File name: | Windscribe_2.0_beta.exe |
Full analysis: | https://app.any.run/tasks/c1c7cae9-e0e0-46b0-9e9a-e35cf5a3f529 |
Verdict: | Malicious activity |
Analysis date: | February 21, 2020, 17:43:18 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 7218CDF313B7FD0B84F83E7A2ABD67C8 |
SHA1: | 4548F29430E44FA03E7DEE4619D8DCD56E0A7B96 |
SHA256: | A800DEE98F1F3753175D5DD4FE197CE8C180A29E8051E4590F9DB953C4E360DF |
SSDEEP: | 196608:NEzAr9+pBAVVj3nI4dyL/v7EgS8CxB/Yn6goNr0pSwuMN/2k9+23JeMK:N6yo8VfkP3hCxmn6gK0ruMx9hPK |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
ProductVersion: | 2.0.0.14 |
---|---|
ProductName: | Windscribe |
OriginalFileName: | Windscribe.exe |
LegalCopyright: | Copyright (C) 2019 Windscribe Limited |
FileVersion: | 2.0.0.14 |
FileDescription: | Windscribe Installer |
CompanyName: | Windscribe Limited |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 2.0.0.14 |
FileVersionNumber: | 2.0.0.14 |
Subsystem: | Windows GUI |
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x23b4b |
UninitializedDataSize: | - |
InitializedDataSize: | 13909504 |
CodeSize: | 381952 |
LinkerVersion: | 14.16 |
PEType: | PE32 |
TimeStamp: | 2020:02:21 00:53:26+01:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 20-Feb-2020 23:53:26 |
Detected languages: |
|
Debug artifacts: |
|
CompanyName: | Windscribe Limited |
FileDescription: | Windscribe Installer |
FileVersion: | 2.0.0.14 |
LegalCopyright: | Copyright (C) 2019 Windscribe Limited |
OriginalFilename: | Windscribe.exe |
ProductName: | Windscribe |
ProductVersion: | 2.0.0.14 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000110 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 20-Feb-2020 23:53:26 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0005D22D | 0x0005D400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70906 |
.rdata | 0x0005F000 | 0x0001A084 | 0x0001A200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.59618 |
.data | 0x0007A000 | 0x000059C0 | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.4877 |
.rsrc | 0x00080000 | 0x00D1F428 | 0x00D1F600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.98994 |
.reloc | 0x00DA0000 | 0x00004A14 | 0x00004C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.61054 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.02293 | 559 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.64946 | 67624 | UNKNOWN | English - United States | RT_ICON |
3 | 3.87618 | 16936 | UNKNOWN | English - United States | RT_ICON |
4 | 4.12656 | 9640 | UNKNOWN | English - United States | RT_ICON |
5 | 4.52198 | 4264 | UNKNOWN | English - United States | RT_ICON |
6 | 4.98123 | 1128 | UNKNOWN | English - United States | RT_ICON |
34465 | 2.79908 | 90 | UNKNOWN | English - United States | RT_GROUP_ICON |
34466 | 5.8429 | 107988 | UNKNOWN | English - United States | BINARY |
34467 | 5.86023 | 107732 | UNKNOWN | English - United States | BINARY |
BADGE_ICON | 4.9052 | 1904 | UNKNOWN | English - United States | RT_RCDATA |
ADVAPI32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
SETUPAPI.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
UxTheme.dll |
dwmapi.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3776 | "C:\Users\admin\Desktop\Windscribe_2.0_beta.exe" | C:\Users\admin\Desktop\Windscribe_2.0_beta.exe | — | explorer.exe |
User: admin Company: Windscribe Limited Integrity Level: MEDIUM Description: Windscribe Installer Exit code: 3221226540 Version: 2.0.0.14 | ||||
3840 | "C:\Users\admin\Desktop\Windscribe_2.0_beta.exe" | C:\Users\admin\Desktop\Windscribe_2.0_beta.exe | explorer.exe | |
User: admin Company: Windscribe Limited Integrity Level: HIGH Description: Windscribe Installer Exit code: 0 Version: 2.0.0.14 | ||||
332 | "sc" create WindscribeService binPath= "C:\Program Files\Windscribe\WindscribeService.exe" start= auto | C:\Windows\system32\sc.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1488 | "sc" description WindscribeService "Manages the firewall and controls the VPN tunnel" | C:\Windows\system32\sc.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3620 | "C:\Program Files\Windscribe\subinacl" /SERVICE WindscribeService /grant=S-1-5-11=STO | C:\Program Files\Windscribe\subinacl.exe | — | Windscribe_2.0_beta.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SubInAcl Exit code: 0 Version: 5.2.3790.1180 | ||||
2716 | "C:\Program Files\Windscribe\tap\tapinstall.exe" install OemVista.inf tapwindscribe0901 | C:\Program Files\Windscribe\tap\tapinstall.exe | Windscribe_2.0_beta.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) | ||||
2864 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{630476d8-716a-2956-341b-b9367cdfcd48}\oemvista.inf" "0" "60e41e9d3" "00000554" "WinSta0\Default" "000005BC" "208" "c:\program files\windscribe\tap" | C:\Windows\system32\DrvInst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3428 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{0e618e8a-05cc-4975-a212-bf70d30f2151} Global\{61887dac-f0e2-57ef-6a29-1f7f348e0f47} C:\Windows\System32\DriverStore\Temp\{497505cc-c3c5-2b2c-e444-fd0eac7d8861}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{497505cc-c3c5-2b2c-e444-fd0eac7d8861}\tapwindscribe0901.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3584 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1928 | C:\Windows\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC} | C:\Windows\system32\DllHost.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\wintun\wintun.cat | cat | |
MD5:12FAFC9E9A774157ED17451900E91271 | SHA256:82201C358D0C8F096409E76247CEC36B37EA52844C2A96A873FE552105E52DDE | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\splittunnel\windscribesplittunnel.cat | cat | |
MD5:C35C54EFC45CEEE76769A7B1C57E8C8D | SHA256:D82D125F5C87DEEC263B1939463CB78BBEB7F6EE65E8A5B7E9C52B6F5EA5875A | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\wintun\wintun.inf | binary | |
MD5:751C58EF5E9FC2F95657C69EEF9CAD66 | SHA256:0D027B050922E0D8A098020074FFEEFF8B487A2C93608D756487FA9200097BF0 | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\splittunnel\WindscribeSplitTunnel.inf | ini | |
MD5:7AB8650946B8174A9088429E4D6D4808 | SHA256:8A930E956D582FD6096994771F54D2846ED6B0ACE8C0CB1B33B280BD1E223B75 | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\tap\OemVista.inf | binary | |
MD5:B830F755018F844DE3BA42EAE5150F6E | SHA256:145AF2483D5322AFF169A91D6EBBB4E504CDE5DFB846C960D051A98596B237EF | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-interlocked-l1-1-0.dll | executable | |
MD5:109032959967F8CB078D72E397238509 | SHA256:C05208903446E2BD528F726AF1287BE05243DD6CD1E42359440F9303FB7790BE | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:A960E117840ACB5FF1D2DCFBBE574E21 | SHA256:5695695176A80A3E7F9EAC80BB3D92DF1A5592BE42B939B14087A3A6AE6EFADF | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-handle-l1-1-0.dll | executable | |
MD5:1F6A4F144E52A23767CC74FE2F796FF0 | SHA256:634924290057AE9C0E4599D2C70656916BE24BD594AB1904C0BE7A8EA91DDC7C | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:A47A7084D4ED2FB6B9181075F91729A0 | SHA256:9490C5938112242CADC2C676F82B60FDCC7E5F56CAA7AA2D2BA3A6ED358683D4 | |||
3840 | Windscribe_2.0_beta.exe | C:\Program Files\Windscribe\api-ms-win-core-file-l1-2-0.dll | executable | |
MD5:045E4617B49E817007D8A88652AF7734 | SHA256:FD387D4E358E3755DB38A618066FB72CD03B17B54D058DBE3DAB82065519EDC7 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | — | 87.245.200.144:80 | http://r5---sn-gxuog0-n8vl.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=85.206.166.82&mm=28&mn=sn-gxuog0-n8vl&ms=nvh&mt=1582307232&mv=m&mvi=4&pcm2cms=yes&pl=23&shardbypass=yes | RU | — | — | whitelisted |
