| File name: | epi_win_live_installer.exe |
| Full analysis: | https://app.any.run/tasks/7cc44725-f7c0-43c3-a90c-7a206eff498f |
| Verdict: | Malicious activity |
| Analysis date: | August 06, 2024, 21:18:28 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 10817751B3C4691911988BE50B035E12 |
| SHA1: | EAB518B4D17BEDC401131E4F3F33373543BF45EC |
| SHA256: | 43A452531DA95BB0D8400B279FC3EE79C984B847492767813171EF722CE6608F |
| SSDEEP: | 196608:D618bSrM0Zh6nQod1bZNX34IW9DovWWSVn:6rf2t/XYlX |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:20 10:13:20+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.37 |
| CodeSize: | 327680 |
| InitializedDataSize: | 14536704 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2bd60 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.43.0.0 |
| ProductVersionNumber: | 4.2.9.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | ESET |
| FileDescription: | ESET Security |
| FileVersion: | 10.43.0.0 |
| InternalName: | Bootstrapper.exe |
| LegalCopyright: | Copyright (c) ESET, spol. s r.o. 1992-2023. All rights reserved. |
| LegalTrademarks: | NOD, NOD32, AMON, ESET are registered trademarks of ESET. |
| OriginalFileName: | Bootstrapper.exe |
| ProductName: | ESET Security |
| ProductVersion: | 4.2.9.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6492 | "C:\Users\admin\AppData\Local\Temp\epi_win_live_installer.exe" | C:\Users\admin\AppData\Local\Temp\epi_win_live_installer.exe | explorer.exe | ||||||||||||
User: admin Company: ESET Integrity Level: MEDIUM Description: ESET Security Version: 10.43.0.0 Modules
| |||||||||||||||
| 6592 | "C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\epi_win_live_installer.exe" --bts-container 6492 "C:\Users\admin\AppData\Local\Temp\epi_win_live_installer.exe" | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\epi_win_live_installer.exe | epi_win_live_installer.exe | ||||||||||||
User: admin Company: ESET Integrity Level: HIGH Description: ESET Security Version: 10.43.0.0 Modules
| |||||||||||||||
| 6648 | "C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\BootHelper.exe" --watchdog 6592 --product "ESET Package Installer" 4.2.9.0 1033 | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\BootHelper.exe | — | epi_win_live_installer.exe | |||||||||||
User: admin Company: ESET Integrity Level: HIGH Description: ESET Security Version: 10.43.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6492) epi_win_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6492) epi_win_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6492) epi_win_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6492) epi_win_live_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\.erm\epi-base.zip | compressed | |
MD5:4ABAB3FB3A0F0FE1DF437C36466FF8C1 | SHA256:F205AE1A0B24838C7C39345098AB23EEF7910C6E18BD863A199279BFB17530DC | |||
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\.bts\token-related-epi.dat | compressed | |
MD5:DD9166D6BA9529997431F3F7C3E12466 | SHA256:C9696F211CD18F5EBD5A2D8B972451398EF28DA6A8C68C0FA1AF5E1EEE3C7046 | |||
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\acstest.exe | executable | |
MD5:0E78E89C9F55AD01B72F5BE795B18795 | SHA256:B33C79EE3B195AD49128806A19EAA3721D61CB337481265E0E7294864EE74259 | |||
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\sciter-x.dll | executable | |
MD5:3C07759621FFD37FFBFE83C9BA4EE993 | SHA256:83068360C6ADF88F9537C5B7AC4F753778C95026FDDC29B739CFD74A107375E7 | |||
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\plgInstaller.dll | executable | |
MD5:AAD421B1254C0DAAF512538E2746179D | SHA256:E5070611200AD4EE4B61E8BD7E69C6DD4051241FB18CEA6D5EDEDA5E6993C409 | |||
| 6592 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\BootHelper.exe | executable | |
MD5:659A42D3D572C037A7CB253C4D7D7838 | SHA256:86470553324A23D63B7E726D64C9F211F89A13392F3275ECE2B6DBE94D31BEBE | |||
| 6492 | epi_win_live_installer.exe | C:\Users\admin\AppData\Local\Temp\eset\bts.session\54943f63-fa29-4fa3-821b-6cf749b3bdf0\epi_win_live_installer.exe | executable | |
MD5:ACA387DE92F5E1DC4250282DC3F4F7D4 | SHA256:9B7126EC995CED82F5A5154222F4709E885BD1A9EAA6DB5F38AE4CEBC25909D7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6592 | epi_win_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repository.eset.com/v1/connectivity_check | unknown | — | — | whitelisted |
6592 | epi_win_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repositorynocdn.eset.com/v1/com/eset/apps/business/era/agent/metadata3.default | unknown | — | — | whitelisted |
6592 | epi_win_live_installer.exe | GET | 200 | 91.228.166.23:80 | http://repository.eset.com/v1/com/eset/apps/business/eei/agent/metadata3 | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3812 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6956 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7012 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6592 | epi_win_live_installer.exe | GET | 302 | 91.228.166.23:80 | http://repository.eset.com/v1/com/eset/apps/business/era/agent/metadata3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1928 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5240 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6592 | epi_win_live_installer.exe | 91.228.166.23:80 | repository.eset.com | ESET, spol. s r.o. | SK | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
6592 | epi_win_live_installer.exe | 23.99.12.158:443 | edf.eset.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6592 | epi_win_live_installer.exe | 138.91.165.201:443 | iploc.eset.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
5336 | SearchApp.exe | 95.100.146.24:443 | www.bing.com | Akamai International B.V. | CZ | unknown |
Domain | IP | Reputation |
|---|---|---|
repository.eset.com |
| unknown |
edf.eset.com |
| unknown |
settings-win.data.microsoft.com |
| unknown |
iploc.eset.com |
| unknown |
repositorynocdn.eset.com |
| unknown |
www.bing.com |
| unknown |
ocsp.digicert.com |
| unknown |
client.wns.windows.com |
| unknown |
login.live.com |
| unknown |
th.bing.com |
| unknown |