| File name: | GlanceGuestSetup_4.17.1.exe.7z |
| Full analysis: | https://app.any.run/tasks/77395cf1-c51c-4a8f-9256-673113ca5040 |
| Verdict: | Malicious activity |
| Analysis date: | October 21, 2024, 19:29:22 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 00A0459F0A130FF6AAB20E2C4EE6983A |
| SHA1: | ECD6652A4C147A1EB1B1E85D07061C2019E291C3 |
| SHA256: | 59F1F509F7C761030284B8812E9BD09B9655EDD762CE6CD03D05E8D8B6DE9403 |
| SSDEEP: | 98304:kW94cI82RhxNJyLI3ki6MNKb0a0WsCZRNzAL9ciWuvGK9fjU+vDSQYFLMvFHGv/l:+rNBkIP5mezd3jxmdWdKm5py89png |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | "C:\Users\admin\AppData\Local\Temp\is-J2MNL.tmp\GlanceGuestSetup_4.17.1.19.tmp" /SL5="$1701FA,14029361,141312,C:\Users\admin\AppData\Local\Temp\GlanceGuestSetup_4.17.1.19.exe" /SILENT /LOG | C:\Users\admin\AppData\Local\Temp\is-J2MNL.tmp\GlanceGuestSetup_4.17.1.19.tmp | GlanceGuestSetup_4.17.1.19.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 764 | C:\Users\admin\AppData\Local\Temp\GlanceGuestSetup_4.17.1.19.exe /SILENT /LOG | C:\Users\admin\AppData\Local\Temp\GlanceGuestSetup_4.17.1.19.exe | GlanceGuestSetup_4.17.1.exe | ||||||||||||
User: admin Company: Glance Networks, Inc. Integrity Level: HIGH Description: GlanceGuest Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 780 | "C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe" | C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe | explorer.exe | ||||||||||||
User: admin Company: Glance Networks, Inc. Integrity Level: HIGH Description: Glance Exit code: 0 Version: 4.17.1.19 Modules
| |||||||||||||||
| 2224 | "C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe" | C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe | — | explorer.exe | |||||||||||
User: admin Company: Glance Networks, Inc. Integrity Level: MEDIUM Description: Glance Exit code: 3221226540 Version: 4.17.1.19 Modules
| |||||||||||||||
| 2376 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2380 | "C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe" | C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe | explorer.exe | ||||||||||||
User: admin Company: Glance Networks, Inc. Integrity Level: HIGH Description: Glance Exit code: 0 Version: 4.17.1.19 Modules
| |||||||||||||||
| 2980 | "C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe" | C:\Users\admin\Desktop\GlanceGuestSetup_4.17.1.exe | — | explorer.exe | |||||||||||
User: admin Company: Glance Networks, Inc. Integrity Level: MEDIUM Description: Glance Exit code: 3221226540 Version: 4.17.1.19 Modules
| |||||||||||||||
| 3620 | "C:\Users\admin\AppData\Local\Temp\is-MVVNP.tmp\GlanceGuestSetup_4.17.1.19.tmp" /SL5="$8025E,14029361,141312,C:\Users\admin\AppData\Local\Temp\GlanceGuestSetup_4.17.1.19.exe" /SILENT /LOG | C:\Users\admin\AppData\Local\Temp\is-MVVNP.tmp\GlanceGuestSetup_4.17.1.19.tmp | GlanceGuestSetup_4.17.1.19.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3792 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\GlanceGuest\GClientCtrl.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | GlanceGuestSetup_4.17.1.19.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3836 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\GlanceGuest\GClientCtrl.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | GlanceGuestSetup_4.17.1.19.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\GlanceGuestSetup_4.17.1.exe.7z | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 15 |
Value: | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 14 |
Value: | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 13 |
Value: | |||
| (PID) Process: | (6660) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 12 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\glance_locales\de\GlanceGuest.exe.dll | executable | |
MD5:18CAD60C118F4EB24696F8F845B5AC2D | SHA256:435F3D6D37369795EF1C352DE802CACF81080BF884CADF8FA56FC37E0591D263 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\glance_locales\fr-CA\is-T6IR0.tmp | executable | |
MD5:A6E0C25ECB4001E8A814E4E9093EB91B | SHA256:337A83F64072603A95FEB699B2E9651F70B54DD6FD1F3BDD82FDC9F73DE0EEEC | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\glance_locales\es-MX\GlanceGuest.exe.dll | executable | |
MD5:38B1D739036BF854673273E7FD4DFF6A | SHA256:23B806130DE50FC3C4A4AA216AB1E35E75801922C721843B05742C043B4AB6D3 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\is-P29PG.tmp | executable | |
MD5:DA408F7F99E656CE838435FB7A9DDAAF | SHA256:7FCE0857CBB6C71DAA841168B6862B5B26CEF8A4DBB53B04F57C9D2BB70FF183 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\is-ITPN4.tmp | binary | |
MD5:E0C8C8C677A943180CA288F8422F8BAE | SHA256:196BB2ED7CF037A0D83C2AD48CB2AF02D817C7FC7E3C7EA970A068C7043F57F5 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\unins000.exe | executable | |
MD5:0B50FCC91D320BEF72598DBE153657F4 | SHA256:9556252C01D616CB02AF7D78CE3593E94B98F175E24D494A7FE3064F98D36B96 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\Glance.exe | executable | |
MD5:BE026B2D712794EB4D18397EEC8108E7 | SHA256:77F07597A4CBABAEBDF188EB91191968871511C3F3524BD5614458A8F7859BB3 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\glance_locales\it\GlanceGuest.exe.dll | executable | |
MD5:D0D477BF0E3EC94D3558FB93199BF245 | SHA256:E5A85361880113E36D659FDAEFE96B8C02F55173D59BAA44C18CB25C241859BF | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\is-95VEP.tmp | executable | |
MD5:2517C3E1F1050851683B60C407E59DB5 | SHA256:D16D9BF386ADB913A8470F181995432F0CFC814F9917D53DB1A49DC72FEB9485 | |||
| 4516 | GlanceGuestSetup_4.17.1.19.tmp | C:\Program Files (x86)\GlanceGuest\is-PFE64.tmp | binary | |
MD5:D8D57F37AB6305973F1E2149A321F82E | SHA256:3A062BCF741BF652892E3503C350BC1F2FE2A658DB562EC4CAC22CEAF0EF3F8B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2776 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 23.220.255.25:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 23.51.49.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.51.49.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4508 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5372 | SIHClient.exe | GET | 200 | 23.51.49.221:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5372 | SIHClient.exe | GET | 200 | 23.51.49.221:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5640 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4360 | SearchApp.exe | 2.22.248.153:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6944 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2776 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2776 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
780 | svchost.exe | 23.214.205.160:443 | go.microsoft.com | AKAMAI-AS | BR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
th.bing.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |