| File name: | line-9.2.0.3402-installer_9Cor-k1.exe |
| Full analysis: | https://app.any.run/tasks/894e666f-771c-4d6d-90fa-e2ed88f7dbd2 |
| Verdict: | Malicious activity |
| Threats: | Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth. |
| Analysis date: | August 22, 2024, 07:02:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0EDAEE326C15B375FD3A1B0E6AB058D4 |
| SHA1: | A1C88A3C233058EC086251B27D82A8264EFD6908 |
| SHA256: | 977A81C4DA0471117319191CB8B3EDB7A6F2A9ADC23A460B6C60692E44F724F1 |
| SSDEEP: | 49152:/7HecD4dnbibBlw2zWoFgvKCINKfiqs68YQAiAcVSW0nKWPOUvb9ikm8eEEVlwqM:T+cD4dn1DoKyCINK/9QAYR0lj9djeEke |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 89600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 423.56.98.8907 |
| ProductVersionNumber: | 423.56.98.8907 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | Softonic International SA |
| FileVersion: | 423.56.98.8907 |
| LegalCopyright: | ©2023 Softonic International SA |
| OriginalFileName: | |
| ProductName: | Softonic International SA |
| ProductVersion: | 3.1.5.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | "C:\Users\admin\AppData\Local\LINE\bin\LineLauncher.exe" --updated 9.2.0.3402 | C:\Users\admin\AppData\Local\LINE\bin\LineLauncher.exe | — | LineUpdater.exe | |||||||||||
User: admin Company: LY Corporation Integrity Level: HIGH Description: LINE Exit code: 0 Version: 1.0.0.23 Modules
| |||||||||||||||
| 300 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | fltMC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 568 | "C:\Program Files\ReasonLabs\Common\Client\v1.4.2\rsAppUI.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\ReasonLabs\EPP" --standard-schemes=mc --secure-schemes=mc --bypasscsp-schemes --cors-schemes --fetch-schemes --service-worker-schemes --streaming-schemes --app-user-model-id=com.reasonlabs.epp --app-path="C:\Program Files\ReasonLabs\Common\Client\v1.4.2\resources\app.asar" --enable-sandbox --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2320 --field-trial-handle=1728,i,5575232025597184243,359035936259713644,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | C:\Program Files\ReasonLabs\Common\Client\v1.4.2\rsAppUI.exe | — | rsAppUI.exe | |||||||||||
User: admin Company: Reason Cybersecurity Ltd. Integrity Level: LOW Description: ReasonLabs Application Version: 1.4.2 Modules
| |||||||||||||||
| 740 | "C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -bn:ReasonLabs -dt:10 | C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Reason Software Company Inc. Integrity Level: SYSTEM Description: Reason Security Synchronize Service Version: 1.8.5.0 Modules
| |||||||||||||||
| 1168 | C:\Users\admin\AppData\Local/LINE//bin/LineUpdater.exe --deploy 9.2.0.3402 en-US real 0 | C:\Users\admin\AppData\Local\LINE\bin\LineUpdater.exe | LINE.exe | ||||||||||||
User: admin Company: LY Corporation Integrity Level: HIGH Description: LineUpdater Exit code: 1 Version: 1.0.1.88 Modules
| |||||||||||||||
| 1172 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | rsLitmus.A.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\AppData\Local\LINE\bin\9.2.0.3402\LineAppMgr.exe" -afterinstall | C:\Users\admin\AppData\Local\LINE\bin\9.2.0.3402\LineAppMgr.exe | — | line-9.2.0.3402-installer.exe | |||||||||||
User: admin Company: LY Corporation Integrity Level: HIGH Description: LINE Exit code: 0 Version: 8.4.0.3014 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\ReasonLabs\EDR\rsEDRSvc.exe" -i | C:\Program Files\ReasonLabs\EDR\rsEDRSvc.exe | — | UnifiedStub-installer.exe | |||||||||||
User: admin Company: Reason Cybersecurity Ltd. Integrity Level: HIGH Description: Reason EDR Service Exit code: 0 Version: 2.2.0 Modules
| |||||||||||||||
| 1920 | "C:\Program Files\ReasonLabs\EDR\rsEDRSvc.exe" | C:\Program Files\ReasonLabs\EDR\rsEDRSvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: Reason Cybersecurity Ltd. Integrity Level: SYSTEM Description: Reason EDR Service Version: 2.2.0 Modules
| |||||||||||||||
| 2660 | "C:\Users\admin\Downloads\line-9.2.0.3402-installer.exe" | C:\Users\admin\Downloads\line-9.2.0.3402-installer.exe | line-9.2.0.3402-installer_9Cor-k1.tmp | ||||||||||||
User: admin Company: LY Corporation Integrity Level: HIGH Description: LINE Exit code: 0 Version: 9.2.0.3402 Modules
| |||||||||||||||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 541A000029CC305661F4DA01 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: C85390025553B7600BD3517EF9F399542169FFFCF57FC703B4A1D3EE7C035B31 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6740) line-9.2.0.3402-installer_9Cor-k1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6148) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6148) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6148) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\AppData\Local\Temp\is-8R5NP.tmp\is-FJUG0.tmp | — | |
