File name: | QTTabBar 2048 Beta2.exe |
Full analysis: | https://app.any.run/tasks/0ec322f5-e3fc-4fe2-aac5-2edbd1e0e9ce |
Verdict: | Malicious activity |
Analysis date: | October 01, 2025, 18:37:27 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
MD5: | 1A4782A50C18736761528BC51678EEFC |
SHA1: | FEF48925960E8A59CB08B98480ACEF768CB9D195 |
SHA256: | 6201B32BAE395974CADFC9059AED718313D2879560C2F6F11B73824CFD60BA47 |
SSDEEP: | 98304:u0el1e+DEreL40FOczKDZj1jxTHrNRtCaVdrG7009gTlwEpEc5PYKbn9YWtsrIAN:sUjA8A |
.exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
---|---|---|
.exe | | | Win64 Executable (generic) (23.8) |
.dll | | | Win32 Dynamic Link Library (generic) (5.6) |
.exe | | | Win32 Executable (generic) (3.8) |
.exe | | | Generic Win/DOS Executable (1.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2021:09:19 05:42:40+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32 |
LinkerVersion: | 48 |
CodeSize: | 4184064 |
InitializedDataSize: | 48640 |
UninitializedDataSize: | - |
EntryPoint: | 0x3ff7da |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.0.0 |
ProductVersionNumber: | 1.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | QTTabBar msi launcher |
CompanyName: | Quizo |
FileDescription: | QTTabBar Installer |
FileVersion: | 1.0.0.0 |
InternalName: | QTTabBar.exe |
LegalCopyright: | Copyright Quizo © 2021 |
LegalTrademarks: | - |
OriginalFileName: | QTTabBar.exe |
ProductName: | QTTabBar |
ProductVersion: | 1.0.0.0 |
AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
320 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
536 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
868 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | RegAsm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
888 | "C:\Users\admin\Downloads\QTTabBar 2048 Beta2.exe" | C:\Users\admin\Downloads\QTTabBar 2048 Beta2.exe | — | explorer.exe | |||||||||||
User: admin Company: Quizo Integrity Level: MEDIUM Description: QTTabBar Installer Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
1324 | "C:\Users\admin\AppData\Local\Temp\QTTabBar\SetupHelper.exe" i 2048.0.0.0 | C:\Users\admin\AppData\Local\Temp\QTTabBar\SetupHelper.exe | msiexec.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: SetupHelper Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
1868 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5220 -prefsLen 39068 -prefMapHandle 5212 -prefMapSize 272997 -jsInitHandle 4908 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5216 -initialChannelId {0effcfc1-dcdf-4d8b-a7fc-979b8c33c6b2} -parentPid 5032 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5032" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
1880 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1976 | "C:\Users\admin\Downloads\QTTabBar 2048 Beta2.exe" | C:\Users\admin\Downloads\QTTabBar 2048 Beta2.exe | explorer.exe | ||||||||||||
User: admin Company: Quizo Integrity Level: HIGH Description: QTTabBar Installer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
2188 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2532 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4248 -prefsLen 44877 -prefMapHandle 4236 -prefMapSize 272997 -jsInitHandle 4240 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4256 -initialChannelId {ccf4067d-b5f8-4096-879f-9c7c8fdda400} -parentPid 5032 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5032" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
|
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000F9A11A7A0233DC017C1A00006C040000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 480000000000000034051D7A0233DC017C1A00006C040000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 480000000000000034051D7A0233DC017C1A00006C040000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4800000000000000B0A6FB790233DC017C1A00006C040000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 4800000000000000B0A6FB790233DC017C1A00006C040000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 4800000000000000E8681F7A0233DC017C1A00006C040000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6780) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 11 | |||
(PID) Process: | (2188) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (2188) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
Operation: | write | Name: | Element |
Value: 0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000 | |||
(PID) Process: | (2188) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002 |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
6780 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
7140 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSICF61.tmp | executable | |
MD5:9945F10135A4C7214FA5605C21E5DE9B | SHA256:9F3B0F3AF4BFA061736935BAB1D50ED2581358DDC9A9C0DB22564ACED1A1807C | |||
6780 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:2C87D7E20723736842753EDB2AFA3CE1 | SHA256:67B0939906C3E6DFC4DF27187FA9EDE88FB8A2E710EF3B7A7C1BB0BE05D790AA | |||
7140 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSICFDF.tmp | executable | |
MD5:9945F10135A4C7214FA5605C21E5DE9B | SHA256:9F3B0F3AF4BFA061736935BAB1D50ED2581358DDC9A9C0DB22564ACED1A1807C | |||
6236 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CFG238C.tmp | xml | |
MD5:2BE48F533744EFA173A2EDE37EA8031E | SHA256:02375FA63B79648ED6BB419C08F78BA9032EE22BA7170250E24427F47FDDFA4E | |||
6780 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{222b6b31-35f8-4475-8ffe-7c566b705796}_OnDiskSnapshotProp | binary | |
MD5:2C87D7E20723736842753EDB2AFA3CE1 | SHA256:67B0939906C3E6DFC4DF27187FA9EDE88FB8A2E710EF3B7A7C1BB0BE05D790AA | |||
6780 | msiexec.exe | C:\Windows\Installer\192253.msi | executable | |
MD5:D4657E4D3A2D1117C5BC97C4393FE75A | SHA256:4C313671BCC34AD60AF66E0E890DAB95AE2E6D8BB16785087EA0836506631909 | |||
6780 | msiexec.exe | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log | text | |
MD5:AE405B77656207FFBC77F2F85FDF1806 | SHA256:70B24F28AB2BFA2F9C02581C93535FE79AAEB7E9FEAE743C45D71E81557FBF34 | |||
6780 | msiexec.exe | C:\Windows\Installer\MSI239C.tmp | executable | |
MD5:9945F10135A4C7214FA5605C21E5DE9B | SHA256:9F3B0F3AF4BFA061736935BAB1D50ED2581358DDC9A9C0DB22564ACED1A1807C | |||
6164 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CFGCFCE.tmp | xml | |
MD5:2BE48F533744EFA173A2EDE37EA8031E | SHA256:02375FA63B79648ED6BB419C08F78BA9032EE22BA7170250E24427F47FDDFA4E |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 23.55.110.193:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1468 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 23.55.110.182:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl | unknown | — | — | whitelisted |
5724 | SIHClient.exe | GET | 200 | 104.79.89.142:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1268 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2464 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 23.55.110.193:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 104.79.89.142:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1468 | svchost.exe | 20.190.160.132:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | Potentially Bad Traffic | ET INFO Possible Firefox Plugin install |