File name:

emailtrackerpro-9.0h-installer_rQYLp-1.exe

Full analysis: https://app.any.run/tasks/2aa5dfb1-20ad-4c66-816e-e7282b98e05f
Verdict: Malicious activity
Analysis date: February 29, 2024, 14:35:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DE47A58A4D39F2C5A638E3DA1FE0196B

SHA1:

188B7CFD0365C7BF1DA3AD7AAB3EE9D4B5EC40D1

SHA256:

8124E20A1FB5075AB91DCB42521A77D901DD3F8CD2088229D2A486DD6940916B

SSDEEP:

49152:L7HecD4dnbibBlwF8pb6fySgHq7IoYYmh8wK+/TG7LsPAdm/lkVU0/v2PegkEajo:3+cD4dnjF8pefyJHmI1YmLKlvsPAdm/6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 1384)
      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 2752)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • icarus.exe (PID: 956)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • java.exe (PID: 2344)
      • java.exe (PID: 3584)
      • icarus.exe (PID: 2240)
      • icarus.exe (PID: 2244)
    • Creates a writable file in the system directory

      • icarus.exe (PID: 2244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 2752)
      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 1384)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • avg_antivirus_free_setup.exe (PID: 2340)
      • icarus.exe (PID: 956)
      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • icarus.exe (PID: 2244)
      • java.exe (PID: 2344)
      • java.exe (PID: 3584)
      • icarus.exe (PID: 2240)
    • Reads security settings of Internet Explorer

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
    • Reads settings of System Certificates

      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
    • Reads the Windows owner or organization settings

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
    • Reads the Internet Settings

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
    • Adds/modifies Windows certificates

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
    • The process creates files with name similar to system file names

      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • icarus.exe (PID: 2244)
    • Starts itself from another location

      • icarus.exe (PID: 956)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
    • Checks for Java to be installed

      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • java.exe (PID: 2344)
      • java.exe (PID: 3584)
    • Process drops legitimate windows executable

      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • icarus.exe (PID: 2244)
    • Creates a software uninstall entry

      • emailtrackerpro-9.0h-installer.exe (PID: 764)
    • The process drops C-runtime libraries

      • icarus.exe (PID: 2244)
    • Drops a system driver (possible attempt to evade defenses)

      • icarus.exe (PID: 2244)
    • The process verifies whether the antivirus software is installed

      • icarus.exe (PID: 2240)
      • icarus.exe (PID: 2244)
  • INFO

    • Checks supported languages

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3668)
      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 1384)
      • wmpnscfg.exe (PID: 3464)
      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 2752)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • icarus.exe (PID: 2244)
      • icarus.exe (PID: 2240)
      • icarus.exe (PID: 956)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • emailtrackerpro.exe (PID: 920)
      • java.exe (PID: 2344)
      • java.exe (PID: 3584)
    • Create files in a temporary directory

      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 1384)
      • emailtrackerpro-9.0h-installer_rQYLp-1.exe (PID: 2752)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • icarus.exe (PID: 956)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • icarus.exe (PID: 2240)
      • icarus.exe (PID: 2244)
      • emailtrackerpro.exe (PID: 920)
      • java.exe (PID: 2344)
      • java.exe (PID: 3584)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3464)
      • explorer.exe (PID: 848)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • emailtrackerpro-9.0h-installer.exe (PID: 968)
      • msedge.exe (PID: 1172)
    • Reads the computer name

      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3668)
      • wmpnscfg.exe (PID: 3464)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer.exe (PID: 3960)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • icarus.exe (PID: 956)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • icarus.exe (PID: 2244)
      • icarus.exe (PID: 2240)
      • java.exe (PID: 3584)
    • Reads the machine GUID from the registry

      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • icarus.exe (PID: 956)
      • icarus.exe (PID: 2244)
      • icarus.exe (PID: 2240)
    • Reads the software policy settings

      • avg_antivirus_free_setup.exe (PID: 2340)
      • emailtrackerpro-9.0h-installer_rQYLp-1.tmp (PID: 3848)
      • avg_antivirus_free_online_setup.exe (PID: 2648)
    • Creates files in the program directory

      • avg_antivirus_free_online_setup.exe (PID: 2648)
      • icarus.exe (PID: 956)
      • icarus.exe (PID: 2244)
      • emailtrackerpro-9.0h-installer.exe (PID: 764)
      • java.exe (PID: 2344)
      • icarus.exe (PID: 2240)
    • Reads CPU info

      • icarus.exe (PID: 956)
      • icarus.exe (PID: 2244)
      • icarus.exe (PID: 2240)
    • Dropped object may contain TOR URL's

