File name:

HotspotShield-8.7.1-plain-773-PreActive.rar

Full analysis: https://app.any.run/tasks/3a1e6ed3-aecb-4274-93e7-fd90bf6d90da
Verdict: Malicious activity
Analysis date: May 15, 2021, 07:24:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

03FFF90A482FE51B10456F3CAEDBE85E

SHA1:

C46C1F8F74CA04F5D02020AAFF86BEFFE5F6FB01

SHA256:

823EBA7BAE338ACABB5400358463B88C0E07C708015CC23876B5511C16572A04

SSDEEP:

393216:woeCimK6iQY4E1lRyktqNkSQYcuuua0A0Q1Svqt:xK0i3tqRciaUQ6O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2792)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • tapinstall.exe (PID: 2748)
      • tap-windows-9.21.2.EXE (PID: 544)
      • nsEC0B.tmp (PID: 4080)
      • nsEDC1.tmp (PID: 2416)
      • tapinstall.exe (PID: 1184)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 948)
      • cmw_srv.exe (PID: 3996)
      • hsscp.exe (PID: 2352)
      • tap-windows-9.21.2.exe (PID: 1544)
    • Drops executable file immediately after starts

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
      • DrvInst.exe (PID: 576)
    • Loads the Task Scheduler DLL interface

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Loads dropped or rewritten executable

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • tap-windows-9.21.2.exe (PID: 1544)
      • tap-windows-9.21.2.EXE (PID: 544)
      • cmw_srv.exe (PID: 3996)
    • Changes settings of System certificates

      • tapinstall.exe (PID: 1184)
      • cmw_srv.exe (PID: 3996)
    • Changes the autorun value in the registry

      • DrvInst.exe (PID: 2880)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • WinRAR.exe (PID: 2800)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • tap-windows-9.21.2.exe (PID: 1544)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2800)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • tap-windows-9.21.2.EXE (PID: 544)
      • tap-windows-9.21.2.exe (PID: 1544)
      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Creates files in the user directory

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 2552)
      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Reads Environment values

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • cmw_srv.exe (PID: 3996)
    • Creates files in the Windows directory

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • cmw_srv.exe (PID: 3996)
    • Drops a file with too old compile date

      • tap-windows-9.21.2.EXE (PID: 544)
      • tap-windows-9.21.2.exe (PID: 1544)
    • Creates a directory in Program Files

      • tap-windows-9.21.2.EXE (PID: 544)
    • Creates files in the program directory

      • tap-windows-9.21.2.EXE (PID: 544)
      • cmw_srv.exe (PID: 3996)
    • Starts application with an unusual extension

      • tap-windows-9.21.2.EXE (PID: 544)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
      • cmw_srv.exe (PID: 3996)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 576)
    • Drops a file with a compile date too recent

      • tapinstall.exe (PID: 1184)
      • DrvInst.exe (PID: 576)
      • DrvInst.exe (PID: 2880)
    • Executed via COM

      • DrvInst.exe (PID: 2880)
      • DrvInst.exe (PID: 576)
    • Adds / modifies Windows certificates

      • tapinstall.exe (PID: 1184)
      • cmw_srv.exe (PID: 3996)
    • Application launched itself

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Executed as Windows Service

      • cmw_srv.exe (PID: 3996)
    • Creates a software uninstall entry

      • tap-windows-9.21.2.EXE (PID: 544)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1464)
      • MsiExec.exe (PID: 2636)
      • MsiExec.exe (PID: 1912)
    • Reads the hosts file

      • HotspotShield-8.7.1-plain-773-PreActive.exe (PID: 1396)
    • Searches for installed software

      • DrvInst.exe (PID: 576)
    • Reads settings of System Certificates

      • cmw_srv.exe (PID: 3996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
19
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start winrar.exe hotspotshield-8.7.1-plain-773-preactive.exe no specs hotspotshield-8.7.1-plain-773-preactive.exe msiexec.exe no specs hotspotshield-8.7.1-plain-773-preactive.exe tap-windows-9.21.2.exe tap-windows-9.21.2.exe nsec0b.tmp no specs tapinstall.exe no specs nsedc1.tmp no specs tapinstall.exe drvinst.exe rundll32.exe no specs drvinst.exe hotspotshield-8.7.1-plain-773-preactive.exe no specs msiexec.exe no specs msiexec.exe no specs cmw_srv.exe hsscp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
544C:\Users\admin\AppData\Local\Temp\tap-windows-9.21.2\tap-windows-9.21.2.EXE /SC:\Users\admin\AppData\Local\Temp\tap-windows-9.21.2\tap-windows-9.21.2.EXE
tap-windows-9.21.2.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\tap-windows-9.21.2\tap-windows-9.21.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
576DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2ae74538-b29e-6d5a-0acd-7035bf8e747f}\oemvista.inf" "0" "6d14a44ff" "000003F4" "WinSta0\Default" "000005D0" "208" "c:\program files\tap-windows\driver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
924rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5571d6c4-112c-2a51-6890-8a07eb99bc01} Global\{27461522-427e-4b6e-5a83-123dc4d67725} C:\Windows\System32\DriverStore\Temp\{5d92e5f6-851b-1f75-2fcd-fa7b02348c19}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{5d92e5f6-851b-1f75-2fcd-fa7b02348c19}\tap0901.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
948"C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe" /i "C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.msi" AI_EUIMSI=1 APPDIR="C:\Program Files\Hotspot Shield" SHORTCUTDIR="C:\Users\Public\Desktop" SECONDSEQUENCE="1" CLIENTPROCESSID="1396" AI_MORE_CMD_LINE=1C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exeHotspotShield-8.7.1-plain-773-PreActive.exe
User:
admin
Company:
hss721.blogspot.com
Integrity Level:
HIGH
Description:
Hotspot Shield 8.7.1 Pre-Active
Exit code:
0
Version:
8.7.1.11380
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2800.35014\hotspotshield-8.7.1-plain-773-preactive.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1184"C:\Program Files\TAP-Windows\bin\tapinstall.exe" install "C:\Program Files\TAP-Windows\driver\OemVista.inf" tap0901C:\Program Files\TAP-Windows\bin\tapinstall.exe
nsEDC1.tmp
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\tap-windows\bin\tapinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1396"C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exe
WinRAR.exe
User:
admin
Company:
hss721.blogspot.com
Integrity Level:
HIGH
Description:
Hotspot Shield 8.7.1 Pre-Active
Exit code:
0
Version:
8.7.1.11380
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2800.35014\hotspotshield-8.7.1-plain-773-preactive.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1464C:\Windows\system32\MsiExec.exe -Embedding B61C172271515E81D46E9686D98CD71B CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1544"C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active\prerequisites\tap-windows-9.21.2.exe" C:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active\prerequisites\tap-windows-9.21.2.exe
HotspotShield-8.7.1-plain-773-PreActive.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\hss721.blogspot.com\hotspot shield 8.7.1 pre-active\prerequisites\tap-windows-9.21.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1912C:\Windows\system32\MsiExec.exe -Embedding 3886994E12B1BB864732A7F485AAA76AC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2352"C:\Program Files\Hotspot Shield\bin\hsscp.exe" "-closeupgrade" "-quit"C:\Program Files\Hotspot Shield\bin\hsscp.execmw_srv.exe
User:
admin
Company:
AnchorFree Inc.
Integrity Level:
MEDIUM
Description:
Hotspot Shield
Exit code:
0
Version:
8.7.1.11380
Total events
4 106
Read events
3 624
Write events
432
Delete events
50

Modification events

(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HotspotShield-8.7.1-plain-773-PreActive.rar
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
25
Suspicious files
21
Text files
256
Unknown types
5

Dropped files

PID
Process
Filename
Type
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\holder0.aiph
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID739.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID7D6.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID7F6.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\MSID826.tmp
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.msiexecutable
MD5:
SHA256:
2800WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2800.35014\HotspotShield-8.7.1-plain-773-PreActive.exeexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.x64.msiexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Roaming\hss721.blogspot.com\Hotspot Shield 8.7.1 Pre-Active 8.7.1.11380\install\lockHotspot Shield 8.7.1_NEW.aiuiexecutable
MD5:
SHA256:
1396HotspotShield-8.7.1-plain-773-PreActive.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1396\hss.ico_1image
MD5:30C9D8F6B4EEFDF5731332B4AE8A625A
SHA256:ABD217F6AA88057D06CF90B488244D34D8E865FDA286EC6E5A2575F6D16CD3D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3996
cmw_srv.exe
13.35.253.121:443
d3sdizpx54za7n.cloudfront.net
US
shared
3996
cmw_srv.exe
13.35.253.22:443
d3sdizpx54za7n.cloudfront.net
US
unknown
3996
cmw_srv.exe
13.35.253.8:443
d3sdizpx54za7n.cloudfront.net
US
shared
3996
cmw_srv.exe
107.178.254.148:443
control.kochava.com
Google Inc.
US
whitelisted
13.32.23.40:443
d1o29kof4patkc.cloudfront.net
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
hsselite.com
  • 184.169.221.190
  • 52.9.81.184
whitelisted
www.hsselite.com
  • 52.9.81.184
  • 184.169.221.190
unknown
d3sdizpx54za7n.cloudfront.net
  • 13.35.253.22
  • 13.35.253.8
  • 13.35.253.178
  • 13.35.253.121
shared
control.kochava.com
  • 107.178.254.148
unknown
d1o29kof4patkc.cloudfront.net
  • 13.32.23.40
  • 13.32.23.120
  • 13.32.23.91
  • 13.32.23.55
shared

Threats

No threats detected
No debug info