File name:

AuraServiceSetup.exe

Full analysis: https://app.any.run/tasks/b9b8c4b6-c4a1-4e1f-ae56-172b735204b1
Verdict: Malicious activity
Analysis date: April 19, 2019, 01:41:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9B804B1A6A77D8ED3B11B48007A46630

SHA1:

F26CC553B895741B8529A76AC5D9270C82C11D93

SHA256:

87F0EE56212B4021289CE9EDA1A1423A5B6DA55AA7F4B444251850CC58B46CAD

SSDEEP:

196608:ugUPEEGU6U3BA8U8HpfFJ2EiQpbcR8sbH:lTEGUVBnxJ/1ldsr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • AuraServiceSetup.exe (PID: 1912)
      • regsvr32.exe (PID: 3524)
      • AsusUpdate.exe (PID: 2056)
      • AsusUpdate.exe (PID: 2696)
      • AsusUpdate.exe (PID: 2300)
      • AsusUpdate.exe (PID: 2164)
      • LightingService.exe (PID: 3928)
    • Application was dropped or rewritten from another process

      • AuraServiceSetup.exe (PID: 1912)
      • AuraServiceSetup.exe (PID: 3892)
      • AacInstaller.exe (PID: 1364)
      • AuraServiceControl.exe (PID: 388)
      • AsusUpdate.exe (PID: 2164)
      • LightingService.exe (PID: 1484)
      • LightingService.exe (PID: 3928)
      • AsusUpdate.exe (PID: 2696)
      • AsusUpdate.exe (PID: 2300)
      • AsusUpdate.exe (PID: 2056)
      • UnInstallHal.exe (PID: 2100)
    • Changes the autorun value in the registry

      • AuraServiceSetup.exe (PID: 3892)
    • Loads the Task Scheduler COM API

      • AsusUpdate.exe (PID: 2696)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 2616)
  • SUSPICIOUS

    • Starts itself from another location

      • AuraServiceSetup.exe (PID: 1912)
      • AsusUpdate.exe (PID: 2696)
    • Executable content was dropped or overwritten

      • AuraServiceSetup.exe (PID: 836)
      • AuraServiceSetup.exe (PID: 1912)
      • AuraServiceSetup.exe (PID: 3892)
      • msiexec.exe (PID: 3544)
      • MSI981C.tmp (PID: 3572)
      • AsusUpdate.exe (PID: 2696)
    • Searches for installed software

      • AuraServiceSetup.exe (PID: 3892)
    • Creates files in the program directory

      • AuraServiceSetup.exe (PID: 3892)
      • AsusUpdate.exe (PID: 2696)
      • MSI981C.tmp (PID: 3572)
      • LightingService.exe (PID: 3928)
    • Creates a software uninstall entry

      • AuraServiceSetup.exe (PID: 3892)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 3524)
      • AsusUpdate.exe (PID: 2696)
      • AsusUpdate.exe (PID: 2056)
    • Disables SEHOP

      • AsusUpdate.exe (PID: 2696)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 3544)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 4068)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2688)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2688)
    • Application launched itself

      • msiexec.exe (PID: 3544)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 3544)
    • Creates files in the program directory

      • msiexec.exe (PID: 3544)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3544)
    • Application was dropped or rewritten from another process

      • MSI981C.tmp (PID: 3572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:05:01 16:33:52+02:00
PEType: PE32
LinkerVersion: 14.1
CodeSize: 302080
InitializedDataSize: 160256
UninitializedDataSize: -
EntryPoint: 0x2e1fd
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.2.10.0
ProductVersionNumber: 3.2.10.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: ASUSTeK Computer Inc.
FileDescription: AURA Service
FileVersion: 3.02.10
InternalName: setup
LegalCopyright: Copyright (c) ASUSTeK Computer Inc.. All rights reserved.
OriginalFileName: AuraServiceSetup.exe
ProductName: AURA Service
ProductVersion: 3.02.10

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-May-2017 14:33:52
Detected languages:
  • English - United States
Debug artifacts:
  • C:\build\work\eca3d12b\wix3\build\ship\x86\burn.pdb
CompanyName: ASUSTeK Computer Inc.
FileDescription: AURA Service
FileVersion: 3.02.10
InternalName: setup
LegalCopyright: Copyright (c) ASUSTeK Computer Inc.. All rights reserved.
OriginalFilename: AuraServiceSetup.exe
ProductName: AURA Service
ProductVersion: 3.02.10

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 01-May-2017 14:33:52
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_NET_RUN_FROM_SWAP
  • IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00049A67
0x00049C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.56282
.rdata
0x0004B000
0x0001EC60
0x0001EE00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.10841
.data
0x0006A000
0x00001730
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.15458
.wixburn8
0x0006C000
0x00000038
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
0.735162
.tls
0x0006D000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0006E000
0x00003614
0x00003800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.38001
.reloc
0x00072000
0x00003DEC
0x00003E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.79026

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.30829
1234
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.00091
296
Latin 1 / Western European
English - United States
RT_ICON

