| File name: | Firefox 64 Bit - CHIP-Installer.exe |
| Full analysis: | https://app.any.run/tasks/b1a5bb31-a91c-4115-b9ec-d6cb56a5ef6b |
| Verdict: | Malicious activity |
| Analysis date: | October 26, 2018, 09:59:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 8EC1D795C369362AEF3F22B94EFD231D |
| SHA1: | C73F0D862494A372F5D3285E2312D1DADA69E673 |
| SHA256: | 9CD4964880A6A2E5FD04CF620810CCC7EEB23976A144BBD6CF4A750E02FAF19C |
| SSDEEP: | 24576:Iq5TfcdHj4fmbDPr2qkjzKJ9TtrRRBHRWQMwTTyFzQJ9TtFKeWHRmBMwklu7:IUTsamjxX5xMwF5jMwX |
| .exe | | | Win64 Executable (generic) (30.7) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (30.1) |
| .exe | | | Win32 EXE Yoda's Crypter (29.5) |
| .exe | | | Win32 Executable (generic) (5) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:10:10 16:48:44+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 344064 |
| InitializedDataSize: | 1196032 |
| UninitializedDataSize: | 1724416 |
| EntryPoint: | 0x1f9920 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.9.9.0 |
| ProductVersionNumber: | 2.9.9.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | German |
| CharacterSet: | Unicode |
| FileVersion: | 2.9.9.0 |
| Comments: | CHIP Secured Installer |
| FileDescription: | CHIP Secured Installer |
| ProductVersion: | 2.9.9.0 |
| LegalCopyright: | Copyright © 2018 Chip Digital GmbH |
| CompanyName: | CHIP Digital GmbH |
| InternalName: | CHIP Secured Installer |
| ProductName: | CHIP Secured Installer |
| OriginalFileName: | CHIP Secured Installer |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 10-Oct-2018 14:48:44 |
| Detected languages: |
|
| FileVersion: | 2.9.9.0 |
| Comments: | CHIP Secured Installer |
| FileDescription: | CHIP Secured Installer |
| ProductVersion: | 2.9.9.0 |
| LegalCopyright: | Copyright © 2018 Chip Digital GmbH |
| CompanyName: | CHIP Digital GmbH |
| InternalName: | CHIP Secured Installer |
| ProductName: | CHIP Secured Installer |
| OriginalFilename: | CHIP Secured Installer |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 10-Oct-2018 14:48:44 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x001A5000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x001A6000 | 0x00054000 | 0x00053C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93604 |
.rsrc | 0x001FA000 | 0x00124000 | 0x00123A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.76801 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.32366 | 1444 | Latin 1 / Western European | German - Germany | RT_MANIFEST |
4 | 3.75291 | 9640 | Latin 1 / Western European | English - United Kingdom | RT_ICON |
7 | 3.34702 | 1428 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
8 | 3.2817 | 1674 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
9 | 3.28849 | 1168 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
10 | 3.28373 | 1532 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
11 | 3.26322 | 1628 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
12 | 3.25812 | 1126 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
99 | 2.0815 | 20 | Latin 1 / Western European | English - United Kingdom | RT_GROUP_ICON |
166 | 2.68292 | 80 | Latin 1 / Western European | English - United Kingdom | RT_MENU |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
GDI32.dll |
IPHLPAPI.DLL |
KERNEL32.DLL |
MPR.dll |
OLEAUT32.dll |
PSAPI.DLL |
SHELL32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1412 | "C:\Users\admin\AppData\Local\Temp\DMR\dmr_72.exe" -install -85086972 -chipderedesign -55bec9a47a5944f6a263b1b9f811c4f7 - -BLUB2 -islufmgiotejhbie -3228 | C:\Users\admin\AppData\Local\Temp\DMR\dmr_72.exe | Firefox 64 Bit - CHIP-Installer.exe | ||||||||||||
User: admin Company: Chip Digital GmbH Integrity Level: HIGH Description: CHIP Secured Installer Exit code: 0 Version: 2.9.9.0 Modules
| |||||||||||||||
| 1812 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2828 | "C:\Program Files\Chip Digital GmbH\chip1click\chip 1-click installer.exe" | C:\Program Files\Chip Digital GmbH\chip1click\chip 1-click installer.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Chip Digital GmbH Integrity Level: SYSTEM Description: chip 1-click installer Exit code: 0 Version: 3.6.9.0 Modules
| |||||||||||||||
| 3044 | MSIEXEC.EXE /i "C:\Users\admin\AppData\Local\Downloaded Installations\{31AD8258-894C-48D5-8149-C47506092754}\Chip Installer.msi" /qn SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\3533bda4c65ccfbbc76d3b22854fd16c" SETUPEXENAME="1-klick-chip-setup.exe" | C:\Windows\system32\MSIEXEC.EXE | — | 1-klick-chip-setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3128 | "C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\8885e35c02f635486ebb103c8d7efba9\Firefox_Setup_63.0.exe" | C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\8885e35c02f635486ebb103c8d7efba9\Firefox_Setup_63.0.exe | — | dmr_72.exe | |||||||||||
User: admin Company: Mozilla Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 18.05 | |||||||||||||||
| 3204 | "C:\Users\admin\AppData\Local\Temp\Firefox 64 Bit - CHIP-Installer.exe" | C:\Users\admin\AppData\Local\Temp\Firefox 64 Bit - CHIP-Installer.exe | — | explorer.exe | |||||||||||
User: admin Company: CHIP Digital GmbH Integrity Level: MEDIUM Description: CHIP Secured Installer Exit code: 3221226540 Version: 2.9.9.0 Modules
| |||||||||||||||
| 3216 | "C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\3533bda4c65ccfbbc76d3b22854fd16c\1-klick-chip-setup.exe" /s /v""/qn"" | C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\3533bda4c65ccfbbc76d3b22854fd16c\1-klick-chip-setup.exe | dmr_72.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3228 | "C:\Users\admin\AppData\Local\Temp\Firefox 64 Bit - CHIP-Installer.exe" | C:\Users\admin\AppData\Local\Temp\Firefox 64 Bit - CHIP-Installer.exe | explorer.exe | ||||||||||||
User: admin Company: CHIP Digital GmbH Integrity Level: HIGH Description: CHIP Secured Installer Exit code: 0 Version: 2.9.9.0 Modules
| |||||||||||||||
| 3608 | C:\Windows\system32\MsiExec.exe -Embedding A0D79F12A73403F4A7F517565FC1CE43 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3228) Firefox 64 Bit - CHIP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3228) Firefox 64 Bit - CHIP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | CID |
Value: afd74f3f-cb88-4e0e-aaed-8d4e1cfb1991 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | PID |
Value: chipderedesign | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | lastPID |
Value: chipderedesign | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1412) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@myvisualiq[1].txt | — | |
MD5:— | SHA256:— | |||
| 3228 | Firefox 64 Bit - CHIP-Installer.exe | C:\Users\admin\AppData\Local\Temp\DMR\islufmgiotejhbie.dat | text | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\progress[1].htm | htm | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\main[1].js | text | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MarselisSlabWeb[1].eot | eot | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\main[1].css | text | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\error[1] | text | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\no-impression[1].gif | — | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\jquery[1].js | text | |
MD5:— | SHA256:— | |||
| 1412 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\kasper-progresspg-ongrey-en[1].gif | image | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1412 | dmr_72.exe | GET | — | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/main.css?v=1461939270 | DE | — | — | malicious |
1412 | dmr_72.exe | GET | — | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/jquery.js | DE | — | — | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/jquery.js | DE | text | 32.2 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/geoip/geoip.php?ip=3231372e362e3231382e313738&givezip=true | DE | text | 14 b | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/progress.php?pid=chipderedesign&cid=85086972&sid=55bec9a47a5944f6a263b1b9f811c4f7&appname=46697265666F78202836342042697429&uid=afd74f3f-cb88-4e0e-aaed-8d4e1cfb1991&scid=&source=BLUB2&language=en-be&piddata=&uaexe=66697265666F782E657865&Camplist=31313131636230656231386533626238623736356362663664623237656132333B36616134613430366632346533303062393463393663623365303933343631643B37373964343266306630313562653938396664366635656230653437653437333B63686970616D617A6F6E69636F6E6F7074696E30303039387566393875663B6438663531333838363832333635626139356261643432646332393330383866 | DE | htm | 2.25 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/main.css?v=1461939270 | DE | text | 1.65 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/MarselisSlabWeb.eot?&1440165143 | DE | eot | 61.7 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/main.js?v=12 | DE | text | 2.74 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/img/bg-icon-speedometer.png | DE | image | 5.35 Kb | malicious |
1412 | dmr_72.exe | GET | 200 | 5.9.198.83:80 | http://api.chip-secured-download.de/downloaderContent/img/kasper-progresspg-ongrey-en.gif | DE | image | 2.30 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1412 | dmr_72.exe | 5.9.198.83:80 | api.chip-secured-download.de | Hetzner Online GmbH | DE | malicious |
1412 | dmr_72.exe | 5.9.198.84:80 | static.chip-secured-download.de | Hetzner Online GmbH | DE | suspicious |
1412 | dmr_72.exe | 5.9.175.19:443 | ocs1.chdi-server.de | Hetzner Online GmbH | DE | malicious |
1412 | dmr_72.exe | 18.194.100.124:443 | t.myvisualiq.net | Amazon.com, Inc. | DE | unknown |
1412 | dmr_72.exe | 104.96.153.236:443 | downloaderapi.chip.de | Akamai Technologies, Inc. | NL | whitelisted |
1412 | dmr_72.exe | 148.251.198.118:80 | ads-not-by-this-site.de | Hetzner Online GmbH | DE | unknown |
1412 | dmr_72.exe | 216.58.205.38:443 | ad.doubleclick.net | Google Inc. | US | unknown |
1412 | dmr_72.exe | 212.124.124.178:80 | www.1-1ads.com | True Records Inc. | US | suspicious |
1412 | dmr_72.exe | 104.96.153.236:80 | downloaderapi.chip.de | Akamai Technologies, Inc. | NL | whitelisted |
1412 | dmr_72.exe | 176.9.97.244:80 | api.chip-secured-download.de | Hetzner Online GmbH | DE | malicious |
Domain | IP | Reputation |
|---|---|---|
api.chip-secured-download.de |
| unknown |
ocs1.chdi-server.de |
| unknown |
static.chip-secured-download.de |
| suspicious |
t.myvisualiq.net |
| whitelisted |
downloaderapi.chip.de |
| whitelisted |
ads-not-by-this-site.de |
| suspicious |
ad.doubleclick.net |
| whitelisted |
www.1-1ads.com |
| whitelisted |
r.chip.de |
| whitelisted |
service.chip-secured-download.de |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1412 | dmr_72.exe | A Network Trojan was detected | MALWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1412 | dmr_72.exe | A Network Trojan was detected | MALWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1412 | dmr_72.exe | A Network Trojan was detected | MALWARE [PTsecurity] DownloadSponsor img_welcome PNG artifact |
1412 | dmr_72.exe | A Network Trojan was detected | MALWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1412 | dmr_72.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1412 | dmr_72.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
1412 | dmr_72.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
1412 | dmr_72.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1412 | dmr_72.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |