| URL: | http://safetx.ahnlab.com/master/win/default/all/astx_setup.exe |
| Full analysis: | https://app.any.run/tasks/c7fdee34-e04d-4f78-9eed-c88dc680cd57 |
| Verdict: | Malicious activity |
| Threats: | A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools. |
| Analysis date: | May 08, 2020, 04:39:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 6213B395BB041D75C3498F115B55A9D7 |
| SHA1: | FD9A8D4F797A1A9DAE21B417265792EFB42A7E0F |
| SHA256: | 7077084861479FE86CDB5310D34DCE064C6DD2CFCB1D7F7B06C370C5106BCCBD |
| SSDEEP: | 3:N1KNEDCCJOICn8ffqEWdyAL4A:CWLOI2g/aJL4A |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 848 | "C:\Users\admin\Downloads\astx_setup.exe" | C:\Users\admin\Downloads\astx_setup.exe | — | chrome.exe | |||||||||||
User: admin Company: AhnLab, Inc. Integrity Level: MEDIUM Description: AhnLab Safe Transaction Setup Program. Exit code: 3221226540 Version: 1.3.64.1419 Modules
| |||||||||||||||
| 984 | "C:\Program Files\AhnLab\Safe Transaction\ASDWsc.exe" /as /register /accessflag:1 /uptodate:0 | C:\Program Files\AhnLab\Safe Transaction\ASDWsc.exe | — | ASDSvc.exe | |||||||||||
User: SYSTEM Company: AhnLab, Inc. Integrity Level: SYSTEM Description: ASDF WSC Control Application Exit code: 126 Version: 2, 5, 0, 75 Modules
| |||||||||||||||
| 1440 | netsh advfirewall firewall set rule name="AhnLab Safe Transaction" dir=in new action=allow program="C:\Program Files\AhnLab\Safe Transaction\StSess.exe" enable=yes | C:\Windows\system32\netsh.exe | — | stsess.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1456 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,11281495096146319585,17719010613494468361,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6259700909286238874 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2280 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1464 | "C:\Program Files\AhnLab\Safe Transaction\ASDWsc.exe" /av /register /accessflag:1 /uptodate:0 | C:\Program Files\AhnLab\Safe Transaction\ASDWsc.exe | — | ASDSvc.exe | |||||||||||
User: SYSTEM Company: AhnLab, Inc. Integrity Level: SYSTEM Description: ASDF WSC Control Application Exit code: 126 Version: 2, 5, 0, 75 Modules
| |||||||||||||||
| 1772 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1040,11281495096146319585,17719010613494468361,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=15688181619548024854 --mojo-platform-channel-handle=1056 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1792 | "C:\Program Files\AhnLab\Safe Transaction\AKDVE.exe" 1100010001001000000000000000000_AntiStealth_SafeTransactionF | C:\Program Files\AhnLab\Safe Transaction\AKDVE.exe | — | ASDSvc.exe | |||||||||||
User: SYSTEM Company: AhnLab, Inc. Integrity Level: SYSTEM Description: AKDVE Exit code: 0 Version: 2, 11, 0, 1 Modules
| |||||||||||||||
| 1844 | "C:\Program Files\AhnLab\Safe Transaction\Cert\nss\certutil" -A -n "ASTxRoot2" -d sql:"C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default" -t "C,," -i "C:\Program Files\AhnLab\Safe Transaction\Cert\ca2.der" | C:\Program Files\AhnLab\Safe Transaction\Cert\nss\certutil.exe | stsess.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1852 | netsh advfirewall firewall delete rule name="AhnLab Safe Transaction" dir=in | C:\Windows\system32\netsh.exe | — | V3Medic.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1880 | "C:\Program Files\AhnLab\Safe Transaction\stsess.exe" /tray | C:\Program Files\AhnLab\Safe Transaction\stsess.exe | — | ASDSvc.exe | |||||||||||
User: admin Company: AhnLab, Inc. Integrity Level: MEDIUM Description: AhnLab Safe Transaction Application Exit code: 0 Version: 1, 4, 0, 76 Modules
| |||||||||||||||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3120-13213713943555664 |
Value: 0 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2344-13233386360686250 |
Value: 259 | |||
| (PID) Process: | (2344) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5EB4E279-928.pma | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\b7834849-9543-4a8d-b2e1-f2036c804fe2.tmp | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2344 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFa88607.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?c=2&p=Ho50vAvX+MM6e7hWk9nBPxLNPvcO8yEaFMG0+r0MqjI=&k=1 | IE | — | — | unknown |
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?c=65&p=ysb1tHFox99KneFEGDugxBBwGsNPlTEh3sFfTG1AKHQ=&k=1 | IE | text | 56 b | unknown |
3228 | stsess.exe | HEAD | 200 | 163.171.75.66:80 | http://webclinic.ahnlab.com/astx/policy/starter_ply.html | US | compressed | 329 Kb | suspicious |
3228 | stsess.exe | HEAD | 200 | 163.171.75.66:80 | http://webclinic.ahnlab.com/astx/policy/extraopn_ply.html | US | compressed | 62.4 Kb | suspicious |
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?d=28&p=Ho50vAvX+MM6e7hWk9nBPxLNPvcO8yEaFMG0+r0MqjI=&k=1 | IE | text | 1.05 Kb | unknown |
3228 | stsess.exe | HEAD | 200 | 163.171.75.66:80 | http://webclinic.ahnlab.com/astx/policy/ply_ver.html | US | compressed | 7.34 Kb | suspicious |
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?c=2&p=Ho50vAvX+MM6e7hWk9nBPxLNPvcO8yEaFMG0+r0MqjI=&k=1 | IE | text | 396 b | unknown |
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?d=28&p=Ho50vAvX+MM6e7hWk9nBPxLNPvcO8yEaFMG0+r0MqjI=&k=1 | IE | text | 1.05 Kb | unknown |
3996 | chrome.exe | GET | 200 | 101.79.211.36:80 | http://safetx.ahnlab.com/master/win/default/all/astx_setup.exe | KR | executable | 47.7 Mb | suspicious |
3432 | ASDSvc.exe | GET | 200 | 34.246.64.247:80 | http://gms.ahnlab.com/jk?c=2&p=Ho50vAvX+MM6e7hWk9nBPxLNPvcO8yEaFMG0+r0MqjI=&k=1 | IE | text | 160 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3996 | chrome.exe | 216.58.210.3:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3996 | chrome.exe | 172.217.22.14:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
3996 | chrome.exe | 101.79.211.36:80 | safetx.ahnlab.com | CDNetworks | KR | suspicious |
3996 | chrome.exe | 172.217.18.3:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3432 | ASDSvc.exe | 34.249.110.217:80 | gms.ahnlab.com | Amazon.com, Inc. | IE | unknown |
3432 | ASDSvc.exe | 34.246.64.247:80 | gms.ahnlab.com | Amazon.com, Inc. | IE | unknown |
3996 | chrome.exe | 216.58.205.238:443 | clients1.google.com | Google Inc. | US | whitelisted |
3996 | chrome.exe | 172.217.18.4:443 | www.google.com | Google Inc. | US | whitelisted |
3996 | chrome.exe | 172.217.16.141:443 | accounts.google.com | Google Inc. | US | suspicious |
3228 | stsess.exe | 163.171.75.66:80 | webclinic.ahnlab.com | CDNetworks | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
safetx.ahnlab.com |
| suspicious |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
ssl.gstatic.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
gms.ahnlab.com |
| unknown |
webclinic.ahnlab.com |
| suspicious |
clients1.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3996 | chrome.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |