| File name: | Jetclean.exe |
| Full analysis: | https://app.any.run/tasks/6203a062-8ed6-4142-96ab-2101d7b2bc81 |
| Verdict: | Malicious activity |
| Analysis date: | December 19, 2023, 01:31:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B787B916CB498375501D8CA9657FDD3C |
| SHA1: | 625E8236EAD1466805257803E69CEA7EDDF41F8E |
| SHA256: | 4F704F0F1DA17915CD151B303268ADDF870A9B7BDFC2803F3AED64B6F66D7147 |
| SSDEEP: | 98304:3A0byZlK4Klfib3Qw6ydQgCuaKdSdxTrQubOvfq1y7QO9++DEasCDnmw0D+0U6gu:UazkTgecnN |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:07:09 15:41:29+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 86016 |
| InitializedDataSize: | 66560 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16478 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.0.0 |
| ProductVersionNumber: | 1.5.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | BlueSprig |
| FileDescription: | JetClean Setup |
| FileVersion: | 1.5.0.0 |
| LegalCopyright: | Copyright © 2011-2013 |
| ProductName: | JetClean |
| ProductVersion: | 1.5.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Users\admin\AppData\Local\Temp\Jetclean.exe" | C:\Users\admin\AppData\Local\Temp\Jetclean.exe | — | explorer.exe | |||||||||||
User: admin Company: BlueSprig Integrity Level: MEDIUM Description: JetClean Setup Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| 268 | "C:\Users\admin\AppData\Local\Temp\Jetclean.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA | C:\Users\admin\AppData\Local\Temp\Jetclean.exe | Jetclean.tmp | ||||||||||||
User: admin Company: BlueSprig Integrity Level: HIGH Description: JetClean Setup Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\is-NFN6F.tmp\Jetclean.tmp" /SL5="$501AC,3913143,153600,C:\Users\admin\AppData\Local\Temp\Jetclean.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA | C:\Users\admin\AppData\Local\Temp\is-NFN6F.tmp\Jetclean.tmp | Jetclean.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 712 | "C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\bluesprigToolbar-stub-1.exe" /S /V"/qn CHANNEL_ID=925777 D_WSD=1 SSC=1 GCDEA=1 GCSA=1 GCSE=1 HP=1" /UM"http://download.mybrowserbar.com/vkits/dlv1/925777/bluesprigToolbar.msi" | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\bluesprigToolbar-stub-1.exe | Jetclean.tmp | ||||||||||||
User: admin Company: Spigot, Inc. Integrity Level: HIGH Description: Setup Launcher Unicode Exit code: 0 Version: 7.2 Modules
| |||||||||||||||
| 1040 | "C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\Upgrade.exe" /Upgrade | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\Upgrade.exe | — | Jetclean.tmp | |||||||||||
User: admin Company: BlueSprig Integrity Level: HIGH Description: JetClean Upgrade Programe Exit code: 0 Version: 1.0.6.6 Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\AppData\Local\Temp\is-3CFSM.tmp\Jetclean.tmp" /SL5="$301AA,3913143,153600,C:\Users\admin\AppData\Local\Temp\Jetclean.exe" | C:\Users\admin\AppData\Local\Temp\is-3CFSM.tmp\Jetclean.tmp | — | Jetclean.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1864 | "C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\ToolbarAcceptRate.exe" 1 925777 | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\ToolbarAcceptRate.exe | Jetclean.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2248 | "C:\Program Files\BlueSprig\JetClean\Install.exe" | C:\Program Files\BlueSprig\JetClean\Install.exe | Jetclean.tmp | ||||||||||||
User: admin Company: BlueSprig Integrity Level: HIGH Exit code: 0 Version: 1.0.0.10 Modules
| |||||||||||||||
| 2292 | "C:\Program Files\BlueSprig\JetClean\AutoUpdate.exe" /Check | C:\Program Files\BlueSprig\JetClean\AutoUpdate.exe | JetClean.exe | ||||||||||||
User: admin Company: BlueSprig Integrity Level: HIGH Description: JetClean Updater Exit code: 0 Version: 1.0.9.141 Modules
| |||||||||||||||
| 2300 | "C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\BlueSprig\JetClean\JetCleanExtMenu.dll" | C:\Windows\System32\regsvr32.exe | — | JetCleanInit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (668) Jetclean.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1864) ToolbarAcceptRate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1864) ToolbarAcceptRate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1864) ToolbarAcceptRate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1864) ToolbarAcceptRate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 124 | Jetclean.exe | C:\Users\admin\AppData\Local\Temp\is-3CFSM.tmp\Jetclean.tmp | executable | |
MD5:4BA02A2F64504261FCA1AD62CDCFA651 | SHA256:6B1506A2BCD8AF3AA3E2D97C35D86D520C98577E9F6475B71AFBD76578308C62 | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\getCountry | text | |
