| File name: | HousecallLauncher64.exe |
| Full analysis: | https://app.any.run/tasks/933082fd-e51d-4b33-b3f1-1238ce2a1970 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | December 20, 2024, 12:06:18 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | 45BB33FB54C9ED70DC212E569BB8497C |
| SHA1: | D7AD89CBEE1EB4226352DA47358B927D7EE66F0E |
| SHA256: | 454F6EB6995896870D967BB169DD3ED74C55B2629ABC7F553BEF8FE974092C8A |
| SSDEEP: | 98304:ZeU69y3++14cqt4W7Qz8Pt/u2rk7PpK9OtbS8CXDH3dCfQvx0rSxLyldIfwIfU7l:YXJSJL |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:11:12 07:12:04+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.28 |
| CodeSize: | 483840 |
| InitializedDataSize: | 323072 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x27c34 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.62.1.1180 |
| ProductVersionNumber: | 1.62.1.1180 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Trend Micro Inc. |
| CoverageBuild: | None |
| CompileOption: | None |
| BuildType: | Rel |
| FileDescription: | Trend Micro Application Launcher |
| FileVersion: | 1.62.1.1180 |
| InternalName: | AppLauncher.exe |
| LegalCopyright: | Copyright (C) 2024 Trend Micro Incorporated. All rights reserved. |
| LegalTrademarks: | Copyright (C) Trend Micro Inc. |
| OriginalFileName: | 7zsfx.exe |
| ProductName: | Trend Micro HouseCall |
| ProductVersion: | 1.62 |
| SpecialBuild: | 1180 |
| PrivateBuild: | Build 1180 - None |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2160 | CleanerOneChecker.exe | C:\Program Files\Trend Micro\HouseCall\CleanerOne\CleanerOneChecker.exe | housecall.bin | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2676 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | CleanerOneChecker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4624 | "housecall.bin" A9DB8345 604CD9D | C:\Program Files\Trend Micro\HouseCall\housecall.bin | Setup.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro HouseCall Version: 1.62.1.1180 Modules
| |||||||||||||||
| 6196 | "C:\Program Files\Trend Micro\HouseCall\TisEzIns.exe" /b /u "http://gr.trendmicro.com/GREntry/NonPayment?Target=PROMOTE&PID=HC10&FunID=HouseCallTAVPackage&Locale=EN-US" /f "C:\Program Files\Trend Micro\HouseCall\setup-TAV.exe" | C:\Program Files\Trend Micro\HouseCall\TisEzIns.exe | housecall.bin | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Helps download the Trend Micro software installer Version: 17.6.0.1007 Modules
| |||||||||||||||
| 6204 | "C:\Program Files\Trend Micro\7zS83A9ED33\AU\patch64.exe" "C:\Program Files\Trend Micro\7zS83A9ED33\AU\AU_Data\AU_Temp\6916_6984" 0 | C:\Program Files\Trend Micro\7zS83A9ED33\AU\patch64.exe | Setup.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: patch program Exit code: 0 Version: 2.89.0.1055 Modules
| |||||||||||||||
| 6228 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | patch64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6444 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | hcpackage64.exe.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6532 | exe.exe -y | C:\Program Files\Trend Micro\HCBackup\hcpackage64.exe.tmp | Setup.exe | ||||||||||||
User: admin Company: trend_company_name Integrity Level: HIGH Description: Trend Micro HouseCall Exit code: 0 Version: 1.62.1.1180 Modules
| |||||||||||||||
| 6536 | "C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe" | C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe | — | explorer.exe | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: MEDIUM Description: Trend Micro Application Launcher Exit code: 3221226540 Version: 1.62.1.1180 Modules
| |||||||||||||||
| 6712 | "C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe" | C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe | explorer.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro Application Launcher Exit code: 0 Version: 1.62.1.1180 Modules
| |||||||||||||||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\HouseCall |
| Operation: | write | Name: | VID |
Value: HC202100 | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
| Operation: | delete value | Name: | E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
Value: | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000A7F2E41606411150306B9CE3B49CB0C97E0000000100000008000000000063F58926D701140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8090000000100000022000000302006082B06010505070303060A2B0601040182370A030406082B06010505070308190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D460F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB0B000000010000002A0000005300650063007400690067006F0020002800550054004E0020004F0062006A00650063007400290000006200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F1D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF670868000000010000000800000000409120D035D90120000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 5C00000001000000040000000008000068000000010000000800000000409120D035D9011D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF67086200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F0B000000010000002A0000005300650063007400690067006F0020002800550054004E0020004F0062006A00650063007400290000000F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819090000000100000022000000302006082B06010505070303060A2B0601040182370A030406082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D87E0000000100000008000000000063F58926D701040000000100000010000000A7F2E41606411150306B9CE3B49CB0C920000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
| Operation: | delete value | Name: | 742C3192E607E424EB4549542BE1BBC53E6174E2 |
Value: | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
| Operation: | write | Name: | Blob |
Value: 04000000010000001000000010FC635DF6263E0DF325BE5F79CD67677E0000000100000008000000000010C51E92D2011D000000010000001000000027B3517667331CE2C1E74002B5FF2298620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E7009000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030119000000010000001000000091161B894B117ECDC257628DB460CC04030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E20F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD80B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D00610072007900200043004100000053000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C0140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB69777A000000010000000E000000300C060A2B0601040182375E010268000000010000000800000000003DB65BD9D5012000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64 | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
