File name: | trade124setup.exe |
Full analysis: | https://app.any.run/tasks/a99a92da-4719-4034-a0b0-e22c43c8f7f2 |
Verdict: | Malicious activity |
Analysis date: | March 14, 2019, 08:54:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | AA7C7B3C580F5D97FF29BFF13D87CEC5 |
SHA1: | E0B6A73A550ADFD8267BAE7F85B0EFD465FE693B |
SHA256: | 893068F0CC6E2C1B2AA51AEB50D5F3BEC80BC9BEFF1A48D87C75AD1F3F78AD52 |
SSDEEP: | 24576:3IdzsDtRe+IjHIjPYOtAuGskOOxhbI9/nQnC+iLIIv7Lgu/g9s8b:32zwtk+gHI8OtPGskOSbI9/QnC+iLZvO |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
ProductVersion: | 5.0.0.1985 |
---|---|
ProductName: | Setup |
OriginalFileName: | Setup |
LegalTrademarks: | MetaTrader |
LegalCopyright: | © 2000-2019, MetaQuotes Software Corp. |
InternalName: | Setup |
FileVersion: | 5.0.0.1985 |
FileDescription: | Setup |
CompanyName: | MetaQuotes Software Corp. |
Comments: | https://www.metaquotes.net |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.0.0.1985 |
FileVersionNumber: | 5.0.0.1985 |
Subsystem: | Windows GUI |
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x312e10 |
UninitializedDataSize: | 2224128 |
InitializedDataSize: | 159744 |
CodeSize: | 999424 |
LinkerVersion: | 14.16 |
PEType: | PE32 |
TimeStamp: | 1970:01:14 10:16:48+01:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3152 | "C:\Users\admin\Desktop\trade124setup.exe" | C:\Users\admin\Desktop\trade124setup.exe | — | explorer.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 5.0.0.1985 | ||||
2340 | "C:\Users\admin\Desktop\trade124setup.exe" | C:\Users\admin\Desktop\trade124setup.exe | trade124setup.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: Setup Exit code: 1 Version: 5.0.0.1985 | ||||
864 | "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" /install | C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe | — | trade124setup.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 | ||||
3980 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | trade124setup.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3952 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3980 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3360 | "C:\Windows\explorer.exe" "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" | C:\Windows\explorer.exe | — | trade124setup.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2764 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2452 | "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" | C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe | explorer.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 | ||||
1620 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:2 /compile:"1785453_23496" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 | ||||
2448 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:21 /compile:"1791937_5556" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A23.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A25.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A24.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A26.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A28.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A27.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A29.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A2A.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A69.tmp | — | |
MD5:— | SHA256:— | |||
2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A6A.tmp | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2340 | trade124setup.exe | 88.212.244.84:443 | api4.mql5.com | Servers.com, Inc. | RU | unknown |
2340 | trade124setup.exe | 78.140.180.43:443 | api1.mql5.com | Webzilla B.V. | NL | suspicious |
2340 | trade124setup.exe | 206.221.189.58:443 | — | Choopa, LLC | US | unknown |
2340 | trade124setup.exe | 47.95.9.170:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2340 | trade124setup.exe | 142.0.194.252:443 | — | Servers.com, Inc. | US | unknown |
2340 | trade124setup.exe | 139.99.68.28:443 | — | OVH SAS | SG | unknown |
2340 | trade124setup.exe | 47.245.38.25:443 | — | — | US | unknown |
2340 | trade124setup.exe | 104.41.54.220:443 | — | Microsoft Corporation | BR | whitelisted |
2340 | trade124setup.exe | 197.189.238.138:443 | — | HETZNER | ZA | unknown |
2340 | trade124setup.exe | 47.52.161.165:443 | — | Alibaba (China) Technology Co., Ltd. | HK | unknown |
Domain | IP | Reputation |
---|---|---|
content.mql5.com |
| suspicious |
www.download.windowsupdate.com |
| whitelisted |
api1.mql5.com |
| suspicious |
www.mql5.com |
| suspicious |
www.bing.com |
| whitelisted |
c.mql5.com |
| suspicious |
connect.facebook.net |
| whitelisted |
api4.mql5.com |
| unknown |
demo-invest.mt.leveratetech.com |
| unknown |
real-invest.mt.leveratetech.com |
| unknown |