| URL: | http://contentcdn.vtechda.com/vtechkidsDownload/FR-fre/1716/Setup/PC/Kidizoom1716_FR_fre_Setup.exe |
| Full analysis: | https://app.any.run/tasks/ab4a463b-e90e-4dca-865c-857d3cdb1540 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | June 14, 2019, 09:07:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 57F6E1E99CDCF632A7E36306C60C2EBD |
| SHA1: | 2E864061997C90EEDB40998FF37CC6692403971B |
| SHA256: | 67C24E44326702FA72D0F8F67D6B261F690D3F44DD5943E89CB600DD08EE26A3 |
| SSDEEP: | 3:N1KdKL8gsKEyThGNjvE8SXvUSRR3L13CA:CIEKfG9c1XMSRRb13CA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=940,1202593172576514276,2785419405118137926,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=3759865898777856456 --mojo-platform-channel-handle=3752 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1444 | "C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe" lauch | C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe | SetupLoaderWrapper.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: AgentMon Application Exit code: 0 Version: 5.0.1.0 Modules
| |||||||||||||||
| 1672 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3660 --on-initialized-event-handle=308 --parent-handle=312 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1720 | "C:\Users\admin\Downloads\Kidizoom1716_FR_fre_Setup.exe" | C:\Users\admin\Downloads\Kidizoom1716_FR_fre_Setup.exe | chrome.exe | ||||||||||||
User: admin Company: VTech Integrity Level: MEDIUM Description: Kidizoom_1716_FR_frePlugin Setup Exit code: 0 Version: 1.1.0.2 Modules
| |||||||||||||||
| 1900 | C:\Users\admin\AppData\Local\Temp\qt_temp.Gi17202799\ProdSetup.exe | C:\Users\admin\AppData\Local\Temp\qt_temp.Gi17202799\ProdSetup.exe | SetupLoader.exe | ||||||||||||
User: admin Company: VTech Integrity Level: HIGH Description: ProdSetup Exit code: 0 Version: 1.3.4.2 Modules
| |||||||||||||||
| 1976 | "C:\Users\admin\AppData\Local\Temp\qt_temp.Gi17202799\SetupLoader.exe" | C:\Users\admin\AppData\Local\Temp\qt_temp.Gi17202799\SetupLoader.exe | SetupLoaderWrapper.exe | ||||||||||||
User: admin Company: VTech Integrity Level: HIGH Description: Setup Loader Exit code: 0 Version: 0.9.5.0 Modules
| |||||||||||||||
| 2052 | "C:\Program Files\VTech\DownloadManager\System\KillALl.exe" "" | C:\Program Files\VTech\DownloadManager\System\KillALl.exe | DM_Cleanup.exe | ||||||||||||
User: admin Company: VTech Integrity Level: HIGH Description: Kill Application for Download Manager Exit code: 0 Version: 1, 3, 4, 0 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,1202593172576514276,2785419405118137926,131072 --enable-features=PasswordImport --service-pipe-token=9229381766526083586 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9229381766526083586 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2052 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=940,1202593172576514276,2785419405118137926,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=12093851127285970670 --mojo-platform-channel-handle=960 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 2440 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,1202593172576514276,2785419405118137926,131072 --enable-features=PasswordImport --service-pipe-token=18237179778706359896 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18237179778706359896 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2012 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3488-13197474229333984 |
Value: 0 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3272) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3272-13204976847855250 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\5418db45-e6de-4e19-abda-56aaa8a172dc.tmp | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3272 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_166855.png | US | image | 15.0 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_274105.png | US | image | 16.3 Kb | shared |
3272 | chrome.exe | GET | 200 | 143.204.214.17:80 | http://contentcdn.vtechda.com/vtechkidsDownload/FR-fre/1716/Setup/PC/Kidizoom1716_FR_fre_Setup.exe | US | executable | 14.7 Mb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_200939.png | US | image | 11.9 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_136105.png | US | image | 11.9 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_215659.png | US | image | 14.4 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_273405.png | US | image | 14.1 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_274505.png | US | image | 16.8 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_275205.png | US | image | 16.0 Kb | shared |
3880 | DownloadManager.exe | GET | 200 | 143.204.214.59:80 | http://contentcdn.vtechda.com/Data/CrossSell/Ver2/LLNHome/FR-fre/100x80_171605.png | US | image | 11.5 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3272 | chrome.exe | 172.217.22.35:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3272 | chrome.exe | 143.204.214.17:80 | contentcdn.vtechda.com | — | US | suspicious |
3272 | chrome.exe | 172.217.16.141:443 | accounts.google.com | Google Inc. | US | suspicious |
3272 | chrome.exe | 172.217.21.196:443 | www.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.21.238:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
1976 | SetupLoader.exe | 149.126.77.143:443 | www.vtechda.com | Incapsula Inc | DE | unknown |
1976 | SetupLoader.exe | 143.204.214.118:443 | contentcdn.vtechda.com | — | US | suspicious |
3272 | chrome.exe | 172.217.18.163:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3880 | DownloadManager.exe | 172.217.18.168:443 | ssl.google-analytics.com | Google Inc. | US | whitelisted |
3880 | DownloadManager.exe | 149.126.77.143:443 | www.vtechda.com | Incapsula Inc | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
contentcdn.vtechda.com |
| shared |
accounts.google.com |
| shared |
www.google.com |
| malicious |
ssl.gstatic.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
www.vtechda.com |
| unknown |
system.vtechda.com |
| shared |
www.gstatic.com |
| whitelisted |
clients1.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3272 | chrome.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
SetupLoader.exe | [IniXmlReader::set_file] Failed to open the DA configuration file "C:/Users/admin/AppData/Local/Temp/qt_temp.Gi17202799/Common.cfg"
|
SetupLoader.exe | [HVTechSysInfo::get_install_path] Failed to open the installation path record file "C:\ProgramData/VTech/DA/InstallPath/DAInstallationPath.xml"
|
SetupLoader.exe | QString::arg: Argument missing: Bienvenue dans l'Assistant d'Installation de l'Explor@ Park<sup>?</sup>, Kidizoom Smart Watch DX
|
SetupLoader.exe | QString::arg: Argument missing: L'Assistant vous aide ? d?marrer l'Explor@ Park<sup>?</sup> et ? installer tous les composants n?cessaires sur votre ordinateur.
Il est recommand? de fermer toutes les applications avant de continuer.
Cliquez sur Suivant pour continuer, ou Annuler pour quitter l'Assistant d'Installation., Kidizoom Smart Watch DX
|
SetupLoader.exe | [HVTechSysInfo::get_install_path] Failed to open the installation path record file "C:\ProgramData/VTech/DA/InstallPath/DAInstallationĸ |
SetupLoader.exe | [HVTechSysInfo::get_install_path] Failed to open the installation path record file "C:\ProgramData/VTech/DA/InstallPath/DAInstallationPath.xml"
|
SetupLoader.exe | dltotal 6.23091e+07 dlnow 14480
|
SetupLoader.exe | dltotal 6.23091e+07 dlnow 14480
|
SetupLoader.exe | dltotal 6.23091e+07 dlnow 14480
|
SetupLoader.exe | dltotal 6.23091e+07 dlnow 14480
|