File name:

Eset 授權獲取器 v1.2.exe

Full analysis: https://app.any.run/tasks/b0c0c8ad-ec72-4cb4-a062-f9f483abae85
Verdict: Malicious activity
Analysis date: July 07, 2025, 00:28:20
OS: Windows 10 Professional (build: 19044, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

7EF45C06F75051E22DCB075B4F91A548

SHA1:

82AC43C4FF94A4B3CFC213A9C0552FA922ABF42D

SHA256:

BA0467FBE4AB0157B4EDC1F07A8E272FAB6B21AD00573B3740AC52200149E0BA

SSDEEP:

12288:6Rl0Lba4qPwKU9S0WVaA+a4qPwKU9S0WVaAKSa0k:5Pa48wKWUIA+a48wKWUIAB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads security settings of Internet Explorer

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads Internet Explorer settings

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
  • INFO

    • The sample compiled with english language support

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Checks proxy server information

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Creates files or folders in the user directory

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Checks supported languages

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the computer name

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Create files in a temporary directory

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the machine GUID from the registry

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the software policy settings

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:01:22 10:22:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 122880
InitializedDataSize: 122880
UninitializedDataSize: -
EntryPoint: 0x1228
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.9
ProductVersionNumber: 1.0.0.9
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Developed by avi01
CompanyName: ForumW.org
FileDescription: Get ESET Logins!
ProductName: ESET Login Finder by avi01!!
FileVersion: 1.00.0009
ProductVersion: 1.00.0009
InternalName: Eset Login Viewer v1.2
OriginalFileName: Eset Login Viewer v1.2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eset 授權獲取器 v1.2.exe

Process information

PID
CMD
Path
Indicators
Parent process
2128"C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe" C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe
explorer.exe
User:
admin
Company:
ForumW.org
Integrity Level:
MEDIUM
Description:
Get ESET Logins!
Version:
1.00.0009
Modules
Images
c:\users\admin\appdata\local\temp\eset 授權獲取器 v1.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
2 498
Read events
2 493
Write events
5
Delete events
0

Modification events

(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
Executable files
0
Suspicious files
37
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\lander[1].htmhtml
MD5:3BABF07AA574D8763DD61FE5051E77D9
SHA256:58DFE0949D0E101E2A90A31B314129B7A748EE64B204493082206EADE70E1762
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:932CCB614B981B8372842E32ECC781A5
SHA256:1835D96689BD49692C0439345CA2BEFD3973C4EAFEDF8DBF0CA6E26E55CEC5F3
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:8B5B2482D507004A36CE826117E15FA5
SHA256:C2362F6539316FFBCA845446C0ECF51348140C7A40B237B0E6A694441E85E0A9
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59730952BA026034B98B214466DE1BEC_B82D0A54BE553CEFAEAC7EB404524ABCbinary
MD5:C4BDB78B6D652CCE059D20B3C2D466F5
SHA256:91273E6004DCC07684196C6DF4A78374B2E186412A6D8E416323A59F53F00A63
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:59EFF68EBB481BF29C75998F6AC36B9C
SHA256:902283DDA4CCD498B1996BACD0DFDA502088598EC66060D40613F1FC59863300
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26binary
MD5:9AF475F79BD1CCD7DA7629D0B08AE555
SHA256:BE9B7B49258A24603003E242C2FEBE27BB29DF9357A1C7F7F65209DD08F1E464
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562binary
MD5:81A04435121A3DF64E94EFCC4B15F04D
SHA256:4F659D1D93ED927D782475ECED8EDE6685345F5E6A6E0FF3F57553225682F7D6
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26binary
MD5:4CD80BDD13FD4243B20D1EED4C5535F4
SHA256:D2493D98CFF5B5BF3A9D2508E6B98DE3CCFEDFBE9325030354CCA5F321BC71E0
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:7B7196EF72D28D2C3244A45F36388332
SHA256:10AEE39F086782F65BC34E55F5E433B0BAFC5D1C235CEA2ABAF1EE0AFCD80C59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
37
DNS requests
29
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2128
Eset 授權獲取器 v1.2.exe
GET
200
15.197.204.56:80
http://www.for-ever.cn/nod32/
unknown
unknown
2128
Eset 授權獲取器 v1.2.exe
GET
301
15.197.204.56:80
http://www.for-ever.cn/lander
unknown
unknown
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCAX5fWHFN5qv
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCAzkUhA%3D%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQUwPiEZQ6%2FsVZNPaFToNfxx8ZwqAQUfAwyH6fZMH%2FEfWijYqihzqsHWycCAQc%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
142.250.186.131:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDcoK%2FxnLAb6BIF1Rb7Ythv
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2668
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2128
Eset 授權獲取器 v1.2.exe
15.197.204.56:80
www.for-ever.cn
AMAZON-02
US
unknown
2128
Eset 授權獲取器 v1.2.exe
15.197.204.56:443
www.for-ever.cn
AMAZON-02
US
unknown
2128
Eset 授權獲取器 v1.2.exe
192.124.249.23:80
ocsp.godaddy.com
SUCURI-SEC
US
whitelisted
2128
Eset 授權獲取器 v1.2.exe
142.250.185.68:443
www.google.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
2128
Eset 授權獲取器 v1.2.exe
2.21.239.4:443
img1.wsimg.com
AKAMAI-AS
TR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.for-ever.cn
  • 15.197.204.56
unknown
ocsp.godaddy.com
  • 192.124.249.23
  • 192.124.249.22
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.24
whitelisted
www.google.com
  • 142.250.185.68
whitelisted
img1.wsimg.com
  • 2.21.239.4
  • 2.21.239.21
whitelisted
ocsp.starfieldtech.com
  • 192.124.249.23
  • 192.124.249.41
  • 192.124.249.22
  • 192.124.249.36
  • 192.124.249.24
whitelisted
c.pki.goog
  • 172.217.18.3
whitelisted
o.pki.goog
  • 142.250.186.131
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info