| File name: | centbrowser_5.0.1002.354_x64.exe |
| Full analysis: | https://app.any.run/tasks/b7cd05aa-b502-4cff-afa5-9d0370d508e6 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | May 20, 2025, 17:07:12 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 8 sections |
| MD5: | 5BBC8606A3CE3CA6922A21A8410CE667 |
| SHA1: | C8553ABAD299BFEFD8F350F44615E27F4A8CD93B |
| SHA256: | B8EEFD006853FC7B415CCBE4987D9B03F83C92CFEE55182A59E4217AFD2A0ABA |
| SSDEEP: | 786432:nYqhfyZZyETwHWcNY9zAqFvRMIpMcf5L3FOHlr1wSMZLQgv83PFH:n7VyTLMl+1oIpMcf5LF21GZLQ79 |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2022:07:20 01:00:58+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14 |
| CodeSize: | 13824 |
| InitializedDataSize: | 101523456 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1000 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.1002.354 |
| ProductVersionNumber: | 5.0.1002.354 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Cent Studio |
| FileDescription: | CentBrowser Installer |
| FileVersion: | 5.0.1002.354 |
| InternalName: | mini_installer |
| LegalCopyright: | Copyright 2022 Cent Studio. All rights reserved. |
| ProductName: | CentBrowser Installer |
| ProductVersion: | 5.0.1002.354 |
| CompanyShortName: | Cent Studio |
| ProductShortName: | CentBrowser Installer |
| LastChange: | e51e22f80a0d067416a443ed9c4cb5871f48937a-refs/branch-heads/5005@{#1268} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 540 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=57 --mojo-platform-channel-handle=2780 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 664 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --start-stack-profiler --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=42 --mojo-platform-channel-handle=6752 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 664 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=62 --mojo-platform-channel-handle=5580 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 672 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=73 --mojo-platform-channel-handle=6412 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 680 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=6012 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 732 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=6044 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 736 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=69 --mojo-platform-channel-handle=5752 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 744 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=72 --mojo-platform-channel-handle=6620 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 812 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=52 --mojo-platform-channel-handle=6436 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| 1128 | "C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=109 --mojo-platform-channel-handle=6288 --field-trial-handle=1884,i,660608601917485215,10641693998038613805,131072 --enable-features=ScrollableTabStrip /prefetch:1 | C:\Users\admin\AppData\Local\CentBrowser\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Cent Studio Integrity Level: LOW Description: Cent Browser Exit code: 0 Version: 5.0.1002.354 Modules
| |||||||||||||||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 19 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 25 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 39 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 59 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 46 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | InstallerProgress |
Value: 53 | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | UninstallString |
Value: C:\Users\admin\AppData\Local\CentBrowser\Application\5.0.1002.354\Installer\setup.exe | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\CentBrowser |
| Operation: | write | Name: | UninstallArguments |
Value: --uninstall | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CentBrowser |
| Operation: | write | Name: | DisplayName |
Value: Cent Browser | |||
| (PID) Process: | (8036) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CentBrowser |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\CentBrowser\Application\5.0.1002.354\Installer\setup.exe" --uninstall | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\ICUDTL.DA_ | — | |
MD5:— | SHA256:— | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\icudtl.dat | — | |
MD5:— | SHA256:— | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\d3dcompiler_47.dll | executable | |
MD5:CB9807F6CF55AD799E920B7E0F97DF99 | SHA256:5653BC7B0E2701561464EF36602FF6171C96BFFE96E4C3597359CD7ADDCBA88A | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\libEGL.dll | executable | |
MD5:E80893E22147700CDBA830378AC93E41 | SHA256:59D40B6FDF629163F89E965ECF7FECE51B696899F9BBF8C85512E0B177080BA3 | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\D3DCOMPILER_47.DL_ | compressed | |
MD5:52A4A61292F11633F149C21097436C45 | SHA256:6AB728490D04883189F86A7F076D13B95E2F729F1F343D12238A8129CB668430 | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\setup_resources\SETUP_STRINGS_FR.PAK | binary | |
MD5:97DF97F40B1A0E8E90CD367CCF7E8E86 | SHA256:B8C3C0116EF6BF02DE72400C2F8F81DA6CD03318AB27601CEEF31022AE274B64 | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\libGLESv2.dll | executable | |
MD5:EE4D3F47E1BE38B34B2949ED568FAA2F | SHA256:0203D48CEF8A9E48C2DD67CDFC3819DAB61A3A41E535F2E6116D8AFBC695E7D7 | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\setup_resources\SETUP_IMAGES_100_PERCENT.PAK | binary | |
MD5:55F47F7D5273A1B30A4797A2B7A61934 | SHA256:FD481515C4598EADB7F779997BB1D6BFB9656A0BE7299A4570240826152BB78B | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\setup_resources\SETUP_STRINGS_EN-US.PAK | pgc | |
MD5:A3B94840D04C161B0C5CA93772F95F73 | SHA256:DF644F20C0BD7B2F20BE98945EF3001F0C55D702F575C2E85F1753927BA63A1E | |||
| 7888 | centbrowser_5.0.1002.354_x64.exe | C:\Users\admin\AppData\Local\Temp\CB_W6X8H0_CR_58412.tmp\LIBGLESV2.DL_ | compressed | |
MD5:A2C2C93E43F15F4E5C9A8EBE65CE2DC5 | SHA256:ADCFA041B47B4E978F65855428402476D3E6CD9AA5E5E91233D2B06CC0CE80CA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2104 | svchost.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7372 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7sy7xmfackw2sk6iujs3vzvwsa_9799/hfnkpimlhhgieaddgfemjhofmfblmnib_9799_all_acwopzqpez52ugbathatzmi6vgga.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | unknown | — | — | whitelisted |
7372 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 69.192.161.161:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5024 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2108 | chrome.exe | 74.125.71.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
2108 | chrome.exe | 104.22.36.210:443 | stat.centbrowser.com | CLOUDFLARENET | — | suspicious |
2108 | chrome.exe | 142.250.185.106:443 | optimizationguide-pa.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
stat.centbrowser.com |
| unknown |
accounts.google.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
www.ebay.com |
| whitelisted |
ir.ebaystatic.com |
| whitelisted |
srv.main.ebayrtm.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M2 |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1 |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M3 |
— | — | Misc activity | SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1 |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M2 |
— | — | Misc activity | SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt) |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M3 |
— | — | Misc activity | ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1 |