File name: | C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004_d\MailRuUpdater.exe |
Full analysis: | https://app.any.run/tasks/ddba8ccb-a16a-4b4e-8c58-be8a04380950 |
Verdict: | Malicious activity |
Analysis date: | March 14, 2019, 14:46:43 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 4AC5A9796E153B190E70E2F51E49A131 |
SHA1: | 9C4AF8945EAC90449DD54A965EAA427924252FAE |
SHA256: | 5530BE4592507773E6CA5EF13160973824C8DCFF7F4CB4F97B5B508A336C8727 |
SSDEEP: | 98304:TXfQtrzsLexRQ8uhYCxncrqcnEU3Id17Dp+LkIX:zfQtrgLex68uhYsWqcnEUe7Bw |
.exe | | | Win32 EXE PECompact compressed (generic) (53.4) |
---|---|---|
.exe | | | Win64 Executable (generic) (35.5) |
.exe | | | Win32 Executable (generic) (5.8) |
.exe | | | Generic Win/DOS Executable (2.5) |
.exe | | | DOS Executable Generic (2.5) |
Comments: | - |
---|---|
ProductVersion: | 5.1.0.195 |
ProductName: | MailRuUpdater |
OriginalFileName: | MailRuUpdater.exe |
LegalCopyright: | Copyright 2015 |
InternalName: | MailRuUpdater |
FileVersion: | 5.1.0.195 |
FileDescription: | Mail.Ru updater |
CompanyName: | Mail.Ru |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.1.0.195 |
FileVersionNumber: | 5.1.0.195 |
Subsystem: | Windows GUI |
SubsystemVersion: | 5.1 |
ImageVersion: | - |
OSVersion: | 5.1 |
EntryPoint: | 0x14369d |
UninitializedDataSize: | - |
InitializedDataSize: | 819200 |
CodeSize: | 2716160 |
LinkerVersion: | 14.12 |
PEType: | PE32 |
TimeStamp: | 2019:02:27 17:45:17+01:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 27-Feb-2019 16:45:17 |
Detected languages: |
|
TLS Callbacks: | 1 callback(s) detected. |
Debug artifacts: |
|
CompanyName: | Mail.Ru |
FileDescription: | Mail.Ru updater |
FileVersion: | 5.1.0.195 |
InternalName: | MailRuUpdater |
LegalCopyright: | Copyright 2015 |
OriginalFilename: | MailRuUpdater.exe |
ProductName: | MailRuUpdater |
ProductVersion: | 5.1.0.195 |
Comments: | - |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000120 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 6 |
Time date stamp: | 27-Feb-2019 16:45:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x002971D1 | 0x00297200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66286 |
.rdata | 0x00299000 | 0x00084B34 | 0x00084C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26541 |
.data | 0x0031E000 | 0x00017168 | 0x00014800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.09698 |
_RDATA | 0x00336000 | 0x000005E0 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.61028 |
.rsrc | 0x00337000 | 0x0000E628 | 0x0000E800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.55667 |
.reloc | 0x00346000 | 0x0001D27C | 0x0001D400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.57893 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.07176 | 640 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 5.40354 | 4264 | UNKNOWN | Russian - Russia | RT_ICON |
3 | 5.92812 | 2440 | UNKNOWN | Russian - Russia | RT_ICON |
4 | 6.09802 | 1128 | UNKNOWN | Russian - Russia | RT_ICON |
9 | 1.68186 | 58 | UNKNOWN | Russian - Russia | RT_STRING |
128 | 2.65534 | 62 | UNKNOWN | Russian - Russia | RT_GROUP_ICON |
1032 | 5.40076 | 32038 | UNKNOWN | English - United States | BIN |
ADVAPI32.dll |
CRYPT32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
PSAPI.DLL |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
USERENV.dll |
Title | Ordinal | Address |
---|---|---|
??0?$oserializer@Vtext_woarchive@archive@boost@@U?$pair@$CBUProcessKey@sysinfo@mailru@@UProcessInfo@23@@std@@@detail@archive@boost@@QAE@XZ | 1 | 0x00015BED |
??0?$oserializer@Vtext_woarchive@archive@boost@@U?$pair@$CBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@Vptime@posix_time@boost@@@std@@@detail@archive@boost@@QAE@XZ | 2 | 0x0004BFF7 |
??0?$oserializer@Vtext_woarchive@archive@boost@@UCollectingData@sysinfo@mailru@@@detail@archive@boost@@QAE@XZ | 3 | 0x00015C11 |
??0?$oserializer@Vtext_woarchive@archive@boost@@UProcessInfo@sysinfo@mailru@@@detail@archive@boost@@QAE@XZ | 4 | 0x00015C35 |
??0?$oserializer@Vtext_woarchive@archive@boost@@UProcessKey@sysinfo@mailru@@@detail@archive@boost@@QAE@XZ | 5 | 0x00015C59 |
??0?$oserializer@Vtext_woarchive@archive@boost@@UProductChange@Impl@ProdMonTask@prodmon@mailru@@@detail@archive@boost@@QAE@XZ | 6 | 0x0004C01B |
??0?$oserializer@Vtext_woarchive@archive@boost@@UProductEvent@Impl@ProdMonTask@prodmon@mailru@@@detail@archive@boost@@QAE@XZ | 7 | 0x0004C03F |
??0?$oserializer@Vtext_woarchive@archive@boost@@UState@Impl@ProdMonTask@prodmon@mailru@@@detail@archive@boost@@QAE@XZ | 8 | 0x0004C063 |
??0?$oserializer@Vtext_woarchive@archive@boost@@V?$map@UProcessKey@sysinfo@mailru@@UProcessInfo@23@U?$less@UProcessKey@sysinfo@mailru@@@std@@V?$allocator@U?$pair@$CBUProcessKey@sysinfo@mailru@@UProcessInfo@23@@std@@@6@@std@@@detail@archive@boost@@QAE@XZ | 9 | 0x00015C7D |
??0?$oserializer@Vtext_woarchive@archive@boost@@V?$map@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@Vptime@posix_time@boost@@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@V?$allocator@U?$pair@$CBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@Vptime@posix_time@boost@@@std@@@2@@std@@@detail@archive@boost@@QAE@XZ | 10 | 0x0004C087 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3180 | "C:\Users\admin\AppData\Local\Temp\MailRuUpdater.exe" | C:\Users\admin\AppData\Local\Temp\MailRuUpdater.exe | explorer.exe | ||||||||||||
User: admin Company: Mail.Ru Integrity Level: MEDIUM Description: Mail.Ru updater Version: 5.1.0.195 Modules
|
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
Operation: | write | Name: | Name |
Value: MailRuUpdater.exe | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\AppDataLow\Software\Mail.Ru\IE_Bar\Settings |
Operation: | write | Name: | GUID |
Value: {160D9896-06FF-477A-A181-B7AC1AC7AA1C} | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Mail.Ru\Tech |
Operation: | write | Name: | UserID |
Value: {3CE599B0-91D0-4B36-9EC7-6243D64B59FD} | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{2AB1F4AB-E3FA-4047-9033-EC223C8354F5} |
Operation: | write | Name: | finished_time |
Value: 7C698A5C00000000 | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{84DC8324-C256-4EF5-B0DC-383B43EE77E9} |
Operation: | write | Name: | finished_time |
Value: 9C698A5C00000000 | |||
(PID) Process: | (3180) MailRuUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{FC604959-8A01-4E8B-A3E5-87CEEBD6FEDB} |
Operation: | write | Name: | finished_time |
Value: 9C698A5C00000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3180 | MailRuUpdater.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-shm | — | |
MD5:— | SHA256:— | |||
3180 | MailRuUpdater.exe | C:\ProgramData\Mail.Ru\Id | text | |
MD5:6F5080224CC1294614E67B24C63C23DF | SHA256:80EB17840470D74068888D3B8157BADBA1990206A5D1D76B67F792B38C3102FA | |||
3180 | MailRuUpdater.exe | C:\ProgramData\Mail.ru\ifrm | binary | |
MD5:AF447F9F31BB68924F424CA0185A8850 | SHA256:DA8FA66F59109FA7B1BF688892F912A6F4FDB4E7E85020A11FEA8523DDB19316 | |||
3180 | MailRuUpdater.exe | C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004 | binary | |
MD5:1BC93EBD8AF66B36CDE64E2A8538D6B7 | SHA256:3B3A9EED032F7068DB5D2DECC2C33D822B9A5901632EF6A5F460EC1505C6A5DC | |||
3180 | MailRuUpdater.exe | C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\prodmon | binary | |
