URL:

https://online.qbyte.com/CitrixReceiver.exe

Full analysis: https://app.any.run/tasks/96b2ee9e-4b86-4432-ba2f-2bc58be9f73c
Verdict: Malicious activity
Analysis date: March 11, 2020, 03:59:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

83A7ACA87AD99F5648EAAE54F73D4C37

SHA1:

372A887DCCC721899BE79E91874636C9454BF58C

SHA256:

4E6D5ADFF60E75B2F83544A46C9E7D454DBF88909940A5CD3DBBD45796341791

SSDEEP:

3:N8CIjAK5GA4Cn:2CsA04C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CitrixReceiver.exe (PID: 1876)
      • CitrixReceiver.exe (PID: 3364)
      • TrolleyExpress.exe (PID: 3528)
      • SetIntegrityLevel.exe (PID: 3836)
      • concentr.exe (PID: 2884)
      • SetIntegrityLevel.exe (PID: 1676)
      • wfcrun32.exe (PID: 3228)
      • usbinst.exe (PID: 3148)
      • usbinst.exe (PID: 2816)
      • usbinst.exe (PID: 2904)
      • Receiver.exe (PID: 3104)
      • ceip.exe (PID: 2228)
      • icaconf.exe (PID: 2652)
      • SelfService.exe (PID: 1156)
      • SelfServicePlugin.exe (PID: 836)
      • concentr.exe (PID: 2060)
      • ConfigurationWizard.exe (PID: 3224)
      • redirector.exe (PID: 3752)
    • Loads dropped or rewritten executable

      • TrolleyExpress.exe (PID: 3528)
      • rundll32.exe (PID: 3576)
      • concentr.exe (PID: 2060)
      • Receiver.exe (PID: 3104)
      • MsiExec.exe (PID: 3784)
      • concentr.exe (PID: 2884)
      • redirector.exe (PID: 3752)
      • icaconf.exe (PID: 2652)
      • SelfService.exe (PID: 1156)
      • SelfServicePlugin.exe (PID: 836)
      • ConfigurationWizard.exe (PID: 3224)
      • wfcrun32.exe (PID: 3228)
    • Changes settings of System certificates

      • TrolleyExpress.exe (PID: 3528)
    • Changes the autorun value in the registry

      • usbinst.exe (PID: 2816)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3352)
      • CitrixReceiver.exe (PID: 3364)
      • concentr.exe (PID: 2060)
      • wfcrun32.exe (PID: 3228)
      • usbinst.exe (PID: 3148)
      • DrvInst.exe (PID: 2772)
      • usbinst.exe (PID: 2904)
      • usbinst.exe (PID: 2816)
      • SelfService.exe (PID: 1156)
      • SelfServicePlugin.exe (PID: 836)
      • TrolleyExpress.exe (PID: 3528)
      • ConfigurationWizard.exe (PID: 3224)
      • msiexec.exe (PID: 3324)
    • Creates COM task schedule object

      • msiexec.exe (PID: 3324)
      • MsiExec.exe (PID: 3784)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 3324)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 3324)
    • Removes files from Windows directory

      • msiexec.exe (PID: 3324)
      • DrvInst.exe (PID: 2772)
      • DrvInst.exe (PID: 3144)
      • usbinst.exe (PID: 2816)
    • Executed via COM

      • wfcrun32.exe (PID: 3228)
      • DrvInst.exe (PID: 2772)
      • DrvInst.exe (PID: 3144)
    • Creates files in the user directory

      • wfcrun32.exe (PID: 3228)
    • Creates files in the Windows directory

      • usbinst.exe (PID: 2816)
      • msiexec.exe (PID: 3324)
      • DrvInst.exe (PID: 2772)
      • DrvInst.exe (PID: 3144)
    • Adds / modifies Windows certificates

      • TrolleyExpress.exe (PID: 3528)
    • Creates files in the driver directory

      • usbinst.exe (PID: 2816)
      • DrvInst.exe (PID: 3144)
      • DrvInst.exe (PID: 2772)
    • Creates files in the program directory

