File name:

roboforex4setup.exe

Full analysis: https://app.any.run/tasks/65856d67-9d7d-4f07-bfeb-64b0ae87b971
Verdict: Malicious activity
Analysis date: August 13, 2020, 09:17:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

1B5D30B4B9F86D14C0EA5FCDD23C925E

SHA1:

3F59D1FFCEF02488369C16C6C37F9372D1359FAD

SHA256:

ABB2151ECAD0B06D05119787E8BA3444FFF318A2374F0C24A255852BBF05EA06

SSDEEP:

24576:npYrVTcx9jHNB6ftPIkvCzM5KKZfWcfb0sC4a/ym/i2paIKuO4kDo7Xk6:npy49bNBetPIkBKKZfWcAWaKm/Bp5O4f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • roboforex4setup.exe (PID: 4060)
    • Application was dropped or rewritten from another process

      • metaeditor.exe (PID: 3720)
      • terminal.exe (PID: 3040)
      • metaeditor.exe (PID: 1884)
      • metaeditor.exe (PID: 2032)
      • terminal.exe (PID: 2228)
      • metaeditor.exe (PID: 3020)
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • roboforex4setup.exe (PID: 4060)
      • terminal.exe (PID: 2228)
    • Creates files in the user directory

      • roboforex4setup.exe (PID: 4060)
      • metaeditor.exe (PID: 3020)
      • metaeditor.exe (PID: 3720)
      • metaeditor.exe (PID: 2032)
      • metaeditor.exe (PID: 1884)
      • terminal.exe (PID: 3040)
    • Application launched itself

      • roboforex4setup.exe (PID: 296)
    • Creates a software uninstall entry

      • roboforex4setup.exe (PID: 4060)
    • Reads internet explorer settings

      • roboforex4setup.exe (PID: 4060)
      • terminal.exe (PID: 3040)
    • Changes IE settings (feature browser emulation)

      • terminal.exe (PID: 2228)
    • Modifies the open verb of a shell class

      • terminal.exe (PID: 2228)
    • Starts Internet Explorer

      • roboforex4setup.exe (PID: 4060)
    • Adds / modifies Windows certificates

      • roboforex4setup.exe (PID: 4060)
    • Executed via COM

      • explorer.exe (PID: 1752)
    • Executable content was dropped or overwritten

      • roboforex4setup.exe (PID: 4060)
      • terminal.exe (PID: 3040)
    • Creates files in the program directory

      • roboforex4setup.exe (PID: 4060)
  • INFO

    • Reads settings of System Certificates

      • roboforex4setup.exe (PID: 4060)
      • iexplore.exe (PID: 4036)
      • terminal.exe (PID: 3040)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 4036)
    • Changes internet zones settings

      • iexplore.exe (PID: 4044)
    • Application launched itself

      • iexplore.exe (PID: 4044)
    • Creates files in the user directory

      • iexplore.exe (PID: 4036)
    • Reads internet explorer settings

      • iexplore.exe (PID: 4036)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 4036)
    • Changes settings of System certificates