MD5:— | SHA256:— | |||
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\AppData\Local\Temp\is-8R5NP.tmp\line-9.2.0.3402-installer.exe | — | |
MD5:— | SHA256:— | |||
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\Downloads\line-9.2.0.3402-installer.exe | — | |
MD5:— | SHA256:— | |||
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\AppData\Local\Temp\is-8R5NP.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6712 | line-9.2.0.3402-installer_9Cor-k1.exe | C:\Users\admin\AppData\Local\Temp\is-Q4GJ3.tmp\line-9.2.0.3402-installer_9Cor-k1.tmp | executable | |
MD5:62ED5886215FEDD237C3BDE6018DA87A | SHA256:6ED54B13A42F8B404B30DF8FFFEED451F5E9CBC157AD7396AAB42FAB1F9484F8 | |||
| 6148 | component0.exe | C:\Users\admin\AppData\Local\Temp\jxn0s4w3.exe | executable | |
MD5:0FE9BE1E8AEE8D93AECCFBCCED910B4B | SHA256:450D357F6BEBBA4D5025A5BC91E6DED8CF982D7C7A2C30E22AA932F20E541488 | |||
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\AppData\Local\Temp\is-8R5NP.tmp\N.png | image | |
MD5:1A01027365500D86730A737EB32CBF2A | SHA256:D79A97538B93179012A5EBEBDE873EDC18E30A0287953800F7AA7EA4F25724E1 | |||
| 6424 | jxn0s4w3.exe | C:\Users\admin\AppData\Local\Temp\7zS819DE3F2\cs-CZ\UnifiedStub.resources.dll | executable | |
MD5:F230C03FC14C59760D29F3364A43581F | SHA256:7DFB9CD2FA7AB935F6DCFABEB2F65CD1E3CB30BF0A4E0B8F6CC878F05147FDBC | |||
| 6424 | jxn0s4w3.exe | C:\Users\admin\AppData\Local\Temp\7zS819DE3F2\da-DK\UnifiedStub.resources.dll | executable | |
MD5:C7D53FBA41BBD98B09ADC6370530187D | SHA256:0973897156246245DAFC537D4023FD899E29F65F9AFCCC0049F41BC08138F5F5 | |||
| 6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | C:\Users\admin\AppData\Local\Temp\is-8R5NP.tmp\is-LOBD3.tmp | image | |
MD5:4167C79312B27C8002CBEEA023FE8CB5 | SHA256:C3BF350627B842BED55E6A72AB53DA15719B4F33C267A6A132CB99FF6AFE3CD8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
888 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1920 | rsEDRSvc.exe | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | — | — | whitelisted |
6132 | rsEngineSvc.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
6132 | rsEngineSvc.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6132 | rsEngineSvc.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAk0TOtH29pBvQ1YLJIYF4o%3D | unknown | — | — | whitelisted |
6132 | rsEngineSvc.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAc2N7ckVHzYR6z9KGYqXls%3D | unknown | — | — | whitelisted |
1920 | rsEDRSvc.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBTDHsfuqfubd3pihvq4mgQVWgHWNwQUyH7SaoUqG8oZmAQHJ89QEE9oqKICEzMAAAAHh6M0o3uljhwAAAAAAAc%3D | unknown | — | — | whitelisted |
6132 | rsEngineSvc.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAVEr%2FOUnQg5pr%2FbP1%2FlYRY%3D | unknown | — | — | whitelisted |
1920 | rsEDRSvc.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBTOQYLFSE5GO%2FpaRVfYu7d9gZEbQAQU2UEpsA8PY2zvadf1zSmepEhqMOYCEzMAAAAEllBL0tvuy4gAAAAAAAQ%3D | unknown | — | — | whitelisted |
304 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2088 | svchost.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4876 | RUXIMICS.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2120 | MoUsoCoreWorker.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2088 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | 54.239.192.117:443 | d25qho5rs4tpl0.cloudfront.net | AMAZON-02 | US | unknown |
6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | 151.101.193.91:443 | images.sftcdn.net | FASTLY | US | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6740 | line-9.2.0.3402-installer_9Cor-k1.tmp | 199.232.194.133:443 | gsf-fl.softonic.com | FASTLY | US | unknown |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
d25qho5rs4tpl0.cloudfront.net |
| whitelisted |
images.sftcdn.net |
| whitelisted |
gsf-fl.softonic.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
rsEngineSvc.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\ReasonLabs\EPP\x64\SQLite.Interop.dll"...
|
rsEDRSvc.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\ReasonLabs\EDR\x64\SQLite.Interop.dll"...
|
LINE.exe | [MODULE_VALIDATOR] module open failed : "C:/Users/admin/AppData/Local/LINE/bin/9.2.0.3402/WtsApi32.dll"
|
LINE.exe | [MODULE_VALIDATOR] moduleName : "WtsApi32.dll" 0
|
LINE.exe | [MODULE_VALIDATOR] module open failed : "C:/Users/admin/AppData/Local/LINE/bin/WtsApi32.dll"
|
LINE.exe | [MODULE_VALIDATOR] moduleName : "WtsApi32.dll" 0
|
LINE.exe | [MODULE_VALIDATOR] module open failed : "C:/Users/admin/AppData/Local/LINE/bin/9.2.0.3402/rpcrt4.dll"
|
LINE.exe | [MODULE_VALIDATOR] moduleName : "rpcrt4.dll" 0
|
LINE.exe | [MODULE_VALIDATOR] module open failed : "C:/Users/admin/AppData/Local/LINE/bin/rpcrt4.dll"
|
LINE.exe | [MODULE_VALIDATOR] moduleName : "rpcrt4.dll" 0
|