      • TrolleyExpress.exe (PID: 3528)
    • Creates a software uninstall entry

      • TrolleyExpress.exe (PID: 3528)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 3324)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 3352)
      • msiexec.exe (PID: 3324)
    • Reads the hosts file

      • chrome.exe (PID: 3352)
      • chrome.exe (PID: 3176)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 3352)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2536)
      • MsiExec.exe (PID: 2288)
      • MsiExec.exe (PID: 2884)
      • MsiExec.exe (PID: 2724)
      • MsiExec.exe (PID: 968)
      • msiexec.exe (PID: 3324)
      • MsiExec.exe (PID: 3772)
    • Reads settings of System Certificates

      • TrolleyExpress.exe (PID: 3528)
      • Receiver.exe (PID: 3104)
      • chrome.exe (PID: 3176)
      • msiexec.exe (PID: 3324)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3324)
    • Creates files in the program directory

      • msiexec.exe (PID: 3324)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2772)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
93
Monitored processes
46
Malicious processes
17
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fa8a9d0,0x6fa8a9e0,0x6fa8a9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
664"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,13122921986071910869,16698460852706446142,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5441031730174990297 --mojo-platform-channel-handle=1004 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
836"C:\Program Files\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe"C:\Program Files\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe
MsiExec.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
MEDIUM
Description:
Citrix Receiver
Exit code:
0
Version:
4.3.100.10167
Modules
Images
c:\program files\citrix\ica client\selfserviceplugin\selfserviceplugin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
968C:\Windows\system32\MsiExec.exe -Embedding EE61D9C453D0B6645F5E578711853EA7C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1156"C:\Program Files\Citrix\ICA Client\SelfServicePlugin\SelfService.exe" -cleanPNA -exitC:\Program Files\Citrix\ICA Client\SelfServicePlugin\SelfService.exe
msiexec.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
HIGH
Description:
Citrix Receiver
Exit code:
0
Version:
4.3.100.10167
Modules
Images
c:\program files\citrix\ica client\selfserviceplugin\selfservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1300C:\Windows\system32\MsiExec.exe -Embedding FC73ED85534918A7A529F0A95199AD46C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1676"C:\Program Files\Citrix\ICA Client\SetIntegrityLevel.exe" $redirector.exe /startup$MC:\Program Files\Citrix\ICA Client\SetIntegrityLevel.exe
msiexec.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
HIGH
Description:
Citrix Connection Center Launcher Utility
Exit code:
6
Version:
14.3.100.10
Modules
Images
c:\program files\citrix\ica client\setintegritylevel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
1876"C:\Users\admin\Downloads\CitrixReceiver.exe" C:\Users\admin\Downloads\CitrixReceiver.exechrome.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
MEDIUM
Description:
Citrix Receiver
Exit code:
3221226540
Version:
14.3.100.10
Modules
Images
c:\users\admin\downloads\citrixreceiver.exe
c:\systemroot\system32\ntdll.dll
1904"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,13122921986071910869,16698460852706446142,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=13944670558079429097 --mojo-platform-channel-handle=2412 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2060concentr.exe /startupC:\Program Files\Citrix\ICA Client\concentr.exe
SetIntegrityLevel.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
MEDIUM
Description:
Citrix Connection Center
Exit code:
0
Version:
14.3.100.10
Modules
Images
c:\program files\citrix\ica client\concentr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcp80.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
10 615
Read events
3 677
Write events
6 820
Delete events
118

Modification events

(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2124) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:3352-13228372797187875
Value:
259
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3120-13213713943555664
Value:
0
(PID) Process:(3352) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3352-13228372797187875
Value:
259
Executable files
673
Suspicious files
40
Text files
380
Unknown types
33

Dropped files

PID
Process
Filename
Type
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5E68623D-D18.pma
MD5:
SHA256:
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\53a4c974-37de-4a50-adfd-9cab2fecc7b8.tmp
MD5:
SHA256:
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:33B05E8AC9C178C58ED3321F496588C0
SHA256:2CDF6A09638A0B563EA2672D6926210771902E0A9203FE15D2857FC4EB954CDE
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RFa66d1a.TMPtext
MD5:F69C20D5B552B8D973FB1CBA5FDD7D87
SHA256:48799968D50E2D74E625A0AB18E93C6792AF20010334C6BB4E935C8D26F7026A
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFa66d1a.TMPtext
MD5:DA692BE42E4EF2668AE7499A7D5DA720
SHA256:EB865CAF59002C092F5FDBE22D01935866BC1277108B29E897052CB2439630ED
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RFa66d68.TMPtext
MD5:FC9FFE77348619CC285333DFF5E1D5D1
SHA256:7CB9B3575330B3D776A21EB7A7407E34F013A0975B7418DA11B5C85DEC91D1F3
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RFa66e04.TMPtext
MD5:6F174C3088498A2CD266BCA5EE2F6624
SHA256:2EEEC1240EB66978ED12E9034F8D4284B0CA1DC82495954636D68140E2187FA4
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
3352chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFa66edf.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3176
chrome.exe
216.58.210.4:443
www.google.com
Google Inc.
US
whitelisted
172.217.23.110:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3176
chrome.exe
216.58.207.35:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3176
chrome.exe
199.185.7.110:443
online.qbyte.com
Q9 Networks Inc.
CA
unknown
3176
chrome.exe
172.217.22.109:443
accounts.google.com
Google Inc.
US
whitelisted
3176
chrome.exe
172.217.21.195:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3176
chrome.exe
172.217.23.163:443
www.gstatic.com
Google Inc.
US
whitelisted
3176
chrome.exe
172.217.21.206:443
clients1.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
online.qbyte.com
  • 199.185.7.110
unknown
clientservices.googleapis.com
  • 216.58.207.35
whitelisted
accounts.google.com
  • 172.217.22.109
shared
www.google.com
  • 216.58.210.4
malicious
ssl.gstatic.com
  • 172.217.21.195
whitelisted
sb-ssl.google.com
  • 172.217.23.110
whitelisted
www.gstatic.com
  • 172.217.23.163
whitelisted
clients1.google.com
  • 172.217.21.206
whitelisted

Threats

No threats detected
Process
Message
CitrixReceiver.exe
RunPackage: bootstrap install started
CitrixReceiver.exe
Extracting files to folder with index -1
CitrixReceiver.exe
CUpdatePackage::dualpk does not exist...C:\Users\admin\AppData\Local\Temp\Ctx-310856BE-FBC7-40DA-8464-C322C882DBC2\Extract\dualpk.cab
CitrixReceiver.exe
CUpdatePackage::InternalRun: CCabinetReader::Commandline C:\Users\admin\AppData\Local\Temp\Ctx-310856BE-FBC7-40DA-8464-C322C882DBC2\Extract\TrolleyExpress.exe "C:\Users\admin\Downloads\CitrixReceiver.exe"
CitrixReceiver.exe
CUpdatePackage::InternalRun: User`is an Admin
TrolleyExpress.exe
Information - CApp::InitializeResourceModule(918) - Loaded Resource Module: C:\Users\admin\AppData\Local\Temp\Ctx-310856BE-FBC7-40DA-8464-C322C882DBC2\Extract\TrolleyExpressUI_en.dll
TrolleyExpress.exe
Information - CApp::InitializeLog(716) - * Command Line: "C:\Users\admin\Downloads\CitrixReceiver.exe"
TrolleyExpress.exe
Information - CApp::InitializeLog(715) - * Build Time: 06:05:40
TrolleyExpress.exe
Information - CApp::InitInstance(260) - User is Admin User : 1
TrolleyExpress.exe
Information - CCommandLine::ParseParam(121) - Command Line Parameter: C:\Users\admin\Downloads\CitrixReceiver.exe = true