download: | oanda4setup.exe |
Full analysis: | https://app.any.run/tasks/8d440be3-7310-4300-83a8-be152d7a07ce |
Verdict: | Malicious activity |
Analysis date: | February 11, 2019, 04:05:53 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | 0DB00A483673DAA7E3355A9837DB4090 |
SHA1: | B205351045302F1A6608A0351330E78B3206DBE9 |
SHA256: | 7790740C1975A6903BDA8CC5DB687D6E4AF7CE2AFF46EA101074631EFBE63F2F |
SSDEEP: | 24576:Y+Gxs/2sDdVHpk4CtdjNz88X10h603HOTXapEijstHSmjd:zGxWDXHpk/jNzJl63sXapItH1R |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
ProductVersion: | 5.0.0.1983 |
---|---|
ProductName: | Setup |
OriginalFileName: | Setup |
LegalTrademarks: | MetaTrader |
LegalCopyright: | © 2000-2019, MetaQuotes Software Corp. |
InternalName: | Setup |
FileVersion: | 5.0.0.1983 |
FileDescription: | Setup |
CompanyName: | MetaQuotes Software Corp. |
Comments: | https://www.metaquotes.net |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.0.0.1983 |
FileVersionNumber: | 5.0.0.1983 |
Subsystem: | Windows GUI |
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x312d70 |
UninitializedDataSize: | 2224128 |
InitializedDataSize: | 159744 |
CodeSize: | 999424 |
LinkerVersion: | 14.16 |
PEType: | PE32 |
TimeStamp: | 1970:01:14 10:16:48+01:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3000 | "C:\Users\admin\AppData\Local\Temp\oanda4setup.exe" | C:\Users\admin\AppData\Local\Temp\oanda4setup.exe | — | explorer.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 5.0.0.1983 | ||||
3628 | "C:\Users\admin\AppData\Local\Temp\oanda4setup.exe" | C:\Users\admin\AppData\Local\Temp\oanda4setup.exe | oanda4setup.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: Setup Exit code: 1 Version: 5.0.0.1983 | ||||
3888 | "C:\Program Files\OANDA - MetaTrader\terminal.exe" /install | C:\Program Files\OANDA - MetaTrader\terminal.exe | — | oanda4setup.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 | ||||
3108 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | oanda4setup.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3800 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3108 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3816 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | oanda4setup.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
684 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3816 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3272 | "C:\Windows\explorer.exe" "C:\Program Files\OANDA - MetaTrader\terminal.exe" | C:\Windows\explorer.exe | — | oanda4setup.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3480 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2896 | "C:\Program Files\OANDA - MetaTrader\terminal.exe" | C:\Program Files\OANDA - MetaTrader\terminal.exe | explorer.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader Version: 4.0.0.1170 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A90.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A92.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A91.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A93.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A96.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A94.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A95.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9AA7.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9B35.tmp | — | |
MD5:— | SHA256:— | |||
3628 | oanda4setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9B36.tmp | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3628 | oanda4setup.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 2.16.186.56:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
3628 | oanda4setup.exe | GET | 304 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 55.2 Kb | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | unknown | der | 969 b | whitelisted |
3628 | oanda4setup.exe | GET | 200 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | unknown | der | 969 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3628 | oanda4setup.exe | 104.41.54.220:443 | — | Microsoft Corporation | BR | whitelisted |
3628 | oanda4setup.exe | 206.221.189.58:443 | — | Choopa, LLC | US | unknown |
3628 | oanda4setup.exe | 88.212.244.84:443 | — | Servers.com, Inc. | RU | unknown |
3628 | oanda4setup.exe | 197.189.238.138:443 | — | HETZNER | ZA | unknown |
3628 | oanda4setup.exe | 47.52.161.165:443 | — | Alibaba (China) Technology Co., Ltd. | HK | unknown |
3628 | oanda4setup.exe | 142.0.194.252:443 | — | Servers.com, Inc. | US | unknown |
3628 | oanda4setup.exe | 47.95.9.170:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3628 | oanda4setup.exe | 47.245.38.25:443 | — | — | US | unknown |
3628 | oanda4setup.exe | 52.184.28.1:443 | — | Microsoft Corporation | HK | unknown |
3628 | oanda4setup.exe | 78.140.180.43:443 | api1.mql5.com | Webzilla B.V. | NL | suspicious |
Domain | IP | Reputation |
---|---|---|
content.mql5.com |
| suspicious |
api14.mql5.com |
| unknown |
www.download.windowsupdate.com |
| whitelisted |
api1.mql5.com |
| suspicious |
www.bing.com |
| whitelisted |
www.mql5.com |
| suspicious |