| download: | click |
| Full analysis: | https://app.any.run/tasks/26ead472-5203-4a51-bab4-2a91b09d181e |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2021, 17:58:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E9D5F515458D905D99241F91A367A446 |
| SHA1: | BB46A573D8577AC3661E5FED1045F6DEA5D12FC2 |
| SHA256: | 8ACBA6A43E3E58ED56CEED407F4AE8AC22F13EAC419E73FD60415AB5CB9E266C |
| SSDEEP: | 393216:B8SHqzVhrv2K9gDw1q96j0PcPy3p2tWUhz24SejlDdq0IuqyZ4Bv+IZhuiEM3g9C:B8BVJf1Wc0PRoS4Rzq0hqZFZIEI/AUU |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:09:17 07:33:38+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 299008 |
| InitializedDataSize: | 197120 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2df71 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.22.5.12023 |
| ProductVersionNumber: | 10.22.5.12023 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Pango Inc. |
| FileDescription: | Hotspot Shield 10.22.5 |
| FileVersion: | 10.22.5.12023 |
| InternalName: | setup |
| LegalCopyright: | © Pango Inc. All rights reserved. |
| OriginalFileName: | HSS-10.22.5-install-plain-773-plain.exe |
| ProductName: | Hotspot Shield 10.22.5 |
| ProductVersion: | 10.22.5.12023 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 17-Sep-2019 05:33:38 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Pango Inc. |
| FileDescription: | Hotspot Shield 10.22.5 |
| FileVersion: | 10.22.5.12023 |
| InternalName: | setup |
| LegalCopyright: | © Pango Inc. All rights reserved. |
| OriginalFilename: | HSS-10.22.5-install-plain-773-plain.exe |
| ProductName: | Hotspot Shield 10.22.5 |
| ProductVersion: | 10.22.5.12023 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 17-Sep-2019 05:33:38 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00048FF7 | 0x00049000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57206 |
.rdata | 0x0004A000 | 0x0001F760 | 0x0001F800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.13752 |
.data | 0x0006A000 | 0x000016FC | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.15516 |
.wixburn8 | 0x0006C000 | 0x00000038 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.744582 |
.rsrc | 0x0006D000 | 0x0000BEC0 | 0x0000C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.24894 |
.reloc | 0x00079000 | 0x00003DD0 | 0x00003E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.78827 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.30829 | 1234 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.19553 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.42272 | 296 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 3.8706 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 3.72244 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 2.49242 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 7.93074 | 10436 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 3.72819 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 3.98 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
10 | 4.22043 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
ADVAPI32.dll |
Cabinet.dll (delay-loaded) |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Windows\system32\lodctr.exe" C:\Windows\Microsoft.NET\Framework\v4.0.30319\_DataOracleClientPerfCounters_shared12_neutral.ini | C:\Windows\system32\lodctr.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Load PerfMon Counters Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 464 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe executeQueuedItems 1 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Common Language Runtime native compiler Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 608 | mofcomp C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet.mof | C:\Windows\system32\wbem\mofcomp.exe | — | aspnet_regiis.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: The Managed Object Format (MOF) Compiler Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 656 | "C:\ProgramData\Package Cache\3727DC47F12D9EA5EBA87145228DFF0CE8076E25\redist\ndp48-web.exe" /q /norestart /ChainingPackage "Hotspot Shield 10.22.5" /log "C:\Users\admin\AppData\Local\Temp\Hotspot_Shield_10.22.5_20211118175828_000_NetFx48Web.log.html" /pipe NetFxSection.{2123B2C1-4AFC-4E2C-B5B5-DCEDD46BEA03} | C:\ProgramData\Package Cache\3727DC47F12D9EA5EBA87145228DFF0CE8076E25\redist\ndp48-web.exe | HSS-10.22.5-install-plain-773-plain.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.8 Setup Exit code: 0 Version: 4.8.04115.00 Modules
| |||||||||||||||