      • icarus.exe (PID: 956)
      • icarus.exe (PID: 2244)
      • icarus.exe (PID: 2240)
    • Reads Environment values

      • icarus.exe (PID: 2244)
    • Creates files or folders in the user directory

      • emailtrackerpro-9.0h-installer.exe (PID: 764)
    • Application launched itself

      • msedge.exe (PID: 1020)
      • msedge.exe (PID: 1172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 4.11.2.1487
ProductVersionNumber: 4.11.2.1487
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 4.11.2.1487
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 4.11.2.1487
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
87
Monitored processes
38
Malicious processes
13
Suspicious processes
1

Behavior graph

Click at the process to see the details
start emailtrackerpro-9.0h-installer_rqylp-1.exe emailtrackerpro-9.0h-installer_rqylp-1.tmp no specs emailtrackerpro-9.0h-installer_rqylp-1.exe emailtrackerpro-9.0h-installer_rqylp-1.tmp wmpnscfg.exe no specs avg_antivirus_free_setup.exe avg_antivirus_free_online_setup.exe emailtrackerpro-9.0h-installer.exe icarus.exe explorer.exe no specs icarus.exe icarus.exe emailtrackerpro-9.0h-installer.exe no specs emailtrackerpro-9.0h-installer.exe emailtrackerpro.exe no specs msedge.exe no specs java.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe icacls.exe no specs msedge.exe no specs java.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1284 --field-trial-handle=1416,i,2487275378328038316,7299234763841156367,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
764"C:\Users\admin\Downloads\emailtrackerpro-9.0h-installer.exe" C:\Users\admin\Downloads\emailtrackerpro-9.0h-installer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\emailtrackerpro-9.0h-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
848"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
920"C:\Program Files\eMailTrackerPro\emailtrackerpro.exe"C:\Program Files\eMailTrackerPro\emailtrackerpro.exeemailtrackerpro-9.0h-installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\emailtrackerpro\emailtrackerpro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
956C:\Windows\Temp\asw-7c69a6f3-247f-469f-a07c-ebee52494e98\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-7c69a6f3-247f-469f-a07c-ebee52494e98\icarus-info.xml /install /silent /ws /psh:92pTu5f8VuvcZQxpkghwTcCHeTkBSOIG3Ad8HK6SeEEcmemAgc8caccntsMhtOzdI9bjv0e0UWoh14 /cookie:mmm_irs_ppi_902_451_o /track-guid:4e482a1c-00f3-49c0-89ec-04a9abfce430 /edat_dir:C:\Windows\Temp\asw.cf4dadc129d413bcC:\Windows\Temp\asw-7c69a6f3-247f-469f-a07c-ebee52494e98\common\icarus.exe
avg_antivirus_free_online_setup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Installer
Exit code:
0
Version:
24.1.6758.0
Modules
Images
c:\windows\temp\asw-7c69a6f3-247f-469f-a07c-ebee52494e98\common\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
968"C:\Users\admin\Downloads\emailtrackerpro-9.0h-installer.exe" C:\Users\admin\Downloads\emailtrackerpro-9.0h-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\emailtrackerpro-9.0h-installer.exe
c:\windows\system32\ntdll.dll
1020"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Program Files\eMailTrackerPro\readme.htmlC:\Program Files\Microsoft\Edge\Application\msedge.exeemailtrackerpro-9.0h-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate "C:\Program Files\eMailTrackerPro\readme.html"C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1384"C:\Users\admin\AppData\Local\Temp\emailtrackerpro-9.0h-installer_rQYLp-1.exe" C:\Users\admin\AppData\Local\Temp\emailtrackerpro-9.0h-installer_rQYLp-1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Softonic International SA
Exit code:
0
Version:
4.11.2.1487
Modules
Images
c:\users\admin\appdata\local\temp\emailtrackerpro-9.0h-installer_rqylp-1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3576 --field-trial-handle=1364,i,12358583328397940,5965368661417391694,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
33 879
Read events
33 475
Write events
379
Delete events
25

Modification events

(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
080F0000CE4D4D831C6BDA01
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
7A4121D5D2606057C15263F09FED46E21C86ED06D3C62B819590B5AC535733C1
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:CABD2A79A1076A31F21D253635CB039D4329A5E8
Value:
(PID) Process:(3848) emailtrackerpro-9.0h-installer_rQYLp-1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Operation:writeName:Blob
Value:
0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
Executable files
499
Suspicious files
638
Text files
508
Unknown types
271

