| URL: | http://files.trendmicro.com/products/Titanium/16.0/NABU/TrendMicro_16.0_MR_32bit.exe |
| Full analysis: | https://app.any.run/tasks/9c1a6827-9aa0-4653-ab69-a47a5c6381f7 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | October 26, 2019, 10:49:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | EFE6DB9FCF047B5AC0784822B6D7CD17 |
| SHA1: | B7AA68649257F5E64FB51F78AB10FE6C717A822F |
| SHA256: | 5971938A91EA974DF0F0C1BC79EEA0CD28EEC08514605A13427D9FB08B566A72 |
| SSDEEP: | 3:N1KYyGL+3Q7aQGRW4+KrkwsODNXMtAC:CYyyuRW4ywDDNON |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://files.trendmicro.com/products/Titanium/16.0/NABU/TrendMicro_16.0_MR_32bit.exe | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 720 | coreFrameworkHost.exe 3520 1 | C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe | coreServiceShell.exe | ||||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Anti-Malware Solution Platform Exit code: 0 Version: 6.5.0.1143 Modules
| |||||||||||||||
| 892 | "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\WscStatusController.exe" | C:\Program Files\Trend Micro\UniClient\UiFrmWrk\WscStatusController.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro WSC Status Controller Exit code: 0 Version: 6.5.0.1143 Modules
| |||||||||||||||
| 1252 | "C:\Windows\system32\runonce.exe" -r | C:\Windows\system32\runonce.exe | — | precleanerpackage.bin | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Run Once Wrapper Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1448 | "C:\ProgramData\Trend Micro Installer\TrendMicro_16.0_MR_32bit_1572087082\Vizor32\VizorHtmlDialog.exe" "C:\ProgramData\Trend Micro Installer\TrendMicro_16.0_MR_32bit_1572087082\Vizor32" "MAIN" "C:\ProgramData\Trend Micro Installer\TrendMicro_16.0_MR_32bit_1572087082\Common\UI\Installer.cmpt" 1033 -set "OEMName" "" -set "PID" "TIG0" -set "PLID" "TIT-STD-MR-1600" -set "ParentPID" "2860" -set "iAUURL" "https://ipv6-iaus.trendmicro.com/iau_server.dll" -set "iKBURL" "https://gr.trendmicro.com/GREntry/NonPayment?TARGET=iKB&" | C:\ProgramData\Trend Micro Installer\TrendMicro_16.0_MR_32bit_1572087082\Vizor32\VizorHtmlDialog.exe | Setup.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro Mini Browser Exit code: 0 Version: 16.0.0.1146 Modules
| |||||||||||||||
| 1516 | C:\Windows\system32\cmd.exe /c REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1636 | regsvr32.exe /s "C:\Program Files\Trend Micro\Titanium\plugin\TmOverlayIcon.dll" | C:\Windows\system32\regsvr32.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1712 | REG DELETE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro /f | C:\Windows\system32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1952 | "regedit.exe" /s DebugLogOn.reg | C:\Windows\regedit.exe | — | precleanerpackage.bin | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Trend Micro\AirSupport\shortcut.exe" -Create "C:\Program Files\Trend Micro\AirSupport" "C:\Program Files\Trend Micro\AirSupport\Resource\TukaSupport\Shortcuts\EN-US\Shortcut.xml" | C:\Program Files\Trend Micro\AirSupport\shortcut.exe | — | Setup.exe | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Shortcut Exit code: 0 Version: 6.0.0.1225 Modules
| |||||||||||||||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 7C020F1803000000 | |||
| (PID) Process: | (2524) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: D3000C1803000000 | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (236) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.pset | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore | — | |
MD5:— | SHA256:— | |||
| 236 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.pset | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
236 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
236 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
236 | firefox.exe | GET | 200 | 2.18.232.128:80 | http://files.trendmicro.com/products/Titanium/16.0/NABU/TrendMicro_16.0_MR_32bit.exe | unknown | executable | 153 Mb | suspicious |
236 | firefox.exe | POST | 200 | 172.217.23.163:80 | http://ocsp.pki.goog/gts1o1 | US | der | 472 b | whitelisted |
236 | firefox.exe | GET | 200 | 2.16.186.50:80 | http://detectportal.firefox.com/success.txt | unknown | text | 8 b | whitelisted |
236 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
236 | firefox.exe | GET | 200 | 2.16.186.50:80 | http://detectportal.firefox.com/success.txt | unknown | text | 8 b | whitelisted |
3520 | coreServiceShell.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.0 Kb | whitelisted |
3364 | TrendMicro_16.0_MR_32bit.exe | GET | 200 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.0 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
236 | firefox.exe | 2.16.186.50:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
236 | firefox.exe | 2.18.232.128:80 | files.trendmicro.com | Akamai International B.V. | — | whitelisted |
236 | firefox.exe | 35.164.109.147:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
236 | firefox.exe | 143.204.101.115:443 | snippets.cdn.mozilla.net | — | US | unknown |
236 | firefox.exe | 34.223.160.244:443 | tiles.services.mozilla.com | Amazon.com, Inc. | US | unknown |
236 | firefox.exe | 172.217.23.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
236 | firefox.exe | 35.160.111.136:443 | push.services.mozilla.com | Amazon.com, Inc. | US | malicious |
2540 | pingsender.exe | 52.40.106.174:443 | incoming.telemetry.mozilla.org | Amazon.com, Inc. | US | unknown |
236 | firefox.exe | 13.225.78.65:443 | tracking-protection.cdn.mozilla.net | — | US | suspicious |
236 | firefox.exe | 54.68.166.121:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
files.trendmicro.com |
| suspicious |
detectportal.firefox.com |
| whitelisted |
e16632.dscd.akamaiedge.net |
| suspicious |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
236 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
236 | firefox.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
Process | Message |
|---|---|
TrendMicro_16.0_MR_32bit.exe | The DLL not found. |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32\SHCore.dll |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32R |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32\pcacli.dll |
TrendMicro_16.0_MR_32bit.exe | The DLL not found. |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32\edputil.dll |
TrendMicro_16.0_MR_32bit.exe | The DLL not found. |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32\CoreMessaging.dll |
TrendMicro_16.0_MR_32bit.exe | The DLL not found. |
TrendMicro_16.0_MR_32bit.exe | C:\Windows\System32\CoreUIComponents.dll |