MD5:F2468FD932D1DA097F224C066BFEB1D8 | SHA256:E1D2A7D097D701A9809C1BAC691AD04206D5C9125CA770FD6F5354234C507D50 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3180 | MailRuUpdater.exe | GET | 204 | 217.69.139.245:80 | http://mrds.mail.ru/update/2/version.txt?type=mru_online&tool=mrupdater&masterid=%7BE1AA23DD-35DA-4EFD-96D0-B42A7E28A5BD%7D&user_id=%7B3CE599B0-91D0-4B36-9EC7-6243D64B59FD%7D&osver=7&osbit=32&osvernum=6.1&ossp=Service%20Pack%201&uac=1&admin=1&ver=5.1.0.195&mailru_guard=0&mailru_updater=1&comp_mem=3583&tool_mem=4&elapsed_time=1&mr_service=0&os=win6.1&install_id=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&GUID=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D | RU | — | — | suspicious |
3180 | MailRuUpdater.exe | GET | — | 217.69.139.245:80 | http://mrds.mail.ru/update/2/version.txt?type=task_executed&taskid=%7B2AB1F4AB-E3FA-4047-9033-EC223C8354F5%7D&done=1&masterid=%7BE1AA23DD-35DA-4EFD-96D0-B42A7E28A5BD%7D&user_id=%7B3CE599B0-91D0-4B36-9EC7-6243D64B59FD%7D&osver=7&osbit=32&osvernum=6.1&ossp=Service%20Pack%201&uac=1&admin=1&ver=5.1.0.195&mailru_guard=0&mailru_updater=1&comp_mem=3583&tool_mem=8&elapsed_time=23&mr_service=0&os=win6.1&install_id=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&GUID=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&tool=mrupdater | RU | — | — | suspicious |
3180 | MailRuUpdater.exe | GET | 204 | 217.69.139.245:80 | http://mrds.mail.ru/update/2/version.txt?type=mruinfo&last_ch=16064655&ch_ver=68.0.3440.106&ie_hp=about&ie_dse=www.bing.com&ie_ver=8.00.7600.16385&last_ff=17120255&ff_ver=61.0.2&masterid=%7BE1AA23DD-35DA-4EFD-96D0-B42A7E28A5BD%7D&user_id=%7B3CE599B0-91D0-4B36-9EC7-6243D64B59FD%7D&osver=7&osbit=32&osvernum=6.1&ossp=Service%20Pack%201&uac=1&admin=1&ver=5.1.0.195&mailru_guard=0&mailru_updater=1&comp_mem=3583&tool_mem=8&elapsed_time=23&mr_service=0&os=win6.1&install_id=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&GUID=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&tool=mrupdater | RU | — | — | suspicious |
3180 | MailRuUpdater.exe | GET | 204 | 217.69.139.245:80 | http://mrds.mail.ru/update/2/version.txt?type=task_executed&taskid=%7B901B414B-72A2-48C6-8DCD-29388B8B3E40%7D&done=1&masterid=%7BE1AA23DD-35DA-4EFD-96D0-B42A7E28A5BD%7D&user_id=%7B3CE599B0-91D0-4B36-9EC7-6243D64B59FD%7D&osver=7&osbit=32&osvernum=6.1&ossp=Service%20Pack%201&uac=1&admin=1&ver=5.1.0.195&mailru_guard=0&mailru_updater=1&comp_mem=3583&tool_mem=7&elapsed_time=23&mr_service=0&os=win6.1&install_id=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&GUID=%7B160D9896-06FF-477A-A181-B7AC1AC7AA1C%7D&tool=mrupdater | RU | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3180 | MailRuUpdater.exe | 95.163.144.16:443 | mrproddisup.com | Mrgroup Investments Limited | RU | unknown |
3180 | MailRuUpdater.exe | 217.69.139.247:443 | xmlbinupdate.mail.ru | Limited liability company Mail.Ru | RU | malicious |
3180 | MailRuUpdater.exe | 217.69.139.110:443 | mailruupdater.cdnmail.ru | Limited liability company Mail.Ru | RU | malicious |
3180 | MailRuUpdater.exe | 217.69.139.245:443 | mrds.mail.ru | Limited liability company Mail.Ru | RU | malicious |
3180 | MailRuUpdater.exe | 217.69.139.245:80 | mrds.mail.ru | Limited liability company Mail.Ru | RU | malicious |
3180 | MailRuUpdater.exe | 95.163.144.32:443 | mrdistrupd.com | Mrgroup Investments Limited | RU | unknown |
Domain | IP | Reputation |
---|---|---|
mrds.mail.ru |
| suspicious |
binupdate.mail.ru |
| shared |
xmlbinupdate.mail.ru |
| shared |
mrproddisup.com |
| unknown |
mrdistrupd.com |
| unknown |
mailruupdater.cdnmail.ru |
| unknown |