Imports

ADVAPI32.dll
Cabinet.dll (delay-loaded)
GDI32.dll
KERNEL32.dll
OLEAUT32.dll
RPCRT4.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
19
Malicious processes
7
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start auraservicesetup.exe auraservicesetup.exe auraservicesetup.exe vssvc.exe no specs drvinst.exe no specs aacinstaller.exe auraservicecontrol.exe no specs msiexec.exe cmd.exe no specs regsvr32.exe msiexec.exe no specs msi981c.tmp asusupdate.exe asusupdate.exe no specs asusupdate.exe no specs asusupdate.exe lightingservice.exe no specs lightingservice.exe uninstallhal.exe

Process information

PID
CMD
Path
Indicators
Parent process
388"C:\ProgramData\Package Cache\688A6FC316CF5FFF6A55DABBDBEAACAA9FF5C975\AuraServiceControl.exe" C:\ProgramData\Package Cache\688A6FC316CF5FFF6A55DABBDBEAACAA9FF5C975\AuraServiceControl.exeAuraServiceSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\programdata\package cache\688a6fc316cf5fff6a55dabbdbeaacaa9ff5c975\auraservicecontrol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
836"C:\Users\admin\AppData\Local\Temp\AuraServiceSetup.exe" C:\Users\admin\AppData\Local\Temp\AuraServiceSetup.exe
explorer.exe
User:
admin
Company:
ASUSTeK Computer Inc.
Integrity Level:
MEDIUM
Description:
AURA Service
Exit code:
0
Version:
3.02.10
Modules
Images
c:\users\admin\appdata\local\temp\auraservicesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1364"C:\ProgramData\Package Cache\309E3940917CAFA9899EE07433DB238703120D25\AacInstaller.exe" /C:\Users\admin\AppData\Local\Temp\aacC:\ProgramData\Package Cache\309E3940917CAFA9899EE07433DB238703120D25\AacInstaller.exe
AuraServiceSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\programdata\package cache\309e3940917cafa9899ee07433db238703120d25\aacinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1484"C:\Program Files\LightingService\LightingService.exe" /serviceC:\Program Files\LightingService\LightingService.exemsiexec.exe
User:
admin
Company:
ASUSTek Computer Inc.
Integrity Level:
HIGH
Description:
LightingService
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\program files\lightingservice\lightingservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1912"C:\Users\admin\AppData\Local\Temp\{02A9588B-48E0-4F28-999C-E8B82BDBBAC5}\.cr\AuraServiceSetup.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\AuraServiceSetup.exe" -burn.filehandle.attached=148 -burn.filehandle.self=156 C:\Users\admin\AppData\Local\Temp\{02A9588B-48E0-4F28-999C-E8B82BDBBAC5}\.cr\AuraServiceSetup.exe
AuraServiceSetup.exe
User:
admin
Company:
ASUSTeK Computer Inc.
Integrity Level:
MEDIUM
Description:
AURA Service
Exit code:
0
Version:
3.02.10
Modules
Images
c:\users\admin\appdata\local\temp\{02a9588b-48e0-4f28-999c-e8b82bdbbac5}\.cr\auraservicesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2008C:\Windows\system32\MsiExec.exe -Embedding E1C90F4E1C20805ED915F5A4D0AD5CC2 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2056"C:\Program Files\ASUS\Update\AsusUpdate.exe" /regserverC:\Program Files\ASUS\Update\AsusUpdate.exeAsusUpdate.exe
User:
SYSTEM
Company:
ASUSTeK Computer Inc.
Integrity Level:
SYSTEM
Description:
ASUS Update
Exit code:
0
Version:
1.3.101.0
Modules
Images
c:\program files\asus\update\asusupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2100"C:\ProgramData\Package Cache\CC2258A035BB7027158BF72E21FD12C2DBCC0CDE\UnInstallHal.exe"C:\ProgramData\Package Cache\CC2258A035BB7027158BF72E21FD12C2DBCC0CDE\UnInstallHal.exe
AuraServiceSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\programdata\package cache\cc2258a035bb7027158bf72e21fd12c2dbcc0cde\uninstallhal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2164"C:\Program Files\ASUS\Update\AsusUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMTAxLjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMDEuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsyMTdEN0ZBQS04REFBLTRFMjEtOEEyQS1GQzU4NzAxQ0RFRkR9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHRlc3Rzb3VyY2U9ImF1dG8iIHJlcXVlc3RpZD0iezI2Q0M4RDMwLTczQTAtNDIwOS1CNjAwLUY5QjMxODg5NjUxOX0iIGRlZHVwPSJjciI-PGh3IHBoeXNtZW1vcnk9IjMiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjAiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezA3OUIyQTZDLURDODItNDJFMy05NEI2LTlCMzZFNjgzRDQ2NH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMDEuMCIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIyMTI1Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Program Files\ASUS\Update\AsusUpdate.exe
AsusUpdate.exe
User:
SYSTEM
Company:
ASUSTeK Computer Inc.
Integrity Level:
SYSTEM
Description:
ASUS Update
Exit code:
2147954575
Version:
1.3.101.0
Modules
Images
c:\program files\asus\update\asusupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2300"C:\Program Files\ASUS\Update\AsusUpdate.exe" /regsvcC:\Program Files\ASUS\Update\AsusUpdate.exeAsusUpdate.exe
User:
SYSTEM
Company:
ASUSTeK Computer Inc.
Integrity Level:
SYSTEM
Description:
ASUS Update
Exit code:
0
Version:
1.3.101.0
Modules
Images
c:\program files\asus\update\asusupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
2 019
Read events
817
Write events
1 137
Delete events
65

