| File name: | HousecallLauncher64.exe |
| Full analysis: | https://app.any.run/tasks/9e4e3bea-6828-45ce-9292-5caa474d7bff |
| Verdict: | Malicious activity |
| Analysis date: | June 04, 2025, 09:12:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | 1AEF0C3744DF974A5BD4AFC86FB5559B |
| SHA1: | 3355AA72E9A4CFCD9F35D880E718E1EC84B269BE |
| SHA256: | B1A29C465A85169B3A888B1A644C21E4B9D3F3C9D5AA56BEF343E5D42B859AA1 |
| SSDEEP: | 98304:xeU69y3++14cqKaRRDw5em/a15+m8tWnRcbS8CXDH3dCfQvx0rSxLyldIfwIfU71:m02XJSJH |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:11:12 07:12:04+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.28 |
| CodeSize: | 483840 |
| InitializedDataSize: | 323072 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x27c34 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.62.1.1180 |
| ProductVersionNumber: | 1.62.1.1180 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Trend Micro Inc. |
| CoverageBuild: | None |
| CompileOption: | None |
| BuildType: | Rel |
| FileDescription: | Trend Micro Application Launcher |
| FileVersion: | 1.62.1.1180 |
| InternalName: | AppLauncher.exe |
| LegalCopyright: | Copyright (C) 2024 Trend Micro Incorporated. All rights reserved. |
| LegalTrademarks: | Copyright (C) Trend Micro Inc. |
| OriginalFileName: | 7zsfx.exe |
| ProductName: | Trend Micro HouseCall |
| ProductVersion: | 1.62 |
| SpecialBuild: | 1180 |
| PrivateBuild: | Build 1180 - None |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2236 | "C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe" | C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe | — | explorer.exe | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: MEDIUM Description: Trend Micro Application Launcher Exit code: 3221226540 Version: 1.62.1.1180 Modules
| |||||||||||||||
| 2868 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | hcpackage64.exe.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3140 | exe.exe -y | C:\Program Files\Trend Micro\HCBackup\hcpackage64.exe.tmp | Setup.exe | ||||||||||||
User: admin Company: trend_company_name Integrity Level: HIGH Description: Trend Micro HouseCall Exit code: 0 Version: 1.62.1.1180 Modules
| |||||||||||||||
| 6040 | "C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe" | C:\Users\admin\AppData\Local\Temp\HousecallLauncher64.exe | explorer.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro Application Launcher Version: 1.62.1.1180 Modules
| |||||||||||||||
| 7184 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7252 | "C:\Program Files\Trend Micro\7zS8974FB52\AU\patch64.exe" "C:\Program Files\Trend Micro\7zS8974FB52\AU\AU_Data\AU_Temp\7376_6300" 0 | C:\Program Files\Trend Micro\7zS8974FB52\AU\patch64.exe | Setup.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: patch program Exit code: 0 Version: 2.89.0.1055 Modules
| |||||||||||||||
| 7376 | .\setup.exe | C:\Program Files\Trend Micro\7zS8974FB52\Setup.exe | HousecallLauncher64.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro HouseCall Launcher Version: 1.62.1.1180 Modules
| |||||||||||||||
| 8076 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | patch64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7376) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\HouseCall |
| Operation: | write | Name: | VID |
Value: HC202410 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\au.db | binary | |
MD5:819F4E8DEAEB5AC05799CF24513AA321 | SHA256:E34768E56F82BF755E9E2DB1ABC2D64C7B20F82913EDBBEBEE10C55ED54BAC6D | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\aucfg.ini | binary | |
MD5:B8994884773962713DB9181A52396B87 | SHA256:4C3E192E58A42249C96432828155CA0A54A3D669287444DE655B7564D0C0429E | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\HouseCall_downloader.bmp | image | |
MD5:8E6E50CF326A4704AC34E518BFFAE9DA | SHA256:A22AF87CA743498627C1E3DD15709E41F3AB488D4B358F9BAFB5AFD5E842EEE2 | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\DLConfig.xml | text | |
MD5:2B4A6799C0D14E9CE75B40702B93EA6D | SHA256:A3EFF19AF84B0588FB51CDDF9902DA561AC189F89EC5F6C98FC21348459667E7 | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\curl-ca-bundle.crt | text | |
MD5:C658D9F253217D3C010B830D05973BB7 | SHA256:193A35B6DE7EE049FF512599DD4E8290DC30C2F47F9A3818CA8F273FFCA683DB | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\x500_std.db | binary | |
MD5:4A5254761F92EB0FB968421DB26BBB0B | SHA256:48335D3E1165FD3C504845E0BD279436302D9B90DC99C4B6A070302D555D5EAF | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\cert5_std.db | binary | |
MD5:A693B8CD8EC6F1ABF4D824661D6E50CE | SHA256:2E2016B9247EC27A7C0B11F4E28D00BA452B4A64C5218AC1FF3E165842A922DE | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\dlstr.xml | xml | |
MD5:976BA471421A8EAA9013C591A452FD9D | SHA256:3CD7CED197B7AAD0B94E9029AA7057CA8AE13F63FEFA212C6D744DDF569D5F71 | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\ciussi64.dll | executable | |
MD5:A32BCF865C1D39D306D9B552C48A9A6F | SHA256:D59AFADF3515DBA5BF2B469CB9C9A0187902A3A9E9E612BBA3FE70A8394A2761 | |||
| 6040 | HousecallLauncher64.exe | C:\Program Files\Trend Micro\7zS8974FB52\AU\Build64.exe | executable | |
MD5:C6FCFA160487FBA72DC2DB84AC9EEF3A | SHA256:824ABB1E7DA6BBEF6512FFA9D71AF647718425C604308AC1348374E45644845C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7376 | Setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm%2FrYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEA6g%2Fk37dMxkvDIUMQPCfIs%3D | unknown | — | — | whitelisted |
7376 | Setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEALE0eWKSmgMVo2jBH5%2BTV8%3D | unknown | — | — | whitelisted |
2392 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7376 | Setup.exe | HEAD | 200 | 184.24.77.60:80 | http://housecall8-ctp-p.activeupdate.trendmicro.co.jp:80/activeupdate/japan/ini_xml.zip | unknown | — | — | unknown |
7376 | Setup.exe | GET | 200 | 184.24.77.60:80 | http://housecall8-ctp-p.activeupdate.trendmicro.co.jp:80/activeupdate/japan/pattern/icrc/ioth2024300.zip | unknown | — | — | unknown |
7376 | Setup.exe | GET | 200 | 2.19.126.152:80 | http://housecall8-ctp-p.activeupdate.trendmicro.co.jp:80/activeupdate/japan/pattern/tmwlchk_205500.zip | unknown | — | — | unknown |
7376 | Setup.exe | GET | 200 | 184.24.77.60:80 | http://housecall8-ctp-p.activeupdate.trendmicro.co.jp:80/activeupdate/japan/engine/dce-dll-mssign-x64-v75-1035.zip | unknown | — | — | unknown |
7376 | Setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAMoAohqwi3Iey%2BznBTYouQ%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
7636 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
4452 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7376 | Setup.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
7376 | Setup.exe | 2.23.245.87:443 | go.trendmicro.com | Ooredoo Q.S.C. | QA | whitelisted |
6544 | svchost.exe | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.trendmicro.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7376 | Setup.exe | Attempted Administrator Privilege Gain | AV EXPLOIT Potential ZIP file exploiting CVE-2023-36413 |
7376 | Setup.exe | Attempted Administrator Privilege Gain | AV EXPLOIT Potential ZIP file exploiting CVE-2023-36413 |