MD5:3A52F3C22ED6FCDE5BF696A6C02C9E73 | SHA256:6814EF46F686990CF4E946F966167B0507E1D642C44E51F61BFFB0BBA2D4672B | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\itdownload.dll | executable | |
MD5:DEE52C28FB4198CC702F3C379C5E982B | SHA256:E005BC8003CA90903F021DF51C9AF6D35B750E67799ECBABED0AF71BA54A4231 | |||
| 268 | Jetclean.exe | C:\Users\admin\AppData\Local\Temp\is-NFN6F.tmp\Jetclean.tmp | executable | |
MD5:4BA02A2F64504261FCA1AD62CDCFA651 | SHA256:6B1506A2BCD8AF3AA3E2D97C35D86D520C98577E9F6475B71AFBD76578308C62 | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\RdZone.dll | executable | |
MD5:61AD4BFDB2885D3497596DFAD2889C9A | SHA256:4AE86843FBB76C8A9BC3C364F85EC8EC1727556970E7ED5C2D31868E631C3162 | |||
| 712 | bluesprigToolbar-stub-1.exe | C:\Users\admin\AppData\Local\Temp\{2E596077-3F8A-4FF4-BF20-DEBD1AF14E16}\Setup.INI | text | |
MD5:CF2836EC0962ECCA8E8085A53BB73629 | SHA256:294BEDBCCF9A7B68CAAEC45089D9587A4715675634A206F72AC69C9BAD0E16A3 | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\bluesprigToolbar-stub-1.exe | executable | |
MD5:5AB8FD011AA0BA8C335936CAAD03B08B | SHA256:BCB98161A6EFFDBFCA627547FC6307B86BA40F43E142C13E3C43E4A9B9F5068E | |||
| 668 | Jetclean.tmp | C:\Users\admin\AppData\Local\Temp\is-DHPKB.tmp\ToolbarAcceptRate.exe | executable | |
MD5:CA0C64A36FDF69E6B916A8906E9AE9A4 | SHA256:8C051D485A974D7C9B2F834EF463A9C0489F76A6F5BE48067C45BBBC85051D27 | |||
| 712 | bluesprigToolbar-stub-1.exe | C:\Users\admin\AppData\Local\Temp\{2E596077-3F8A-4FF4-BF20-DEBD1AF14E16}\0x0409.ini | text | |
MD5:BE345D0260AE12C5F2F337B17E07C217 | SHA256:E994689A13B9448C074F9B471EDEEC9B524890A0D82925E98AB90B658016D8F3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2248 | Install.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a75bb86b5190f439 | unknown | compressed | 4.66 Kb | unknown |
2248 | Install.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5507f402ec456380 | unknown | compressed | 4.66 Kb | unknown |
2248 | Install.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D | unknown | binary | 471 b | unknown |
2248 | Install.exe | GET | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCZXmpIP%2Bo%2BHhJmodADfw%2Fc | unknown | binary | 472 b | unknown |
2248 | Install.exe | GET | 200 | 199.46.34.145:80 | http://www.bluesprig.com/cms/includes/zcs5q4lyo71.2309131409404.css | unknown | text | 37.5 Kb | unknown |
668 | Jetclean.tmp | GET | 200 | 18.219.121.101:80 | http://api.mybrowserbar.com/cgi/getcountry.cgi | unknown | text | 2 b | unknown |
1864 | ToolbarAcceptRate.exe | GET | 200 | 18.219.121.101:80 | http://www.mybrowserbar.com/images/pixel.gif?tb=1&cnid=925777 | unknown | image | 1.07 Kb | unknown |
712 | bluesprigToolbar-stub-1.exe | GET | 404 | 18.219.121.101:80 | http://download.mybrowserbar.com/vkits/dlv1/925777/bluesprigToolbar.msi | unknown | html | 196 b | unknown |
712 | bluesprigToolbar-stub-1.exe | GET | 404 | 18.219.121.101:80 | http://download.mybrowserbar.com/vkits/dlv1/925777/bluesprigToolbar.msi | unknown | html | 196 b | unknown |
712 | bluesprigToolbar-stub-1.exe | GET | 404 | 18.219.121.101:80 | http://download.mybrowserbar.com/vkits/dlv1/925777/bluesprigToolbar.msi | unknown | html | 196 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
668 | Jetclean.tmp | 18.219.121.101:80 | api.mybrowserbar.com | AMAZON-02 | US | unknown |
1864 | ToolbarAcceptRate.exe | 18.219.121.101:80 | api.mybrowserbar.com | AMAZON-02 | US | unknown |
712 | bluesprigToolbar-stub-1.exe | 18.219.121.101:80 | api.mybrowserbar.com | AMAZON-02 | US | unknown |
2248 | Install.exe | 199.46.34.145:80 | www.bluesprig.com | Akamai International B.V. | US | unknown |
2248 | Install.exe | 142.250.185.168:443 | www.googletagmanager.com | GOOGLE | US | unknown |
2248 | Install.exe | 157.240.253.1:80 | connect.facebook.net | FACEBOOK | DE | unknown |
2248 | Install.exe | 157.240.253.1:443 | connect.facebook.net | FACEBOOK | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
api.mybrowserbar.com |
| unknown |
www.mybrowserbar.com |
| malicious |
download.mybrowserbar.com |
| unknown |
www.bluesprig.com |
| unknown |
www.googletagmanager.com |
| whitelisted |
connect.facebook.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
download.bluesprig.com |
| unknown |
Process | Message |
|---|---|
JetCleanInit.exe | /s "C:\Program Files\BlueSprig\JetClean\JetCleanExtMenu.dll" |
JetCleanInit.exe | Not OS 64 |
JetCleanInit.exe | 42 |
JetClean.exe | WaitForExplorer |
JetClean.exe | Count: 97 |
JetClean.exe | Count: 97 |
JetClean.exe | Count: 97 |
JetClean.exe | Count: 97 |
JetClean.exe | Count: 97 |
JetClean.exe | Count: 97 |