2336 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D | US | der | 471 b | whitelisted |
2336 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
2336 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
3912 | chrome.exe | GET | 301 | 144.76.226.41:80 | http://www.filedropper.com/ | DE | html | 236 b | suspicious |
2336 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D | US | der | 471 b | whitelisted |
2336 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEF6v9x%2BT7vVdbD6kKgKpu%2Fc%3D | US | der | 471 b | whitelisted |
3912 | chrome.exe | GET | 302 | 172.217.21.238:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx | US | html | 536 b | whitelisted |
3912 | chrome.exe | GET | 302 | 172.217.21.238:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx | US | html | 515 b | whitelisted |
3912 | chrome.exe | GET | 200 | 87.245.200.147:80 | http://r8---sn-gxuog0-n8vl.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mip=85.206.166.82&mm=28&mn=sn-gxuog0-n8vl&ms=nvh&mt=1582307232&mv=m&mvi=7&pl=23&shardbypass=yes | RU | crx | 293 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2336 | iexplore.exe | 151.139.128.14:80 | ocsp.usertrust.com | Highwinds Network Group, Inc. | US | suspicious |
2336 | iexplore.exe | 104.20.74.194:443 | www.windscribe.com | Cloudflare Inc | US | shared |
2108 | iexplore.exe | 104.20.74.194:443 | www.windscribe.com | Cloudflare Inc | US | shared |
2336 | iexplore.exe | 104.20.75.194:443 | www.windscribe.com | Cloudflare Inc | US | shared |
3676 | WindscribeEngine.exe | 185.232.20.195:443 | — | — | — | unknown |
3676 | WindscribeEngine.exe | 192.190.19.1:443 | — | — | US | unknown |
3676 | WindscribeEngine.exe | 104.20.123.38:443 | api.windscribe.com | Cloudflare Inc | US | shared |
3676 | WindscribeEngine.exe | 208.78.41.147:443 | — | Total Server Solutions L.L.C. | US | unknown |
3676 | WindscribeEngine.exe | 107.150.30.67:443 | — | QuadraNet, Inc | US | unknown |
3676 | WindscribeEngine.exe | 173.44.48.3:443 | — | QuadraNet, Inc | US | unknown |
Domain | IP | Reputation |
---|---|---|
www.windscribe.com |
| unknown |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
windscribe.com |
| unknown |
api.windscribe.com |
| unknown |
accounts.google.com |
| shared |
clientservices.googleapis.com |
| whitelisted |
www.google.com.ua |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Encryption) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (PRF) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (PRF) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Auth) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Auth) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Diffie-Hellman) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Diffie-Hellman) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (Encryption) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (PRF) |
— | — | Generic Protocol Command Decode | SURICATA IKEv2 weak cryptographic parameters (PRF) |
Process | Message |
---|---|
Windscribe.exe | [{gmt_time} 0.201] [basic] App start time: "Fri Feb 21 17:45:38 2020"
|
Windscribe.exe | [{gmt_time} 0.202] [basic] OS Version: "Windows 7 Service Pack 1 (major: 6, minor: 1) (build: 7601)"
|
Windscribe.exe | [{gmt_time} 0.568] [basic] Gui user settings: ""
|
Windscribe.exe | [{gmt_time} 0.570] [basic] Gui settings: ""
|
Windscribe.exe | [{gmt_time} 1.909] [basic] Updated scaled hashes for LDPIs: ""
|
Windscribe.exe | [{gmt_time} 3.238] [basic] Gui internal settings: ""
|
Windscribe.exe | [{gmt_time} 3.277] [gui] Disabled Split Tunneling
|
Windscribe.exe | [{gmt_time} 3.313] [basic] Backend::init()
|
Windscribe.exe | [{gmt_time} 6.225] [basic] Backend::onProcessStarted()
|
Windscribe.exe | [{gmt_time} 6.225] [basic] MainWindowController::changeWindow: 1
|