| 664 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1dc -InterruptEvent 0 -NGENProcess 1c8 -Pipe 1d0 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 680 | C:\Windows\system32\MsiExec.exe -Embedding 43FC8ED09F914285E14FCA853417D9F3 E Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 764 | C:\Windows\system32\MsiExec.exe -Embedding A7B65122DBDF000E035FF4BB125349C6 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 900 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1e4 -InterruptEvent 0 -NGENProcess 1dc -Pipe 1c4 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1004 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1c8 -InterruptEvent 0 -NGENProcess 1bc -Pipe 1cc -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1032 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe" -iru | C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: aspnet_regiis.exe Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2148) click.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\click_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\Hss.Setup.Bootstrapper.dll | executable | |
MD5:— | SHA256:— | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\Foundation.Installer.Common.dll | executable | |
MD5:— | SHA256:— | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\Foundation.Bcl.dll | executable | |
MD5:— | SHA256:— | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\BootstrapperCore.dll | executable | |
MD5:B0D10A2A622A322788780E7A3CBB85F3 | SHA256:F2C2B3CE2DF70A3206F3111391FFC7B791B32505FA97AEF22C0C2DBF6F3B0426 | |||
| 2576 | click.exe | C:\Users\admin\AppData\Local\Temp\{F13AA9AC-B03A-44F9-A5E3-FA2060634F58}\.cr\click.exe | executable | |
MD5:— | SHA256:— | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\mbahost.dll | executable | |
MD5:C59832217903CE88793A6C40888E3CAE | SHA256:9DFA1BC5D2AB4C652304976978749141B8C312784B05CB577F338A0AA91330DB | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\1030\mbapreq.wxl | xml | |
MD5:7C6E4CE87870B3B5E71D3EF4555500F8 | SHA256:CAC263E0E90A4087446A290055257B1C39F17E11F065598CB2286DF4332C7696 | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\1032\mbapreq.wxl | xml | |
MD5:074D5921AF07E6126049CB45814246ED | SHA256:B8E90E20EDF110AAAAEA54FBC8533872831777BE5589E380CFDD17E1F93147B5 | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\1043\mbapreq.wxl | xml | |
MD5:67F28BCDB3BA6774CD66AA198B06FF38 | SHA256:226B778604236931B4AE45F6F272586C884A11517444A34BF45CD5CAE49BE62E | |||
| 2148 | click.exe | C:\Users\admin\AppData\Local\Temp\{407DAEEE-90E4-4C89-B17C-F30256F226B3}\.ba\1042\mbapreq.wxl | xml | |
MD5:442F8463EF5CA42B99B2EFACA696BD01 | SHA256:D22F6ADA97DBFFC1E7548E52163807F982B30B11A2A5109E71F42985102CCCBD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
932 | svchost.exe | GET | 302 | 104.92.93.19:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=amd64&o1=netfx_Full_x86.msi | NL | — | — | whitelisted |
932 | svchost.exe | HEAD | 302 | 104.92.93.19:80 | http://go.microsoft.com/fwlink/?LinkId=328846&clcid=0x409 | NL | — | — | whitelisted |
932 | svchost.exe | HEAD | 302 | 104.92.93.19:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=x86&o1=netfx_Full.mzz | NL | — | — | whitelisted |
932 | svchost.exe | HEAD | 302 | 104.92.93.19:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=amd64&o1=netfx_Full_x86.msi | NL | — | — | whitelisted |
2148 | click.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAOH4Owd%2FwkjMGTfsn1TcqI%3D | US | der | 727 b | whitelisted |
2148 | click.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAqhJdbWMht%2BQeQF2jaXwhU%3D | US | der | 471 b | whitelisted |
3988 | HSS-10.22.5-install-plain-773-plain.exe | GET | 200 | 92.123.194.162:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | der | 1.11 Kb | whitelisted |
2148 | click.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
3988 | HSS-10.22.5-install-plain-773-plain.exe | GET | 200 | 2.21.143.74:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown | der | 1.05 Kb | whitelisted |
932 | svchost.exe | GET | 302 | 104.92.93.19:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=x86&o1=netfx_Full.mzz | NL | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2148 | click.exe | 143.204.101.96:443 | d21j7etzkdo9k9.cloudfront.net | — | US | unknown |
2148 | click.exe | 159.89.100.215:443 | www.legaladviser.us | — | US | unknown |
2148 | click.exe | 138.68.77.102:443 | www.legaladviser.us | Digital Ocean, Inc. | DE | unknown |
2148 | click.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2148 | click.exe | 143.204.101.65:443 | d3h88i27t2k9za.cloudfront.net | — | US | suspicious |
2148 | click.exe | 104.92.93.19:443 | go.microsoft.com | Akamai Technologies, Inc. | NL | unknown |
2148 | click.exe | 68.232.34.200:443 | download.visualstudio.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3988 | HSS-10.22.5-install-plain-773-plain.exe | 92.123.194.162:80 | crl.microsoft.com | Akamai International B.V. | — | whitelisted |
3988 | HSS-10.22.5-install-plain-773-plain.exe | 2.21.143.74:80 | www.microsoft.com | Telia Company AB | — | malicious |
932 | svchost.exe | 104.92.93.19:80 | go.microsoft.com | Akamai Technologies, Inc. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
d21j7etzkdo9k9.cloudfront.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
www.legaladviser.us |
| unknown |
ocsp.digicert.com |
| whitelisted |
d3h88i27t2k9za.cloudfront.net |
| suspicious |
go.microsoft.com |
| whitelisted |
download.visualstudio.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |