File name: | Windscribe_2.0_beta.exe |
Full analysis: | https://app.any.run/tasks/3eb81f64-54b8-4dc1-966c-75e137a45929 |
Verdict: | Malicious activity |
Analysis date: | February 21, 2020, 18:06:39 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 7218CDF313B7FD0B84F83E7A2ABD67C8 |
SHA1: | 4548F29430E44FA03E7DEE4619D8DCD56E0A7B96 |
SHA256: | A800DEE98F1F3753175D5DD4FE197CE8C180A29E8051E4590F9DB953C4E360DF |
SSDEEP: | 196608:NEzAr9+pBAVVj3nI4dyL/v7EgS8CxB/Yn6goNr0pSwuMN/2k9+23JeMK:N6yo8VfkP3hCxmn6gK0ruMx9hPK |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2020:02:21 00:53:26+01:00 |
PEType: | PE32 |
LinkerVersion: | 14.16 |
CodeSize: | 381952 |
InitializedDataSize: | 13909504 |
UninitializedDataSize: | - |
EntryPoint: | 0x23b4b |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 2.0.0.14 |
ProductVersionNumber: | 2.0.0.14 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Dynamic link library |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Windscribe Limited |
FileDescription: | Windscribe Installer |
FileVersion: | 2.0.0.14 |
LegalCopyright: | Copyright (C) 2019 Windscribe Limited |
OriginalFileName: | Windscribe.exe |
ProductName: | Windscribe |
ProductVersion: | 2.0.0.14 |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 20-Feb-2020 23:53:26 |
Detected languages: |
|
Debug artifacts: |
|
CompanyName: | Windscribe Limited |
FileDescription: | Windscribe Installer |
FileVersion: | 2.0.0.14 |
LegalCopyright: | Copyright (C) 2019 Windscribe Limited |
OriginalFilename: | Windscribe.exe |
ProductName: | Windscribe |
ProductVersion: | 2.0.0.14 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000110 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 20-Feb-2020 23:53:26 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0005D22D | 0x0005D400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70906 |
.rdata | 0x0005F000 | 0x0001A084 | 0x0001A200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.59618 |
.data | 0x0007A000 | 0x000059C0 | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.4877 |
.rsrc | 0x00080000 | 0x00D1F428 | 0x00D1F600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.98994 |
.reloc | 0x00DA0000 | 0x00004A14 | 0x00004C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.61054 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.02293 | 559 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.64946 | 67624 | UNKNOWN | English - United States | RT_ICON |
3 | 3.87618 | 16936 | UNKNOWN | English - United States | RT_ICON |
4 | 4.12656 | 9640 | UNKNOWN | English - United States | RT_ICON |
5 | 4.52198 | 4264 | UNKNOWN | English - United States | RT_ICON |
6 | 4.98123 | 1128 | UNKNOWN | English - United States | RT_ICON |
34465 | 2.79908 | 90 | UNKNOWN | English - United States | RT_GROUP_ICON |
34466 | 5.8429 | 107988 | UNKNOWN | English - United States | BINARY |
34467 | 5.86023 | 107732 | UNKNOWN | English - United States | BINARY |
BADGE_ICON | 4.9052 | 1904 | UNKNOWN | English - United States | RT_RCDATA |
ADVAPI32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
SETUPAPI.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
UxTheme.dll |
dwmapi.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2540 | "C:\Users\admin\Desktop\Windscribe_2.0_beta.exe" | C:\Users\admin\Desktop\Windscribe_2.0_beta.exe | — | explorer.exe |
User: admin Company: Windscribe Limited Integrity Level: MEDIUM Description: Windscribe Installer Exit code: 3221226540 Version: 2.0.0.14 | ||||
3732 | "C:\Users\admin\Desktop\Windscribe_2.0_beta.exe" | C:\Users\admin\Desktop\Windscribe_2.0_beta.exe | explorer.exe | |
User: admin Company: Windscribe Limited Integrity Level: HIGH Description: Windscribe Installer Exit code: 0 Version: 2.0.0.14 | ||||
3540 | "sc" create WindscribeService binPath= "C:\Program Files\Windscribe\WindscribeService.exe" start= auto | C:\Windows\system32\sc.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1332 | "sc" description WindscribeService "Manages the firewall and controls the VPN tunnel" | C:\Windows\system32\sc.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2372 | "C:\Program Files\Windscribe\subinacl" /SERVICE WindscribeService /grant=S-1-5-11=STO | C:\Program Files\Windscribe\subinacl.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SubInAcl Exit code: 0 Version: 5.2.3790.1180 | ||||
820 | "C:\Program Files\Windscribe\tap\tapinstall.exe" install OemVista.inf tapwindscribe0901 | C:\Program Files\Windscribe\tap\tapinstall.exe | Windscribe_2.0_beta.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) | ||||
1196 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0cbb98ce-e0cf-5bf6-d9a2-70620999491a}\oemvista.inf" "0" "60e41e9d3" "00000554" "WinSta0\Default" "00000558" "208" "c:\program files\windscribe\tap" | C:\Windows\system32\DrvInst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2932 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{13e74170-9bd3-2c46-674e-885dcad6ec36} Global\{59ff47f3-f133-5544-993b-224c5b871e27} C:\Windows\System32\DriverStore\Temp\{5489d90c-8f71-4c2f-732b-ab3ec08f316c}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{5489d90c-8f71-4c2f-732b-ab3ec08f316c}\tapwindscribe0901.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1836 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3400 | DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem4.inf" "oemvista.inf:tapwindscribe0901.NTx86:tapwindscribe0901.ndi:9.24.2.601:tapwindscribe0901" "60e41e9d3" "00000554" "000005D8" "000005D4" | C:\Windows\system32\DrvInst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\wintun\wintun.cat | cat | |
MD5:12FAFC9E9A774157ED17451900E91271 | SHA256:82201C358D0C8F096409E76247CEC36B37EA52844C2A96A873FE552105E52DDE | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\wintun\wintun.inf | binary | |
MD5:751C58EF5E9FC2F95657C69EEF9CAD66 | SHA256:0D027B050922E0D8A098020074FFEEFF8B487A2C93608D756487FA9200097BF0 | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\splittunnel\windscribesplittunnel.cat | cat | |
MD5:C35C54EFC45CEEE76769A7B1C57E8C8D | SHA256:D82D125F5C87DEEC263B1939463CB78BBEB7F6EE65E8A5B7E9C52B6F5EA5875A | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\splittunnel\WindscribeSplitTunnel.inf | ini | |
MD5:7AB8650946B8174A9088429E4D6D4808 | SHA256:8A930E956D582FD6096994771F54D2846ED6B0ACE8C0CB1B33B280BD1E223B75 | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\tap\tapwindscribe0901.cat | cat | |
MD5:4061C3E87FBD50D8E26A456D661BA3C0 | SHA256:571F31845D1259A672F4EC9DF57DC76D38D79CA0457DE4B3B75F6B7C7AED3B5C | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:72F8626388893A536D0EE370ACC9E456 | SHA256:5C9D7085295DAE9A9B2D3A9C66D99D0061D0BA14F218B95E95E8B01BB7204C87 | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-file-l2-1-0.dll | executable | |
MD5:ADFC5BEBC4A2C52023F47A1E548B0CC9 | SHA256:7DE5743F68D9BD6CFF0FB8021C22D4069E2E993D97735DB0EF65756FF915F39C | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\tap\OemVista.inf | binary | |
MD5:B830F755018F844DE3BA42EAE5150F6E | SHA256:145AF2483D5322AFF169A91D6EBBB4E504CDE5DFB846C960D051A98596B237EF | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:A960E117840ACB5FF1D2DCFBBE574E21 | SHA256:5695695176A80A3E7F9EAC80BB3D92DF1A5592BE42B939B14087A3A6AE6EFADF | |||
