URL:

http://download.memsource.com/production/updates/memsource-editor/win/archive/install/MemsourceEditor-6.225.7-windows.exe

Full analysis: https://app.any.run/tasks/5196b6d7-b0a4-4c4e-b604-9b2ef06bc350
Verdict: Malicious activity
Analysis date: February 12, 2019, 05:12:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

453899583D8B2FCFA5B92BAFB5C3DD3C

SHA1:

CA2486F7D81B80C76B5F934C779C2F911D331C98

SHA256:

624691B48F4AEC66F4B56E6B698AC87529FDD4B83E556F94ED1D85AE1FA54A78

SSDEEP:

3:N1KaKEl4FJTOXaQGRMfNmN9PW/RMKSM7XTlqEde7wZKDrA:Ca54FJTRRMfMe/RMKf8Ede7ZrA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
      • TranslationEditor.exe (PID: 2336)
    • Application was dropped or rewritten from another process

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 3332)
      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
      • TranslationEditor.exe (PID: 2336)
  • SUSPICIOUS

    • Modifies the open verb of a shell class

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
    • Uses NETSH.EXE for network configuration

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
    • Executable content was dropped or overwritten

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
    • Uses ICACLS.EXE to modify access control list

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
    • Creates a software uninstall entry

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
    • Creates files in the program directory

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2804)
    • Application launched itself

      • iexplore.exe (PID: 2804)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3072)
      • iexplore.exe (PID: 2804)
    • Dropped object may contain Bitcoin addresses

      • MemsourceEditor-6.225.7-windows[1].exe (PID: 2328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe memsourceeditor-6.225.7-windows[1].exe no specs memsourceeditor-6.225.7-windows[1].exe netsh.exe no specs netsh.exe no specs icacls.exe no specs icacls.exe no specs translationeditor.exe

Process information

PID
CMD
Path
Indicators
Parent process
2328"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MemsourceEditor-6.225.7-windows[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MemsourceEditor-6.225.7-windows[1].exe
iexplore.exe
User:
admin
Company:
Memsource
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\memsourceeditor-6.225.7-windows[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2336"C:\Program Files\Memsource Editor\TranslationEditor.exe" C:\Program Files\Memsource Editor\TranslationEditor.exe
explorer.exe
User:
admin
Company:
Memsource a.s.
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.225.7.0
Modules
Images
c:\program files\memsource editor\translationeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2416C:\Windows\system32\netsh.exe firewall add allowedprogram "program=\"C:\Program" Files\Memsource Editor\TranslationEditorUpdater.exe\" "name=\"Memsource" Editor Updater\" "mode=ENABLE" "profile=ALL"C:\Windows\system32\netsh.exeMemsourceEditor-6.225.7-windows[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2804"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2892C:\Windows\system32\icacls.exe "C:\Program Files\Memsource Editor" /grant:r "Users:(OI)(CI)F" /C /QC:\Windows\system32\icacls.exeMemsourceEditor-6.225.7-windows[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
3072"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2804 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3168C:\Windows\system32\icacls.exe "C:\Program Files\Memsource Editor" /reset /T /C /QC:\Windows\system32\icacls.exeMemsourceEditor-6.225.7-windows[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
3332"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MemsourceEditor-6.225.7-windows[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MemsourceEditor-6.225.7-windows[1].exeiexplore.exe
User:
admin
Company:
Memsource
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\memsourceeditor-6.225.7-windows[1].exe
c:\systemroot\system32\ntdll.dll
3564C:\Windows\system32\netsh.exe firewall add allowedprogram "program=\"C:\Program" Files\Memsource Editor\TranslationEditor.exe\" "name=\"Memsource" Editor\" "mode=ENABLE" "profile=ALL"C:\Windows\system32\netsh.exeMemsourceEditor-6.225.7-windows[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
Total events
1 092
Read events
907
Write events
180
Delete events
5

Modification events

(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{D8E30C33-2E84-11E9-BAD8-5254004A04AF}
Value:
0
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(2804) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307020002000C0005000C003500D302
Executable files
99
Suspicious files
2
Text files
223
Unknown types
43

Dropped files

PID
Process
Filename
Type
2804iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2804iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2804iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFD9419C87A5F8D313.TMP
MD5:
SHA256:
3072iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\MemsourceEditor-6.225.7-windows[1].exe
MD5:
SHA256:
2804iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MemsourceEditor-6.225.7-windows[1].exe
MD5:
SHA256:
2328MemsourceEditor-6.225.7-windows[1].exeC:\Users\admin\AppData\Local\Temp\br00dea4
MD5:
SHA256:
2328MemsourceEditor-6.225.7-windows[1].exeC:\Users\admin\AppData\Local\Temp\br19219c
MD5:
SHA256:
2328MemsourceEditor-6.225.7-windows[1].exeC:\Users\admin\AppData\Local\Temp\bredbfb2
MD5:
SHA256:
2328MemsourceEditor-6.225.7-windows[1].exeC:\Users\admin\AppData\Local\Temp\brc45f64
MD5:
SHA256:
2328MemsourceEditor-6.225.7-windows[1].exeC:\Users\admin\AppData\Local\Temp\br52d4ff
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3072
iexplore.exe
GET
37.59.34.205:80
http://download.memsource.com/production/updates/memsource-editor/win/archive/install/MemsourceEditor-6.225.7-windows.exe
FR
unknown
2804
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2804
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3072
iexplore.exe
37.59.34.205:80
download.memsource.com
OVH SAS
FR
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
download.memsource.com
  • 37.59.34.205
unknown

Threats

PID
Process
Class
Message
3072
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
TranslationEditor.exe
Unknown option "altgr"
TranslationEditor.exe
[ "13:53::176" ] TranslationEditor::ApplicationLocalisation::SetUp 0x5cf780 -> translation load failed "TranslationEditor_en_us"
TranslationEditor.exe
libpng warning: iCCP: known incorrect sRGB profile
TranslationEditor.exe
"[class TranslationEditor::LoginCall *]Network call error: " QNetworkReply::NetworkError(AuthenticationRequiredError) - "Host requires authentication"
TranslationEditor.exe
call error: "{\"errorCode\":\"AuthInvalidCredentials\",\"errorDescription\":null}"
TranslationEditor.exe
Call error: 7 - ""