Modification events

(PID) Process:(1912) AuraServiceSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1912) AuraServiceSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3892) AuraServiceSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
400000000000000024A7A71451F6D401340F00003C0F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3892) AuraServiceSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000007E09AA1451F6D401340F00003C0F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3892) AuraServiceSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
20
(PID) Process:(3892) AuraServiceSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008040021551F6D401340F00003C0F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3892) AuraServiceSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DAA2041551F6D401340F0000340D0000E80300000100000000000000000000000934CE0AF557CF47B0E8A1D11CE1F7720000000000000000
(PID) Process:(4068) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000009C8E101551F6D401E40F00007C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4068) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000009C8E101551F6D401E40F0000100B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4068) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000009C8E101551F6D401E40F00004C020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
177
Suspicious files
7
Text files
111
Unknown types
4

Dropped files

PID
Process
Filename
Type
3892AuraServiceSetup.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1912AuraServiceSetup.exeC:\Users\admin\AppData\Local\Temp\{B2F9F3F4-7084-4043-A2C4-C878CBCE1D1E}\.ba\BootstrapperApplicationData.xmlxml
MD5:
SHA256:
836AuraServiceSetup.exeC:\Users\admin\AppData\Local\Temp\{02A9588B-48E0-4F28-999C-E8B82BDBBAC5}\.cr\AuraServiceSetup.exeexecutable
MD5:
SHA256:
3892AuraServiceSetup.exeC:\System Volume Information\SPP\OnlineMetadataCache\{0ace3409-57f5-47cf-b0e8-a1d11ce1f772}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2688DrvInst.exeC:\Windows\INF\setupapi.ev3binary
MD5:
SHA256:
2688DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:
SHA256:
3892AuraServiceSetup.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
2688DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:
SHA256:
1912AuraServiceSetup.exeC:\Users\admin\AppData\Local\Temp\{B2F9F3F4-7084-4043-A2C4-C878CBCE1D1E}\.ba\thm.wxlxml
MD5:FC0DB4142556D3F38B0744A12F5F9D3D
SHA256:8FBEB7F0B546D394D99B49D678D516402E8F54E5DEA590CC91733F502F288019
1912AuraServiceSetup.exeC:\Users\admin\AppData\Local\Temp\{B2F9F3F4-7084-4043-A2C4-C878CBCE1D1E}\.ba\logo.pngimage
MD5:80DF19F22C1D266C06ACE7C8B9831762
SHA256:E8E37845754F62B6426CE39CBDA1DB032856BD551E6D39BBACA06AA7C44625C4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2164
AsusUpdate.exe
POST
103.10.4.244:80
http://mb-update.asus.com/service/update2
TW
unknown
2164
AsusUpdate.exe
POST
103.10.4.244:80
http://mb-update.asus.com/service/update2
TW
unknown
2164
AsusUpdate.exe
POST
103.10.4.244:80
http://mb-update.asus.com/service/update2
TW
unknown
2164
AsusUpdate.exe
POST
103.10.4.244:80
http://mb-update.asus.com/service/update2
TW
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2164
AsusUpdate.exe
103.10.4.244:443
mb-update.asus.com
ASUSTek COMPUTER INC.
TW
unknown
2164
AsusUpdate.exe
103.10.4.244:80
mb-update.asus.com
ASUSTek COMPUTER INC.
TW
unknown
103.10.4.244:80
mb-update.asus.com
ASUSTek COMPUTER INC.
TW
unknown

DNS requests

Domain
IP
Reputation
mb-update.asus.com
  • 103.10.4.244
unknown

Threats

No threats detected
Process
Message
AacInstaller.exe
"C:\ProgramData\Package Cache\309E39Ĕ
AacInstaller.exe
"C:\ProgramData\Package Cache\309E3940917CAFA9899EE07433DB238703120D25\AacInstaller.exe" /C:\Users\admin\AppData\Local\Temp\aac
AacInstaller.exe
C:\Users\admin\AppData\Local\Temp\aac
AacInstaller.exe
[ASUS] [AacInstaller] [main] end.
LightingService.exe
In thread_entry0
LightingService.exe
In thread_entry1
LightingService.exe
AsusRogSuraService RestoreAll in thread_entry
LightingService.exe
Into Instance.
LightingService.exe
In RogAuraDeviceManager()
LightingService.exe
[Aura] [LightingService] [RogAuraDeviceManager] [RogAuraDeviceManager] m_S0_enabled(-1)