      • iexplore.exe (PID: 4036)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 4036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1970:01:14 14:41:20+01:00
PEType: PE32
LinkerVersion: 14.26
CodeSize: 1011712
InitializedDataSize: 163840
UninitializedDataSize: 2306048
EntryPoint: 0x32a9d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.2516
ProductVersionNumber: 5.0.0.2516
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: https://www.metaquotes.net
CompanyName: MetaQuotes Software Corp.
FileDescription: Setup
FileVersion: 5.0.0.2516
InternalName: Setup
LegalCopyright: © 2000-2020, MetaQuotes Software Corp.
LegalTrademarks: MetaTrader
OriginalFileName: Setup
ProductName: Setup
ProductVersion: 5.0.0.2516
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start roboforex4setup.exe no specs roboforex4setup.exe terminal.exe no specs iexplore.exe explorer.exe no specs explorer.exe no specs iexplore.exe terminal.exe metaeditor.exe no specs metaeditor.exe no specs metaeditor.exe no specs metaeditor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Users\admin\AppData\Local\Temp\roboforex4setup.exe" C:\Users\admin\AppData\Local\Temp\roboforex4setup.exeexplorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
5.0.0.2516
Modules
Images
c:\users\admin\appdata\local\temp\roboforex4setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
636"C:\Windows\explorer.exe" "C:\Program Files\RoboForex - MetaTrader 4\terminal.exe"C:\Windows\explorer.exeroboforex4setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1752C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1884"C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exe" /packed:2 /compile:"1444484_8338" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\56052557894384461B700D080F65E24B\MQL4" /flg:2C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Exit code:
1
Version:
5.0.0.2375
Modules
Images
c:\program files\roboforex - metatrader 4\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2032"C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exe" /packed:1 /compile:"1461125_23217" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\56052557894384461B700D080F65E24B\MQL4" /flg:2C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Exit code:
1
Version:
5.0.0.2375
Modules
Images
c:\program files\roboforex - metatrader 4\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2228"C:\Program Files\RoboForex - MetaTrader 4\terminal.exe" /installC:\Program Files\RoboForex - MetaTrader 4\terminal.exeroboforex4setup.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
HIGH
Description:
MetaTrader
Exit code:
0
Version:
4.0.0.1280
Modules
Images
c:\program files\roboforex - metatrader 4\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
3020"C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exe" /packed:4 /compile:"1457406_20189" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\56052557894384461B700D080F65E24B\MQL4" /flg:2C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Exit code:
1
Version:
5.0.0.2375
Modules
Images
c:\program files\roboforex - metatrader 4\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3040"C:\Program Files\RoboForex - MetaTrader 4\terminal.exe" C:\Program Files\RoboForex - MetaTrader 4\terminal.exe
explorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaTrader
Exit code:
0
Version:
4.0.0.1280
Modules
Images
c:\program files\roboforex - metatrader 4\terminal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
3720"C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exe" /packed:21 /compile:"1447671_8708" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\56052557894384461B700D080F65E24B\MQL4" /flg:2C:\Program Files\RoboForex - MetaTrader 4\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Exit code:
1
Version:
5.0.0.2375
Modules
Images
c:\program files\roboforex - metatrader 4\metaeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
4036"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4044 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
1 707
Read events
1 542
Write events
165
Delete events
0

Modification events

(PID) Process:(296) roboforex4setup.exeKey:HKEY_CURRENT_USER\Software\MetaQuotes Software
Operation:writeName:ID
Value:
4988720482893199139
(PID) Process:(296) roboforex4setup.exeKey:HKEY_CURRENT_USER\Software\MetaQuotes Software
Operation:writeName:Install.Time
Value:
1597310243
(PID) Process:(296) roboforex4setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(296) roboforex4setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Operation:writeName:Blob
Value:
0400000001000000100000008CCADC0B22CEF5BE72AC411A11A8D8120F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B817E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703010B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748506200000001000000200000008D722F81A9C113C0791DF136A2966DB26C950A971DB46B4199F4EA54B78BFB9F53000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070303190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Operation:writeName:Blob
Value:
04000000010000001000000087CE0B7B2A0E4900E158719B37A893720F00000001000000140000006DCA5BD00DCF1C0F327059D374B29CA6E3C50AA60300000001000000140000000563B8630D62D75ABBC8AB1E4BDFB5A899B24D431D00000001000000100000004F5F106930398D09107B40C3C7CA8F1C0B000000010000001200000044006900670069004300650072007400000014000000010000001400000045EBA2AFF492CB82312D518BA7A7219DF36DC80F6200000001000000200000003E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308190000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000BB030000308203B73082029FA00302010202100CE7E0E517D846FE8FE560FC1BF03039300D06092A864886F70D01010505003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3036313131303030303030305A170D3331313131303030303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AD0E15CEE443805CB187F3B760F97112A5AEDC269488AAF4CEF520392858600CF880DAA9159532613CB5B128848A8ADC9F0A0C83177A8F90AC8AE779535C31842AF60F98323676CCDEDD3CA8A2EF6AFB21F25261DF9F20D71FE2B1D9FE1864D2125B5FF9581835BC47CDA136F96B7FD4B0383EC11BC38C33D9D82F18FE280FB3A783D6C36E44C061359616FE599C8B766DD7F1A24B0D2BFF0B72DA9E60D08E9035C678558720A1CFE56D0AC8497C3198336C22E987D0325AA2BA138211ED39179D993A72A1E6FAA4D9D5173175AE857D22AE3F014686F62879C8B1DAE45717C47E1C0EB0B492A656B3BDB297EDAAA7F0B7C5A83F9516D0FFA196EB085F18774F0203010001A3633061300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041445EBA2AFF492CB82312D518BA7A7219DF36DC80F301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010505000382010100A20EBCDFE2EDF0E372737A6494BFF77266D832E4427562AE87EBF2D5D9DE56B39FCCCE1428B90D97605C124C58E4D33D834945589735691AA847EA56C679AB12D8678184DF7F093C94E6B8262C20BD3DB32889F75FFF22E297841FE965EF87E0DFC16749B35DEBB2092AEB26ED78BE7D3F2BF3B726356D5F8901B6495B9F01059BAB3D25C1CCB67FC2F16F86C6FA6468EB812D94EB42B7FA8C1EDD62F1BE5067B76CBDF3F11F6B0C3607167F377CA95B6D7AF112466083D72704BE4BCE97BEC3672A6811DF80E70C3366BF130D146EF37F1F63101EFA8D1B256D6C8FA5B76101B1D2A326A110719DADE2C3F9C39951B72B0708CE2EE650B2A7FA0A452FA2F0F2
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
0400000001000000100000001BFE69D191B71933A372A80FE155E5B50F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD9796254830300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0B00000001000000100000005300650063007400690067006F0000001D0000000100000010000000885010358D29A38F059B028559C95F901400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD253000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B06010505070307190000000100000010000000EA6089055218053DD01E37E1D806EEDF2000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
0400000001000000100000001BFE69D191B71933A372A80FE155E5B5190000000100000010000000EA6089055218053DD01E37E1D806EEDF090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030753000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD21400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB1D0000000100000010000000885010358D29A38F059B028559C95F900B00000001000000100000005300650063007400690067006F0000000300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD9796254832000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(4060) roboforex4setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0
Operation:writeName:Blob
Value:
040000000100000010000000FA68BCD9B57FADFDC91D068328CC24C10F00000001000000300000000B043572C899DEC43EFD590CFCE610CF443A6315925EBFE589F7506907E44824608489581C7CA0E041458514CF157614030000000100000014000000D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF01D0000000100000010000000280CF6042C30A2646644BA7286A3AA971400000001000000140000003AE10986D4CF19C29676744976DCE035C663639A0B00000001000000180000005300650063007400690067006F00200045004300430000006200000001000000200000004FF460D54B9C86DABFBCFC5712E0400D2BED3FBC4D4FBDAA86E06ADCD2A9AD7A53000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030719000000010000001000000076935B5C5A037216DAAF8AAC76DF42C12000000001000000930200003082028F30820215A00302010202105C8B99C55A94C5D27156DECD8980CC26300A06082A8648CE3D040303308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F726974793076301006072A8648CE3D020106052B81040022036200041AAC545AA9F96823E77AD5246F53C65AD84BABC6D5B6D1E67371AEDD9CD60C61FDDBA08903B80514EC57CEEE5D3FE221B3CEF7D48A79E0A3837E2D97D061C4F199DC259163AB7F30A3B470E2C7A1339CF3BF2E5C53B15FB37D327F8A34E37979A3423040301D0603551D0E041604143AE10986D4CF19C29676744976DCE035C663639A300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300A06082A8648CE3D040303036800306502303667A11608DCE49700411D4EBEE16301CF3BAA421164A09D94390211795C7B1DFA64B9EE1642B3BF8AC209C4ECE4B14D023100E92A61478C524A4B4E1870F6D644D66EF583BA6D58BD24D95648EAEFC4A24681886A3A46D1A99B4DC961DAD15D576A18
Executable files
4
Suspicious files
421
Text files
280
Unknown types
37

Dropped files

PID
Process
Filename
Type
4060roboforex4setup.exeC:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt4clwdata.pngcompressed
MD5:
SHA256:
4060roboforex4setup.exeC:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt4clw.pngcompressed
MD5:
SHA256:
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\symbols.selbinary
MD5:A04EFDFF9789F83477813F182A201F63
SHA256:2BD5156BF4E9A9E25A21F5045B8034FB9700079114C9F648F211E093D1E6A88E
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\EURUSD240.hstbinary
MD5:0E99C7C88062C0C789B32114F53DD8F3
SHA256:7FA181A16DA476DE554A4F61A30A3FA8A1128151082CFFE958327CA525943FC6
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\symbols.rawbinary
MD5:C995D35D802DD67519C5AB906A705187
SHA256:6C297768B98217333BBFDBE3109D7825F7E7B3AF6D40DCD9282D042649975982
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\config\terminal.initext
MD5:DA3FDC4AC3A86B9E2B577D20B4671DA1
SHA256:1416CD862425A3D11EED28BAE3950B3CDCA9983511A85B2B2A588DC8FF82AFA0
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\symgroups.rawbinary
MD5:3038C31B38BC8AE5997C5DAFC3CB9656
SHA256:697EE540318F56C6989007CFA2730B4528AE5E06CFC3C878DCCE98CA21515CEE
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\DDE-Sample.xlsdocument
MD5:CAF7D7F7629CC537EFCD83EFC78AE898
SHA256:59AD82F6306D8CA6379D2B5E3087D1B6F20AF8B57A4F9E148282E4AF927D2490
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\USDJPY240.hstbinary
MD5:636AAEA02F7C0DC5F118006B513B8EB2
SHA256:F8CC9DC0AB2F8B54A0F95ADA3F0BACDA522522C8EE8288ABB8DD64C9A7C5990E
4060roboforex4setup.exeC:\Program Files\RoboForex - MetaTrader 4\history\default\GBPUSD240.hstbinary
MD5:1883C6A300205C1BF53035F7BF419BC0
SHA256:B293A98E2BBF3746E87870C57F0F5BFEA2ABA52BCC70270ED6DDB22A448F618A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
317
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4036
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
US
der
314 b
whitelisted
4036
iexplore.exe
GET
200
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
200
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
304
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
304
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
304
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
304
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
304
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
56.7 Kb
whitelisted
4036
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
US
der
314 b
whitelisted
4036
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEFD9JNA2QaMtHNTAv5vIOzE%3D
US
der
279 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4060
roboforex4setup.exe
78.140.180.86:443
content.mql5.com
Webzilla B.V.
NL
suspicious
4060
roboforex4setup.exe
52.184.28.1:443
Microsoft Corporation
HK
unknown
4060
roboforex4setup.exe
206.221.189.58:443
Choopa, LLC
US
unknown
4060
roboforex4setup.exe
64.120.89.44:443
Nobis Technology Group, LLC
US
unknown
4060
roboforex4setup.exe
88.212.244.84:443
Servers.com, Inc.
RU
unknown
4060
roboforex4setup.exe
139.99.68.28:443
OVH SAS
SG
unknown
4060
roboforex4setup.exe
156.38.206.18:443
HETZNER
ZA
suspicious
4060
roboforex4setup.exe
177.154.156.125:443
EQUINIX BRASIL SP
BR
suspicious
4060
roboforex4setup.exe
142.0.194.252:443
Servers.com, Inc.
US
unknown
138.201.201.91:443
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
content.mql5.com
  • 78.140.180.86
  • 116.202.51.42
suspicious
api1.mql5.net
  • 78.140.180.43
suspicious
www.mql5.com
  • 78.140.180.100
suspicious
ocsp.usertrust.com
  • 151.139.128.14
whitelisted
c.mql5.com
  • 78.140.180.54
suspicious
www.download.windowsupdate.com
  • 2.16.186.81
  • 2.16.186.56
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.sectigo.com
  • 151.139.128.14
whitelisted
mt4-ecn-dc1.roboforex.com
  • 193.42.110.93
unknown

Threats

No threats detected
No debug info