| Operation: | write | Name: | Blob |
Value: 5C00000001000000040000000004000068000000010000000800000000003DB65BD9D5017A000000010000000E000000300C060A2B0601040182375E0102140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB697753000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C00B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D0061007200790020004300410000000F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD8030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E219000000010000001000000091161B894B117ECDC257628DB460CC0409000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070301620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E701D000000010000001000000027B3517667331CE2C1E74002B5FF22987E0000000100000008000000000010C51E92D20104000000010000001000000010FC635DF6263E0DF325BE5F79CD67672000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64 | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
| Operation: | delete value | Name: | 4F65566336DB6598581D584A596C87934D5F2AB4 |
Value: | |||
| (PID) Process: | (6916) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4 |
| Operation: | write | Name: | Blob |
Value: 5C00000001000000040000000004000019000000010000001000000091161B894B117ECDC257628DB460CC040300000001000000140000004F65566336DB6598581D584A596C87934D5F2AB41D000000010000001000000027B3517667331CE2C1E74002B5FF2298140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB697709000000010000002A000000302806082B0601050507030406082B0601050507030206082B0601050507030306082B060105050703010B000000010000003800000056006500720069005300690067006E00200043006C006100730073002000330020005000720069006D006100720079002000430041000000040000000100000010000000782A02DFDB2E14D5A75F0ADFB68E9C5D0F0000000100000010000000F1BBAC2D9038DDEC8DB173C53BC72A2A2000000001000000410200003082023D308201A6021100E49EFDF33AE80ECFA5113E19A4240232300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3034303130373233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D0101020500038181006170EC2F3F9EFD2BE6685421B06779080C2096318A0D7ABEB626DF792C22694936E397776261A232D77A542136BA02C934E725DA4435B0D25C805DB394F8F9ACEEA460752A1F954923B14A7CF4B34772215B7E97AB54AC62E75DECAE9BD2C9B224FB82ADE967154BBAAAA6F097A0F6B0975700C80C3C09A08204BA41DAF799A4 | |||
| (PID) Process: | (4624) housecall.bin | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\HouseCall_downloader.bmp | binary | |
MD5:50960AC419774A394710258261E2DC8B | SHA256:15224BC0D04B82FBA0DB9AD5D7AC283FF914208B8DF13E2DDDC6DCDEC3D127E9 | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\DLConfig.xml | text | |
MD5:0DEB9AFC00EA164C04E67826DE4575B2 | SHA256:39FDAC3A4B9E43BF1050181DF2A5C659D6B7D9B4E9D919D145588C4C2FA491DE | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\AU\patchw64.dll | executable | |
MD5:B44819BA310A5BE8C2097E71AA5484F4 | SHA256:1E738963B73A25C86AB5329FFA3AF4C86755F12F3F09BF5AC17B4588315412D4 | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\AU\x500_std.db | binary | |
MD5:4A5254761F92EB0FB968421DB26BBB0B | SHA256:48335D3E1165FD3C504845E0BD279436302D9B90DC99C4B6A070302D555D5EAF | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\curl-ca-bundle.crt | text | |
MD5:C658D9F253217D3C010B830D05973BB7 | SHA256:193A35B6DE7EE049FF512599DD4E8290DC30C2F47F9A3818CA8F273FFCA683DB | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\AU\aucfg.ini | binary | |
MD5:B8994884773962713DB9181A52396B87 | SHA256:4C3E192E58A42249C96432828155CA0A54A3D669287444DE655B7564D0C0429E | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\Setup.exe | executable | |
MD5:58A803EB14E06CD60E272E3D455F293A | SHA256:80C9A2F6914401CB8B172B594E8D8F562E1FC367CBA0FE8BCA7E0BF85827BA73 | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\dlstr.xml | xml | |
MD5:60E94A31FA1251D3AA133739D77FA17A | SHA256:14E72CF1853BD1FDDDB5A2FED569CFBA4C406CD704E03F652323EC60DC7FE792 | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\AU\Build64.exe | executable | |
MD5:C6FCFA160487FBA72DC2DB84AC9EEF3A | SHA256:824ABB1E7DA6BBEF6512FFA9D71AF647718425C604308AC1348374E45644845C | |||
| 6712 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS83A9ED33\AU\ciussi64.dll | executable | |
MD5:A32BCF865C1D39D306D9B552C48A9A6F | SHA256:D59AFADF3515DBA5BF2B469CB9C9A0187902A3A9E9E612BBA3FE70A8394A2761 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2356 | svchost.exe | GET | 200 | 23.32.238.107:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.32.238.107:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2356 | svchost.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6916 | Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEALE0eWKSmgMVo2jBH5%2BTV8%3D | unknown | — | — | whitelisted |
6916 | Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm%2FrYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEA6g%2Fk37dMxkvDIUMQPCfIs%3D | unknown | — | — | whitelisted |
6916 | Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAGPQ4h8MGJjpq6bORl%2BDTc%3D | unknown | — | — | whitelisted |
6916 | Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6916 | Setup.exe | HEAD | 200 | 104.81.77.15:80 | http://housecall-ctp-p.activeupdate.trendmicro.com:80/activeupdate/ini_xml.zip | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2356 | svchost.exe | 23.32.238.107:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.32.238.107:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.37.237.227:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2356 | svchost.exe | 23.37.237.227:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.21.110.139:443 | www.bing.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6916 | Setup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6916 | Setup.exe | 23.37.236.105:443 | ti-res.trendmicro.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ti-res.trendmicro.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
housecall-ctp-p.activeupdate.trendmicro.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6916 | Setup.exe | Attempted Administrator Privilege Gain | AV EXPLOIT Potential ZIP file exploiting CVE-2023-36413 |
6916 | Setup.exe | Attempted Administrator Privilege Gain | AV EXPLOIT Potential ZIP file exploiting CVE-2023-36413 |
Process | Message |
|---|---|
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |
CleanerOneChecker.exe | pTuner->Initialize(): 553582592 |