.exe no specs ekrn.exe drvinst.exe efwd.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe ecomserver.exe no specs drvinst.exe insthelper.exe no specs conhost.exe no specs insthelper.exe no specs conhost.exe no specs boothelper.exe eguiproxy.exe no specs egui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstHelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
776"C:\Program Files\ESET\ESET Security\ekrn.exe"C:\Program Files\ESET\ESET Security\ekrn.exe
services.exe
User:
SYSTEM
Company:
ESET
Integrity Level:
SYSTEM
Description:
ESET Service
Version:
10.46.9.0
Modules
Images
c:\program files\eset\eset security\ekrn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\user32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
1272DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv\ehdrv.inf" "9" "446a2f407" "00000000000001E4" "Service-0x0-3e7$\Default" "00000000000001E8" "208" "C:\Program Files\ESET\ESET Security\Drivers\ehdrv"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1440C:\Windows\System32\MsiExec.exe -Embedding 36D2DC31E2AE0CFA1A79120CE16A03EE E Global\MSI0000C:\Windows\System32\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1784"C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exe" -sd "C:\WINDOWS\Temp\eset\bts.stats" "ESET Security" "17.2.7.0" "13322"C:\Users\admin\AppData\Local\Temp\eset.temp\{02D83BBE-2ABE-C9A2-54C4-0DCDED3C8AE2}\InstHelper.exemsiexec.exe
User:
admin
Company:
ESET
Integrity Level:
HIGH
Description:
ESET Install Helper
Exit code:
0
Version:
10.46.9.0
Modules
Images
c:\users\admin\appdata\local\temp\eset.temp\{02d83bbe-2abe-c9a2-54c4-0dcded3c8ae2}\insthelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2056"C:\Program Files\ESET\ESET Security\eComServer.exe" /RegServerC:\Program Files\ESET\ESET Security\eComServer.exeekrn.exe
User:
SYSTEM
Company:
ESET
Integrity Level:
SYSTEM
Description:
ESET COM Server
Exit code:
0
Version:
10.46.9.0
Modules
Images
c:\program files\eset\eset security\ecomserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2060DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt\ekbdflt.inf" "9" "4f39970b7" "00000000000001E8" "Service-0x0-3e7$\Default" "0000000000000200" "208" "C:\Program Files\ESET\ESET Security\Drivers\ekbdflt"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2216DrvInst.exe "4" "9" "C:\Program Files\ESET\ESET Security\Drivers\eamonm\eamonm.inf" "9" "4d14d0413" "000000000000021C" "Service-0x0-3e7$\Default" "0000000000000224" "208" "C:\Program Files\ESET\ESET Security\Drivers\eamonm"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2648"C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe" --bts-container 3968 "C:\Users\admin\Desktop\eset_smart_security_premium_live_installer.exe" C:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe
eset_smart_security_premium_live_installer.exe
User:
admin
Company:
ESET
Integrity Level:
HIGH
Description:
ESET Live Installer
Exit code:
0
Version:
10.46.7.0
Modules
Images
c:\users\admin\appdata\local\temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
2808\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstHelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
52 134
Read events
51 260
Write events
844
Delete events
30

Modification events

(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3968) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ESET\ESET Security\CurrentVersion\Plugins\01000400\settings
Operation:writeName:LastUpdateCertTimestamp
Value:
F996765100000000
(PID) Process:(3584) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CAError
Value:
(PID) Process:(2648) eset_smart_security_premium_live_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CADuration
Value:
(PID) Process:(7068) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:writeName:CAError
Value:
InstSupp!caLoadInstallIni=1627;CA|
(PID) Process:(7068) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\ESET\Setup
Operation:delete valueName:CAError
Value:
InstSupp!caLoadInstallIni=1627;CA|
Executable files
282
Suspicious files
123
Text files
118
Unknown types
17

Dropped files

PID
Process
Filename
Type
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l1.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em000_32_l2.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l1.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\em045_32_l2.dll.nup
MD5:
SHA256:
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\sciter-x.dllexecutable
MD5:DBC44FBEEEEE77146D0DF69D6CAB0719
SHA256:A4E88C2BB1884D95F7DB62B8FEE3B6F397C2509D69AF6FFE4F5F0590032A7D65
3968eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eset_smart_security_premium_live_installer.exeexecutable
MD5:E153DA862353C9674277F78F237A6125
SHA256:3FB5984FC68C755A70D3ECBA65D4D236A3BF2AC6467CB9BF426B61DE085BB1AC
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\updater.dllexecutable
MD5:F0DF17D9812FDFC8E4FA27C8E2D7F2E9
SHA256:50B234A43D10AB6D1744CB1CABC752467435C352C40F0C648EB2572A3D4A7456
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eguiActivation.dllexecutable
MD5:7BDADCF008F23AD60DE94D504001D6A8
SHA256:53ADF956388C1FF291BF9346D4B500F8F0ECDC0C2380A7641030E461AAFCBEB7
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\.erm\epi-base.zipcompressed
MD5:F79345477E645F60197C1C0F631BE822
SHA256:5F678A620694E3BC47DC3C46CB229096376380D531169741D3C0177AE5CD0F74
2648eset_smart_security_premium_live_installer.exeC:\Users\admin\AppData\Local\Temp\eset\bts.session\3cc703c8-84e5-4045-af74-19ab8b531343\eguiActivationLang.dllexecutable
MD5:747739AC01C410790893CC9A9C95CE7D
SHA256:6131BD39CD4342621573EB837A9DF252901AE7D99FD4EC62A60CFC7D589F9116
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
101
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAkO6MXeW%2Fpi0q4v9wl8SFc%3D
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repository.eset.com/v1/connectivity_check
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
302
91.228.166.23:80
http://repository.eset.com/v1/com/eset/apps/home/security/windows/metadata3
unknown
unknown
4392
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repositorynocdn.eset.com/v1/com/eset/apps/home/security/windows/metadata3.default
unknown
unknown
4392
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
2648
eset_smart_security_premium_live_installer.exe
GET
200
91.228.166.23:80
http://repository.eset.com/v1/com/eset/apps/home/security/windows/v17/17.2.7.0/ehs_nt64.msi.eula/manifest.erm
unknown
unknown
3540
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4392
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
2204
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3676
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2648
eset_smart_security_premium_live_installer.exe
91.228.166.23:80
repository.eset.com
ESET, spol. s r.o.
SK
unknown
2648
eset_smart_security_premium_live_installer.exe
138.91.165.201:443
iploc.eset.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4392
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4392
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4392
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
repository.eset.com
  • 91.228.166.23
unknown
iploc.eset.com
  • 138.91.165.201
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 52.137.106.217
  • 51.124.78.146
whitelisted
repositorynocdn.eset.com
  • 91.228.166.23
unknown
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.140
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.72
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 2.19.105.250
whitelisted

Threats

No threats detected
No debug info