3732 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-libraryloader-l1-1-0.dll | executable | |
MD5:146E9998951E897A4F7F5A97BAEFA823 | SHA256:AC011F904F8AA7C9A2577D959F7E430CDA544CA13A1B3818C69D8514D079399A |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3624 | chrome.exe | GET | 200 | 195.95.178.206:80 | http://r3---sn-pouxga5o-vu2l.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mip=45.41.138.204&mm=28&mn=sn-pouxga5o-vu2l&ms=nvh&mt=1582308493&mv=m&mvi=2&pl=24&shardbypass=yes | RO | crx | 293 Kb | whitelisted |
3776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
3776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D | US | der | 471 b | whitelisted |
3776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEF6v9x%2BT7vVdbD6kKgKpu%2Fc%3D | US | der | 471 b | whitelisted |
3776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEF6v9x%2BT7vVdbD6kKgKpu%2Fc%3D | US | der | 471 b | whitelisted |
3624 | chrome.exe | GET | 301 | 144.76.226.41:80 | http://www.filedropper.com/ | DE | html | 236 b | suspicious |
3624 | chrome.exe | GET | 302 | 172.217.21.238:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx | US | html | 524 b | whitelisted |
3624 | chrome.exe | GET | 302 | 172.217.21.238:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx | US | html | 519 b | whitelisted |
3776 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
3624 | chrome.exe | GET | 200 | 195.95.178.175:80 | http://r4---sn-pouxga5o-vu2s.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=45.41.138.204&mm=28&mn=sn-pouxga5o-vu2s&ms=nvh&mt=1582308493&mv=m&mvi=3&pl=24&shardbypass=yes | RO | crx | 862 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 185.189.112.67:443 | — | M247 Ltd | DE | unknown |
1720 | WindscribeEngine.exe | 198.96.95.195:443 | — | QuadraNet, Inc | US | unknown |
1720 | WindscribeEngine.exe | 185.236.200.19:443 | — | — | — | unknown |
1720 | WindscribeEngine.exe | 212.103.49.67:443 | — | — | — | unknown |
1720 | WindscribeEngine.exe | 161.129.70.67:443 | — | — | — | unknown |
1720 | WindscribeEngine.exe | 185.232.20.195:443 | — | — | — | unknown |
1720 | WindscribeEngine.exe | 161.129.70.131:443 | — | — | — | unknown |
1720 | WindscribeEngine.exe | 104.20.123.38:443 | api.windscribe.com | Cloudflare Inc | US | shared |
1720 | WindscribeEngine.exe | 38.132.116.195:443 | — | M247 Ltd | US | unknown |
1720 | WindscribeEngine.exe | 104.129.18.195:443 | — | QuadraNet, Inc | US | suspicious |
Domain | IP | Reputation |
---|---|---|
api.windscribe.com |
| unknown |
www.windscribe.com |
| unknown |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
windscribe.com |
| unknown |
static.windscribe.com |
| unknown |
accounts.google.com |
| shared |
clientservices.googleapis.com |
| whitelisted |
www.google.com.ua |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
Process | Message |
---|---|
Windscribe.exe | [{gmt_time} 0.054] [basic] App start time: "Fri Feb 21 18:08:16 2020"
|
Windscribe.exe | [{gmt_time} 0.054] [basic] OS Version: "Windows 7 Service Pack 1 (major: 6, minor: 1) (build: 7601)"
|
Windscribe.exe | [{gmt_time} 0.218] [basic] Gui user settings: ""
|
Windscribe.exe | [{gmt_time} 0.218] [basic] Gui settings: ""
|
Windscribe.exe | [{gmt_time} 0.579] [basic] Updated scaled hashes for LDPIs: ""
|
Windscribe.exe | [{gmt_time} 1.365] [basic] Gui internal settings: ""
|
Windscribe.exe | [{gmt_time} 1.377] [gui] Disabled Split Tunneling
|
Windscribe.exe | [{gmt_time} 1.383] [basic] Backend::init()
|
Windscribe.exe | [{gmt_time} 1.549] [basic] Backend::onProcessStarted()
|
Windscribe.exe | [{gmt_time} 1.549] [basic] MainWindowController::changeWindow: 1
|