URL: | http://www.3planesoft.com/files/screensavermanager.exe |
Full analysis: | https://app.any.run/tasks/9771ee5b-86d0-45fc-bbae-c2bd4851217c |
Verdict: | Malicious activity |
Analysis date: | January 10, 2019, 00:48:49 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 5F20FB4C44416816F95D0D67D9DF1D63 |
SHA1: | 52BD6DEB246159E890BADDD93086CF96ADB839B4 |
SHA256: | 49D9E3AC978C3731D9AE68537E8074EB6CDE74AFF97570157534C0A02F8D1C09 |
SSDEEP: | 3:N1KJS4SJqKXQKHaELJ:Cc4SJqQPaELJ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
404 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000005D4" "000005D0" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
564 | "C:\Program Files\3Planesoft Screensaver Manager\Configurator.exe" | C:\Program Files\3Planesoft Screensaver Manager\Configurator.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
908 | "C:\Windows\System32\rundll32.exe" shell32.dll,Control_RunDLL desk.cpl,ScreenSaver,@ScreenSaver | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1352 | "C:\Program Files\Winter Walk 3D Screensaver\Winter Walk 3D Screensaver.exe" | C:\Program Files\Winter Walk 3D Screensaver\Winter Walk 3D Screensaver.exe | — | Winter_Walk_3D_Screensaver.scr | |||||||||||
User: admin Company: 3Planesoft Integrity Level: MEDIUM Description: Winter Walk 3D Screensaver Exit code: 0 Version: 1, 0, 0, 3 Modules
| |||||||||||||||
1488 | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr /p 131576 | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr | — | rundll32.exe | |||||||||||
User: admin Company: 3Planesoft Integrity Level: MEDIUM Description: 3Planesoft Screensaver Manager Exit code: 0 Version: 2, 0, 0, 166 Modules
| |||||||||||||||
1528 | "C:\Program Files\Opera\opera.exe" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
1728 | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr /s | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr | rundll32.exe | ||||||||||||
User: admin Company: 3Planesoft Integrity Level: MEDIUM Description: 3Planesoft Screensaver Manager Exit code: 0 Version: 2, 0, 0, 166 Modules
| |||||||||||||||
1932 | "C:\Users\admin\Downloads\screensavermanager.exe" /SPAWNWND=$2015A /NOTIFYWND=$20142 | C:\Users\admin\Downloads\screensavermanager.exe | screensavermanager.tmp | ||||||||||||
User: admin Company: 3Planesoft Integrity Level: HIGH Description: 3Planesoft Screensaver Manager Setup Exit code: 0 Version: 2.0.0.164 Modules
| |||||||||||||||
1980 | "C:\Windows\system32\Winter_Walk_3D_Screensaver.scr" /e | C:\Windows\system32\Winter_Walk_3D_Screensaver.scr | — | 3Planesoft_Screensaver_Manager.scr | |||||||||||
User: admin Company: 3Planesoft Integrity Level: MEDIUM Description: Winter Walk 3D Screensaver Exit code: 0 Version: 1, 0, 0, 3 Modules
| |||||||||||||||
2076 | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr /c | C:\Windows\system32\3Planesoft_Screensaver_Manager.scr | Configurator.exe | ||||||||||||
User: admin Company: 3Planesoft Integrity Level: HIGH Description: 3Planesoft Screensaver Manager Exit code: 0 Version: 2, 0, 0, 166 Modules
|
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | dr |
Value: 1 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | delete value | Name: | 3516-13180984670829101 |
Value: 0 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
Operation: | write | Name: | usagestats |
Value: 0 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | delete value | Name: | 3012-13191554945386750 |
Value: 259 | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | metricsid |
Value: | |||
(PID) Process: | (3012) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | metricsid_installdate |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\7b24d70b-91af-4da9-b195-dea8a7c6f700.tmp | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\4c0b6aef-1033-4add-be39-2e9efe6c5132.tmp | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\fda344b4-bf7d-47a9-bb81-5af6114623c2.tmp | — | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old | text | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
3012 | chrome.exe | C:\Users\admin\Downloads\05be7378-86d5-4180-b72e-0e67061ac530.tmp | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1528 | opera.exe | GET | 200 | 66.225.197.197:80 | http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 543 b | whitelisted |
1528 | opera.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAOXQPQlVpLtFek%2BmcpabOk%3D | US | der | 471 b | whitelisted |
3012 | chrome.exe | GET | 200 | 91.199.212.52:80 | http://crt.comodoca.com/COMODORSAAddTrustCA.crt | GB | der | 1.37 Kb | whitelisted |
3012 | chrome.exe | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/files | US | html | 185 b | unknown |
3012 | chrome.exe | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/files/screensavermanager.exe | US | html | 185 b | unknown |
2076 | 3Planesoft_Screensaver_Manager.scr | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/img/alpinevalley_screen01.jpg | US | html | 185 b | unknown |
2076 | 3Planesoft_Screensaver_Manager.scr | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/img/autumnwalk_screen01.jpg | US | html | 185 b | unknown |
2076 | 3Planesoft_Screensaver_Manager.scr | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/img/humanworld_screen01.jpg | US | html | 185 b | unknown |
2076 | 3Planesoft_Screensaver_Manager.scr | POST | 200 | 216.58.207.46:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
2076 | 3Planesoft_Screensaver_Manager.scr | GET | 301 | 66.55.153.226:80 | http://www.3planesoft.com/img/halloweenevening_screen01.jpg | US | html | 185 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3012 | chrome.exe | 172.217.18.3:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3012 | chrome.exe | 66.55.153.226:80 | www.3planesoft.com | Choopa, LLC | US | unknown |
3012 | chrome.exe | 172.217.16.131:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3012 | chrome.exe | 172.217.21.205:443 | accounts.google.com | Google Inc. | US | whitelisted |
3012 | chrome.exe | 66.55.153.226:443 | www.3planesoft.com | Choopa, LLC | US | unknown |
3012 | chrome.exe | 216.58.206.14:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
3012 | chrome.exe | 91.199.212.52:80 | crt.comodoca.com | Comodo CA Ltd | GB | suspicious |
1528 | opera.exe | 82.145.215.40:443 | certs.opera.com | Opera Software AS | — | whitelisted |
3012 | chrome.exe | 172.217.22.3:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
1528 | opera.exe | 66.225.197.197:80 | crl4.digicert.com | CacheNetworks, Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
clientservices.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
www.3planesoft.com |
| unknown |
accounts.google.com |
| shared |
sb-ssl.google.com |
| whitelisted |
crt.comodoca.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
certs.opera.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl4.digicert.com |
| whitelisted |
Process | Message |
---|---|
DXSETUP.exe | DLL_PROCESS_ATTACH |
DXSETUP.exe | DLL_PROCESS_ATTACH |
DXSETUP.exe | DLL_PROCESS_DETACH |
DXSETUP.exe | DLL_PROCESS_DETACH |