Dropped files

PID
Process
Filename
Type
2752emailtrackerpro-9.0h-installer_rQYLp-1.exeC:\Users\admin\AppData\Local\Temp\is-BPSKT.tmp\emailtrackerpro-9.0h-installer_rQYLp-1.tmpexecutable
MD5:F49065A8DF4CF3BE771E987AE950F6E5
SHA256:00D9E9F7333CFB0ED27EC591C24DD9680328BDDA4E3ED8F023700ADE43670263
1384emailtrackerpro-9.0h-installer_rQYLp-1.exeC:\Users\admin\AppData\Local\Temp\is-P8I9C.tmp\emailtrackerpro-9.0h-installer_rQYLp-1.tmpexecutable
MD5:F49065A8DF4CF3BE771E987AE950F6E5
SHA256:00D9E9F7333CFB0ED27EC591C24DD9680328BDDA4E3ED8F023700ADE43670263
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\component0.zipcompressed
MD5:56B0D3E1B154AE65682C167D25EC94A6
SHA256:434BFC9E005A7C8EE249B62F176979F1B4CDE69484DB1683EA07A63E6C1E93DE
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\AVG_AV.pngimage
MD5:5EF5291810C454A35F76D976105F37CC
SHA256:03E69E8C87732C625DF2F628AC63BD145268F9DEA9C5F3DD3670B1CF349A995C
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\mainlogo.pngimage
MD5:E6C65AFEBDEB06FF63FDAD2555C429DD
SHA256:1CBE31A78108CB4FBBA5C2EF4152A7D319EF66BD933587116B0199CD875CD4A3
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\is-0OIML.tmpimage
MD5:E6C65AFEBDEB06FF63FDAD2555C429DD
SHA256:1CBE31A78108CB4FBBA5C2EF4152A7D319EF66BD933587116B0199CD875CD4A3
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\v.pngimage
MD5:94E23586BB0FF2A1BD4E6889155C9DBF
SHA256:940ECF2325D812F8780239B0A1417D8774DE63AF615AC7EA1A8818F22A8D6D72
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\AppData\Local\Temp\is-D31E8.tmp\x.pngimage
MD5:AD693B4CD2C00A6162C1F8DCA82BB867
SHA256:C773A249E6427B76AB29DC6303193584C5EA7B97B073271A7A69AD8F082B7039
3848emailtrackerpro-9.0h-installer_rQYLp-1.tmpC:\Users\admin\Downloads\emailtrackerpro-9.0h-installer.exeexecutable
MD5:7103CC683E16209150E7D8D13B109615
SHA256:37EFACB8411234DD9882D8D3A8709F492EB2ED252132DA099A11BE07C0B4CCB0
2648avg_antivirus_free_online_setup.exeC:\ProgramData\AVG\Icarus\Logs\sfx.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
57
DNS requests
61
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2340
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
2340
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
2340
avg_antivirus_free_setup.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
3584
java.exe
GET
302
38.100.141.80:80
http://www.emailtrackerpro.com/updates/updates.txt
unknown
html
334 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3848
emailtrackerpro-9.0h-installer_rQYLp-1.tmp
18.245.62.156:443
d37yhbgnthy672.cloudfront.net
US
unknown
3848
emailtrackerpro-9.0h-installer_rQYLp-1.tmp
23.67.132.99:443
images.sftcdn.net
AKAMAI-AS
DE
unknown
3848
emailtrackerpro-9.0h-installer_rQYLp-1.tmp
199.232.194.133:443
gsf-fl.softonic.com
FASTLY
US
unknown
2340
avg_antivirus_free_setup.exe
142.250.186.78:80
www.google-analytics.com
GOOGLE
US
whitelisted
2340
avg_antivirus_free_setup.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2340
avg_antivirus_free_setup.exe
23.32.97.64:443
honzik.avcdn.net
AKAMAI-AS
SE
unknown
2648
avg_antivirus_free_online_setup.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown

DNS requests

Domain
IP
Reputation
d37yhbgnthy672.cloudfront.net
  • 18.245.62.156
  • 18.245.62.184
  • 18.245.62.87
  • 18.245.62.181
unknown
images.sftcdn.net
  • 23.67.132.99
whitelisted
gsf-fl.softonic.com
  • 199.232.194.133
  • 199.232.198.133
whitelisted
honzik.avcdn.net
  • 23.32.97.64
  • 2a02:26f0:3500:f9c::240d
  • 2a02:26f0:3500:f92::240d
unknown
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.186.78
whitelisted
analytics.avcdn.net
  • 34.117.223.223
unknown
shepherd.avcdn.net
  • 34.160.176.28
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

PID
Process
Class
Message
3584
java.exe
Potentially Bad Traffic
ET POLICY Vulnerable Java Version 1.8.x Detected
No debug info