File name:

HotspotShield-8.7.1-plain-773-PreActive.rar

Full analysis: https://app.any.run/tasks/3a1e6ed3-aecb-4274-93e7-fd90bf6d90da
Verdict: Malicious activity
Analysis date: May 15, 2021, 07:24:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

03FFF90A482FE51B10456F3CAEDBE85E

SHA1:

C46C1F8F74CA04F5D02020AAFF86BEFFE5F6FB01

SHA256:

823EBA7BAE338ACABB5400358463B88C0E07C708015CC23876B5511C16572A04

SSDEEP:

393216:woeCimK6iQY4E1lRyktqNkSQYcuuua0A0Q1Svqt:xK0i3tqRciaUQ6O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads the Task Scheduler DLL interface

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Loads dropped or rewritten executable

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tap-windows-9.21.2.exe (PID: 1544)
      • cmw_srv.exe (PID: 3996)
    • Application was dropped or rewritten from another process

      • tap-windows-9.21.2.exe (PID: 1544)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2792)
      • nsEC0B.tmp (PID: 4080)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tapinstall.exe (PID: 2748)
      • nsEDC1.tmp (PID: 2416)
      • tapinstall.exe (PID: 1184)
      • cmw_srv.exe (PID: 3996)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 948)
      • hsscp.exe (PID: 2352)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
    • Drops executable file immediately after starts

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • DrvInst.exe (PID: 576)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
    • Changes settings of System certificates

      • tapinstall.exe (PID: 1184)
      • cmw_srv.exe (PID: 3996)
    • Changes the autorun value in the registry

      • DrvInst.exe (PID: 2880)
  • SUSPICIOUS

    • Creates files in the user directory

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
    • Executable content was dropped or overwritten

      • tap-windows-9.21.2.exe (PID: 1544)
      • WinRAR.exe (PID: 2800)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
    • Reads Environment values

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • cmw_srv.exe (PID: 3996)
    • Creates files in the Windows directory

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • cmw_srv.exe (PID: 3996)
    • Drops a file that was compiled in debug mode

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • WinRAR.exe (PID: 2800)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tap-windows-9.21.2.exe (PID: 1544)
      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Drops a file with too old compile date

      • tap-windows-9.21.2.exe (PID: 1544)
      • tap-windows-9.21.2.EXE (PID: 544)
    • Creates a directory in Program Files

      • tap-windows-9.21.2.EXE (PID: 544)
    • Creates files in the program directory

      • tap-windows-9.21.2.EXE (PID: 544)
      • cmw_srv.exe (PID: 3996)
    • Starts application with an unusual extension

      • tap-windows-9.21.2.EXE (PID: 544)
    • Adds / modifies Windows certificates

      • tapinstall.exe (PID: 1184)
      • cmw_srv.exe (PID: 3996)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 576)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • cmw_srv.exe (PID: 3996)
    • Executed via COM

      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Creates a software uninstall entry

      • tap-windows-9.21.2.EXE (PID: 544)
    • Application launched itself

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Drops a file with a compile date too recent

      • DrvInst.exe (PID: 576)
      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 2880)
    • Executed as Windows Service

      • cmw_srv.exe (PID: 3996)
  • INFO

    • Reads the hosts file

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Searches for installed software

      • DrvInst.exe (PID: 576)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2636)
      • MsiExec.exe (PID: 1912)
      • MsiExec.exe (PID: 1464)
    • Reads settings of System Certificates

