| File name: | trade124setup.exe |
| Full analysis: | https://app.any.run/tasks/a99a92da-4719-4034-a0b0-e22c43c8f7f2 |
| Verdict: | Malicious activity |
| Analysis date: | March 14, 2019, 08:54:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | AA7C7B3C580F5D97FF29BFF13D87CEC5 |
| SHA1: | E0B6A73A550ADFD8267BAE7F85B0EFD465FE693B |
| SHA256: | 893068F0CC6E2C1B2AA51AEB50D5F3BEC80BC9BEFF1A48D87C75AD1F3F78AD52 |
| SSDEEP: | 24576:3IdzsDtRe+IjHIjPYOtAuGskOOxhbI9/nQnC+iLIIv7Lgu/g9s8b:32zwtk+gHI8OtPGskOSbI9/QnC+iLZvO |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1970:01:14 10:16:48+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 999424 |
| InitializedDataSize: | 159744 |
| UninitializedDataSize: | 2224128 |
| EntryPoint: | 0x312e10 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.0.1985 |
| ProductVersionNumber: | 5.0.0.1985 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | https://www.metaquotes.net |
| CompanyName: | MetaQuotes Software Corp. |
| FileDescription: | Setup |
| FileVersion: | 5.0.0.1985 |
| InternalName: | Setup |
| LegalCopyright: | © 2000-2019, MetaQuotes Software Corp. |
| LegalTrademarks: | MetaTrader |
| OriginalFileName: | Setup |
| ProductName: | Setup |
| ProductVersion: | 5.0.0.1985 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 864 | "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" /install | C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe | — | trade124setup.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 Modules
| |||||||||||||||
| 1348 | "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" | C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe | explorer.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 Modules
| |||||||||||||||
| 1620 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:2 /compile:"1785453_23496" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 Modules
| |||||||||||||||
| 2340 | "C:\Users\admin\Desktop\trade124setup.exe" | C:\Users\admin\Desktop\trade124setup.exe | trade124setup.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: Setup Exit code: 1 Version: 5.0.0.1985 Modules
| |||||||||||||||
| 2448 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:21 /compile:"1791937_5556" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 Modules
| |||||||||||||||
| 2452 | "C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe" | C:\Program Files\Turbo Trading MT4 Terminal\terminal.exe | explorer.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader Exit code: 0 Version: 4.0.0.1170 Modules
| |||||||||||||||
| 2692 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | explorer.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 0 Version: 5.0.0.1966 Modules
| |||||||||||||||
| 2748 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:4 /compile:"1804609_22774" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 Modules
| |||||||||||||||
| 2764 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3148 | "C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe" /packed:1 /compile:"1811578_3472" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\E000F5C313010FBCD08655E1FF3C3CFF\MQL4" /flg:2 | C:\Program Files\Turbo Trading MT4 Terminal\metaeditor.exe | — | terminal.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 1 Version: 5.0.0.1966 Modules
| |||||||||||||||
| (PID) Process: | (3152) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: C50B83EB-41C8-T-190314 | |||
| (PID) Process: | (3152) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | Install.Time |
Value: 1552553684 | |||
| (PID) Process: | (3152) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: 6BCD5AA1-D277-P-190226 | |||
| (PID) Process: | (3152) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3152) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2340) trade124setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: 6BCD5AA1-D277-P-190226 | |||
| (PID) Process: | (2340) trade124setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2340) trade124setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D4620000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
| (PID) Process: | (2340) trade124setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF67080B00000001000000140000005500530045005200540072007500730074000000140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8090000000100000016000000301406082B0601050507030306082B060105050703080F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
| (PID) Process: | (2340) trade124setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A0304030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB0B00000001000000320000005500530045005200540072007500730074002000280043006F006400650020005300690067006E0069006E006700290000006200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A23.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A25.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A24.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A26.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A28.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A27.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A29.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A2A.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Cab9A69.tmp | — | |
MD5:— | SHA256:— | |||
| 2340 | trade124setup.exe | C:\Users\admin\AppData\Local\Temp\Tar9A6A.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
2340 | trade124setup.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2340 | trade124setup.exe | 52.184.28.1:443 | — | Microsoft Corporation | HK | unknown |
2340 | trade124setup.exe | 88.212.244.84:443 | api4.mql5.com | Servers.com, Inc. | RU | unknown |
2340 | trade124setup.exe | 206.221.189.58:443 | — | Choopa, LLC | US | unknown |
2340 | trade124setup.exe | 47.52.161.165:443 | — | Alibaba (China) Technology Co., Ltd. | HK | unknown |
2340 | trade124setup.exe | 47.245.38.25:443 | — | — | US | unknown |
2340 | trade124setup.exe | 138.201.201.91:443 | c.mql5.com | Hetzner Online GmbH | DE | unknown |
2340 | trade124setup.exe | 47.95.9.170:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2340 | trade124setup.exe | 78.140.180.43:443 | api1.mql5.com | Webzilla B.V. | NL | suspicious |
2340 | trade124setup.exe | 197.189.238.138:443 | — | HETZNER | ZA | unknown |
2340 | trade124setup.exe | 104.41.54.220:443 | — | Microsoft Corporation | BR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
content.mql5.com |
| suspicious |
www.download.windowsupdate.com |
| whitelisted |
api1.mql5.com |
| suspicious |
www.mql5.com |
| suspicious |
www.bing.com |
| whitelisted |
c.mql5.com |
| suspicious |
connect.facebook.net |
| whitelisted |
api4.mql5.com |
| unknown |
demo-invest.mt.leveratetech.com |
| unknown |
real-invest.mt.leveratetech.com |
| unknown |