| URL: | http://cdn.sa.services.tomtom.com/static/sa/Windows/InstallTomTomMyDriveConnect.exe |
| Full analysis: | https://app.any.run/tasks/684a783c-d937-4fa5-9289-37502a5d8c20 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | October 13, 2019, 14:13:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | A163AE5FACF099DC9F05C41360438B8F |
| SHA1: | 9A7129E2CAE3BAD7272127A39A31CE98B93E7EC1 |
| SHA256: | AA2DA5AAEBC570B84AEC110696FC39B362815AF17DE0BA49FF3F3AC9524C1CE0 |
| SSDEEP: | 3:N1KdBLnLWATGKmBGKGLBJaTmc6TDeAGJ:CXnLHKKmED+mPneAk |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1316 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6d90a9d0,0x6d90a9e0,0x6d90a9ec | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1552 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1028,13295521692237414746,15435509559317568879,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=7743226348407567728 --mojo-platform-channel-handle=3200 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1712 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1028,13295521692237414746,15435509559317568879,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=8511388893917632351 --mojo-platform-channel-handle=3472 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1728 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1028,13295521692237414746,15435509559317568879,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7957356398923560252 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2252 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1800 | "C:\Windows\explorer.exe" "C:\Users\admin\AppData\Local\Temp\TempMDC.lnk" | C:\Windows\explorer.exe | — | InstallTomTomMyDriveConnect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1904 | "C:\Program Files\MyDrive Connect\MDCLauncher.exe" | C:\Program Files\MyDrive Connect\MDCLauncher.exe | MDCDLLChecker.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1944 | "C:\Program Files\MyDrive Connect"\\qtdiag.exe | C:\Program Files\MyDrive Connect\qtdiag.exe | cmd.exe | ||||||||||||
User: admin Company: The Qt Company Ltd. Integrity Level: MEDIUM Description: Qt Qtdiag Exit code: 0 Version: 5.9.7.0 Modules
| |||||||||||||||
| 1956 | "C:\Program Files\MyDrive Connect\Driver\win32\DriverPreInstall.exe" | C:\Program Files\MyDrive Connect\Driver\win32\DriverPreInstall.exe | — | InstallTomTomMyDriveConnect.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2004 | "C:\Users\admin\Downloads\InstallTomTomMyDriveConnect.exe" | C:\Users\admin\Downloads\InstallTomTomMyDriveConnect.exe | — | chrome.exe | |||||||||||
User: admin Company: TomTom International B.V. Integrity Level: MEDIUM Description: TomTom MyDrive Connect Exit code: 3221226540 Version: 4.2.6.3888 Modules
| |||||||||||||||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3696) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2552-13215449613863000 |
Value: 259 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
| (PID) Process: | (2552) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6256c899-dedb-4b31-ab09-0a371175649e.tmp | — | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF39aa54.TMP | text | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000001 | — | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000001.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2172 | TomTom MyDrive Connect.exe | GET | — | 216.58.205.228:80 | http://www.google.com/ | US | — | — | malicious |
3820 | chrome.exe | GET | 200 | 2.18.232.239:80 | http://cdn.sa.services.tomtom.com/static/sa/Windows/InstallTomTomMyDriveConnect.exe | unknown | executable | 66.9 Mb | malicious |
2172 | TomTom MyDrive Connect.exe | GET | — | 216.58.205.228:80 | http://www.google.com/ | US | — | — | malicious |
2172 | TomTom MyDrive Connect.exe | GET | 200 | 2.18.232.239:80 | http://cdn.sa.services.tomtom.com/static/sa/localisations/TomTomSupporter_en_US.qm | unknown | qm | 52.1 Kb | malicious |
2172 | TomTom MyDrive Connect.exe | GET | 200 | 2.18.232.239:80 | http://cdn.sa.services.tomtom.com/static/sa/localisations/UIWebKitController_en_US.qm | unknown | qm | 8.74 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3820 | chrome.exe | 216.58.205.227:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3820 | chrome.exe | 2.18.232.239:80 | cdn.sa.services.tomtom.com | Akamai International B.V. | — | whitelisted |
3820 | chrome.exe | 216.58.207.45:443 | accounts.google.com | Google Inc. | US | whitelisted |
3820 | chrome.exe | 216.58.205.228:443 | www.google.com | Google Inc. | US | whitelisted |
3820 | chrome.exe | 172.217.23.163:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
3820 | chrome.exe | 216.58.206.3:443 | www.gstatic.com | Google Inc. | US | whitelisted |
2172 | TomTom MyDrive Connect.exe | 216.58.205.228:80 | www.google.com | Google Inc. | US | whitelisted |
3624 | DxDiag.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3820 | chrome.exe | 172.217.16.206:443 | clients1.google.com | Google Inc. | US | whitelisted |
2172 | TomTom MyDrive Connect.exe | 185.5.121.58:80 | sa.services.tomtom.com | TomTom International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
cdn.sa.services.tomtom.com |
| malicious |
accounts.google.com |
| shared |
www.google.com |
| malicious |
ssl.gstatic.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
clients1.google.com |
| whitelisted |
sa.services.tomtom.com |
| unknown |
www.download.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3820 | chrome.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3820 | chrome.exe | Generic Protocol Command Decode | SURICATA HTTP unable to match response to request |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake SYN resend different seq on SYN recv |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake SYNACK resend with different ack |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake SYNACK resend with different ack |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake SYN resend different seq on SYN recv |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake SYNACK resend with different ack |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM 3way handshake wrong seq wrong ack |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM Packet with invalid ack |
2172 | TomTom MyDrive Connect.exe | Generic Protocol Command Decode | SURICATA STREAM SHUTDOWN RST invalid ack |
Process | Message |
|---|---|
MDCLauncher.exe | data location: "C:/Users/admin/AppData/Local/TomTom/HOME3"
|
MDCLauncher.exe | doc location: "C:/Users/admin/Documents"
|
MDCLauncher.exe | cache location: "C:/Users/admin/AppData/Local/TomTom/HOME3/cache"
|
MDCLauncher.exe | home location: "C:/Users/admin"
|
TomTom MyDrive Connect.exe | the open gl variable ""
|
TomTom MyDrive Connect.exe | QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
|
TomTom MyDrive Connect.exe | QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available
|
TomTom MyDrive Connect.exe | data location: "C:/Users/admin/AppData/Local/TomTom/HOME3"
|
TomTom MyDrive Connect.exe | doc location: "C:/Users/admin/Documents"
|
TomTom MyDrive Connect.exe | cache location: "C:/Users/admin/AppData/Local/TomTom/HOME3/cache"
|