      • cmw_srv.exe (PID: 3996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
19
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start winrar.exe hotspotshield-8.7.1-plain-773-preactive.exe no specs hotspotshield-8.7.1-plain-773-preactive.exe msiexec.exe no specs hotspotshield-8.7.1-plain-773-preactive.exe tap-windows-9.21.2.exe tap-windows-9.21.2.exe nsec0b.tmp no specs tapinstall.exe no specs nsedc1.tmp no specs tapinstall.exe drvinst.exe rundll32.exe no specs drvinst.exe hotspotshield-8.7.1-plain-773-preactive.exe no specs msiexec.exe no specs msiexec.exe no specs cmw_srv.exe hsscp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
544C:\Users\admin\AppData\Local\Temp\tap-windows-9.21.2\tap-windows-9.21.2.EXE /SC:\Users\admin\AppData\Local\Temp\tap-windows-9.21.2\tap-windows-9.21.2.EXE
tap-windows-9.21.2.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\tap-windows-9.21.2\tap-windows-9.21.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
576DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2ae74538-b29e-6d5a-0acd-7035bf8e747f}\oemvista.inf" "0" "6d14a44ff" "000003F4" "WinSta0\Default" "000005D0" "208" "c:\program files\tap-windows\driver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
924rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5571d6c4-112c-2a51-6890-8a07eb99bc01} Global\{27461522-427e-4b6e-5a83-123dc4d67725} C:\Windows\System32\DriverStore\Temp\{5d92e5f6-851b-1f75-2fcd-fa7b02348c19}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{5d92e5f6-851b-1f75-2fcd-fa7b02348c19}\tap0901.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
948"C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe" /i "C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.msi" AI_EUIMSI=1 APPDIR="C:\Program Files\Hotspot Shield" SHORTCUTDIR="C:\Users\Public\Desktop" SECONDSEQUENCE="1" CLIENTPROCESSID="1396" AI_MORE_CMD_LINE=1C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exeHotspotShield-8.7.1-plain-773-PreActive.exe
User:
admin
Company:
hss721.blogspot.com
Integrity Level:
HIGH
Description:
Hotspot Shield 8.7.1 Pre-Active
Exit code:
0
Version:
8.7.1.11380
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2800.35014\hotspotshield-8.7.1-plain-773-preactive.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1184"C:\Program Files\TAP-Windows\bin\tapinstall.exe" install "C:\Program Files\TAP-Windows\driver\OemVista.inf" tap0901C:\Program Files\TAP-Windows\bin\tapinstall.exe
nsEDC1.tmp
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\tap-windows\bin\tapinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1396"C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe
WinRAR.exe
User:
admin
Company:
hss721.blogspot.com
Integrity Level:
HIGH
Description:
Hotspot Shield 8.7.1 Pre-Active
Exit code:
0
Version:
8.7.1.11380
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2800.35014\hotspotshield-8.7.1-plain-773-preactive.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1464C:\Windows\system32\MsiExec.exe -Embedding B61C172271515E81D46E9686D98CD71B CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1544"C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active\prerequisites\tap-windows-9.21.2.exe" C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active\prerequisites\tap-windows-9.21.2.exe
HotspotShield-8.7.1-plain-773-PreActive.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\hss721.blogspot.com\hotspot shield 8.7.1 pre-active\prerequisites\tap-windows-9.21.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1912C:\Windows\system32\MsiExec.exe -Embedding 3886994E12B1BB864732A7F485AAA76AC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2352"C:\Program Files\Hotspot Shield\bin\hsscp.exe" "-closeupgrade" "-quit"C:\Program Files\Hotspot Shield\bin\hsscp.execmw_srv.exe
User:
admin
Company:
AnchorFree Inc.
Integrity Level:
MEDIUM
Description:
Hotspot Shield
Exit code:
0
Version:
8.7.1.11380
Total events
4 106
Read events
3 624
Write events
432
Delete events
50

Modification events

(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HotspotShield-8.7.1-plain-773-PreActive.rar
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
25
Suspicious files
21
Text files
256
Unknown types
5

Dropped files

PID
Process
Filename
Type
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\holder0.aiph
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID739.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID7D6.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID7F6.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID826.tmp
MD5:
SHA256:
2800WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exeexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.msiexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.x64.msiexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.aiuiexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1396\custiconimage
MD5:3EAEBDADE778394F06B29659C9C01ED7
SHA256:719E644C31D0CC6B891F6A1253655DFBA39A3B78E06D24817BE1D8492B172B48
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3996
cmw_srv.exe
13.35.253.121:443
d3sdizpx54za7n.cloudfront.net
US
shared
3996
cmw_srv.exe
13.35.253.8:443
d3sdizpx54za7n.cloudfront.net
US
shared
3996
cmw_srv.exe
107.178.254.148:443
control.kochava.com
Google Inc.
US
whitelisted
3996
cmw_srv.exe
13.35.253.22:443
d3sdizpx54za7n.cloudfront.net
US
unknown
13.32.23.40:443
d1o29kof4patkc.cloudfront.net
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
hsselite.com
  • 184.169.221.190
  • 52.9.81.184
whitelisted
www.hsselite.com
  • 52.9.81.184
  • 184.169.221.190
unknown
d3sdizpx54za7n.cloudfront.net
  • 13.35.253.22
  • 13.35.253.8
  • 13.35.253.178
  • 13.35.253.121
shared
control.kochava.com
  • 107.178.254.148
unknown
d1o29kof4patkc.cloudfront.net
  • 13.32.23.40
  • 13.32.23.120
  • 13.32.23.91
  • 13.32.23.55
shared

Threats

No threats detected
No debug info