| File name: | ClickOnceForGoogleChome.exe |
| Full analysis: | https://app.any.run/tasks/0e8c1229-bd7a-4303-b7d7-afdda8da0c3f |
| Verdict: | Suspicious activity |
| Analysis date: | May 22, 2019, 12:36:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 6608813332B33C057B8AB971140AACC5 |
| SHA1: | 5B22394261811EBF089E2CB0B03F40130AC9A98D |
| SHA256: | 517384A398E62D9CF4572BCC0847482BC430C421F3BEB65E61CF6C9D02C0C8DC |
| SSDEEP: | 768:6bJ2iek1YeE60R/Y9gj2VOvOVmg2PlRPCVzDUIwnPfdh/:6tzekzm5Y9gj2gimg2Pk3Pwndh/ |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:02:15 10:46:22+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 15360 |
| InitializedDataSize: | 106496 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5b1e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This extension enables to run ClickOnce applications from Google Chrome |
| CompanyName: | Menarva Ltd |
| FileDescription: | ClickOnce for Google Chrome |
| FileVersion: | 1.0.0.0 |
| InternalName: | ClickOnceForGoogleChome.exe |
| LegalCopyright: | Copyright © 2015 |
| OriginalFileName: | ClickOnceForGoogleChome.exe |
| ProductName: | ClickOnce for Google Chrome |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 15-Feb-2015 09:46:22 |
| Debug artifacts: |
|
| Comments: | This extension enables to run ClickOnce applications from Google Chrome |
| CompanyName: | Menarva Ltd |
| FileDescription: | ClickOnce for Google Chrome |
| FileVersion: | 1.0.0.0 |
| InternalName: | ClickOnceForGoogleChome.exe |
| LegalCopyright: | Copyright © 2015 |
| OriginalFilename: | ClickOnceForGoogleChome.exe |
| ProductName: | ClickOnce for Google Chrome |
| ProductVersion: | 1.0.0.0 |
| Assembly Version: | 1.0.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000080 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 15-Feb-2015 09:46:22 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00002000 | 0x00003B24 | 0x00003C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.64686 |
.rsrc | 0x00006000 | 0x00019D30 | 0x00019E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.32698 |
.reloc | 0x00020000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.0815394 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.00112 | 490 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 7.80887 | 4008 | UNKNOWN | UNKNOWN | RT_ICON |
3 | 2.22393 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 2.05536 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 2.75766 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
6 | 1.70529 | 67624 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 1.94827 | 16936 | UNKNOWN | UNKNOWN | RT_ICON |
32512 | 2.81879 | 90 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
mscoree.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3084 | "C:\Users\admin\AppData\Local\Temp\ClickOnceForGoogleChome.exe" | C:\Users\admin\AppData\Local\Temp\ClickOnceForGoogleChome.exe | explorer.exe | ||||||||||||
User: admin Company: Menarva Ltd Integrity Level: MEDIUM Description: ClickOnce for Google Chrome Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA |
| Operation: | write | Name: | Blob |
Value: 0300000001000000140000008AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8040000000100000010000000FF5FBC4290FA389E798467EBD7AE940B0F0000000100000014000000C45627B5584BF62327DF60D6185744A2D2F2BCBF190000000100000010000000E843AC3B52EC8C297FA948C9B1FB281918000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C200000000100000088040000308204843082036CA0030201020210421AF2940984191F520A4BC62426A74B300D06092A864886F70D0101050500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3035303630373038303931305A170D3230303533303130343833385A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D8300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D010105050003820101004D422FA6C18AEB07809058468CF81939662A3C5A2C6DCFD4D987558D790B12887B408FD5C7F84B8D551663ADB757DC3B2BBDD3C14F1E03874B449BE3E2404526F326492B6A84F1547AD442DAFCD36ABB667ECA9EEAE9BBDC07C7C3924E833C81499F92D53209EA492EA111719A36D2C54E68B6CB0E1B2516AF6CDE5D76D81F72B193268617DB18DEAF45E9DFFB98AF1418EDA45EF6899445F055044ADDFF27DD064A40F6B4BCF1E40F9902BBFD5D0E2E28C1BE3B5F1A3F971084BC163ED8A39C631D66CB5C5FDA3EF30F0A093522DBDBC03F00F9E60D5D67D1FDA01E032BD940F7BECC87665480A6A3B8F51962D5D226B19826EE9ACB44A7455A8195151AF551 | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\NativeMessagingHosts\menarva.utils.clickonceforgooglechrome |
| Operation: | write | Name: | |
Value: C:\Users\admin\AppData\Local\Menarva\ClickOnceForGoogleChrome\menarva_clickonceforgooglechrome_manifest.json | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | Comments |
Value: ClickOnce for Google Chrome | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | DisplayName |
Value: ClickOnce for Google Chrome | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Local\Menarva\ClickOnceForGoogleChrome\ClickOnceForGoogleChome.exe | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | Publisher |
Value: Menarva Ltd | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (3084) ClickOnceForGoogleChome.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ClickOnceForGoogleChome.exe |
| Operation: | write | Name: | UninstallString |
Value: C:\Users\admin\AppData\Local\Menarva\ClickOnceForGoogleChrome\ClickOnceForGoogleChome.exe /Uninstall | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3084 | ClickOnceForGoogleChome.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6F0E55DF8A480361A1A27F82DAA1ABB7 | der | |
MD5:— | SHA256:— | |||
| 3084 | ClickOnceForGoogleChome.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6F0E55DF8A480361A1A27F82DAA1ABB7 | binary | |
MD5:— | SHA256:— | |||
| 3084 | ClickOnceForGoogleChome.exe | C:\Users\admin\AppData\Local\Menarva\ClickOnceForGoogleChrome\menarva_clickonceforgooglechrome_manifest.json | text | |
MD5:6FBDE4AE99CCD29AE28AF6AC5DA22C59 | SHA256:A5A0F169EC0F65C21D585D702942965C8FCECB7318D0D554965131A67851EA7C | |||
| 3084 | ClickOnceForGoogleChome.exe | C:\Users\admin\AppData\Local\Menarva\ClickOnceForGoogleChrome\ClickOnceForGoogleChome.exe | executable | |
MD5:6608813332B33C057B8AB971140AACC5 | SHA256:517384A398E62D9CF4572BCC0847482BC430C421F3BEB65E61CF6C9D02C0C8DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3084 | ClickOnceForGoogleChome.exe | GET | 200 | 91.199.212.52:80 | http://crt.usertrust.com/UTNAddTrustObject_CA.crt | GB | der | 1.13 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3084 | ClickOnceForGoogleChome.exe | 91.199.212.52:80 | crt.usertrust.com | Comodo CA Ltd | GB | suspicious |
Domain | IP | Reputation |
|---|---|---|
crt.usertrust.com |
| whitelisted |