| File name: | Eset 授權獲取器 v1.2.exe |
| Full analysis: | https://app.any.run/tasks/b0c0c8ad-ec72-4cb4-a062-f9f483abae85 |
| Verdict: | Malicious activity |
| Analysis date: | July 07, 2025, 00:28:20 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 7EF45C06F75051E22DCB075B4F91A548 |
| SHA1: | 82AC43C4FF94A4B3CFC213A9C0552FA922ABF42D |
| SHA256: | BA0467FBE4AB0157B4EDC1F07A8E272FAB6B21AD00573B3740AC52200149E0BA |
| SSDEEP: | 12288:6Rl0Lba4qPwKU9S0WVaA+a4qPwKU9S0WVaAKSa0k:5Pa48wKWUIA+a48wKWUIAB |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:01:22 10:22:14+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 122880 |
| InitializedDataSize: | 122880 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1228 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.9 |
| ProductVersionNumber: | 1.0.0.9 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | Developed by avi01 |
| CompanyName: | ForumW.org |
| FileDescription: | Get ESET Logins! |
| ProductName: | ESET Login Finder by avi01!! |
| FileVersion: | 1.00.0009 |
| ProductVersion: | 1.00.0009 |
| InternalName: | Eset Login Viewer v1.2 |
| OriginalFileName: | Eset Login Viewer v1.2.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2128 | "C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe" | C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe | explorer.exe | ||||||||||||
User: admin Company: ForumW.org Integrity Level: MEDIUM Description: Get ESET Logins! Version: 1.00.0009 Modules
| |||||||||||||||
| (PID) Process: | (2128) Eset 授權獲取器 v1.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2128) Eset 授權獲取器 v1.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2128) Eset 授權獲取器 v1.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2128) Eset 授權獲取器 v1.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch |
| Operation: | write | Name: | Version |
Value: WS not running | |||
| (PID) Process: | (2128) Eset 授權獲取器 v1.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\lander[1].htm | html | |
MD5:3BABF07AA574D8763DD61FE5051E77D9 | SHA256:58DFE0949D0E101E2A90A31B314129B7A748EE64B204493082206EADE70E1762 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 | binary | |
MD5:932CCB614B981B8372842E32ECC781A5 | SHA256:1835D96689BD49692C0439345CA2BEFD3973C4EAFEDF8DBF0CA6E26E55CEC5F3 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 | binary | |
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5 | SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 | binary | |
MD5:8B5B2482D507004A36CE826117E15FA5 | SHA256:C2362F6539316FFBCA845446C0ECF51348140C7A40B237B0E6A694441E85E0A9 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59730952BA026034B98B214466DE1BEC_B82D0A54BE553CEFAEAC7EB404524ABC | binary | |
MD5:C4BDB78B6D652CCE059D20B3C2D466F5 | SHA256:91273E6004DCC07684196C6DF4A78374B2E186412A6D8E416323A59F53F00A63 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:59EFF68EBB481BF29C75998F6AC36B9C | SHA256:902283DDA4CCD498B1996BACD0DFDA502088598EC66060D40613F1FC59863300 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26 | binary | |
MD5:9AF475F79BD1CCD7DA7629D0B08AE555 | SHA256:BE9B7B49258A24603003E242C2FEBE27BB29DF9357A1C7F7F65209DD08F1E464 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562 | binary | |
MD5:81A04435121A3DF64E94EFCC4B15F04D | SHA256:4F659D1D93ED927D782475ECED8EDE6685345F5E6A6E0FF3F57553225682F7D6 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26 | binary | |
MD5:4CD80BDD13FD4243B20D1EED4C5535F4 | SHA256:D2493D98CFF5B5BF3A9D2508E6B98DE3CCFEDFBE9325030354CCA5F321BC71E0 | |||
| 2128 | Eset 授權獲取器 v1.2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 | binary | |
MD5:7B7196EF72D28D2C3244A45F36388332 | SHA256:10AEE39F086782F65BC34E55F5E433B0BAFC5D1C235CEA2ABAF1EE0AFCD80C59 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 15.197.204.56:80 | http://www.for-ever.cn/nod32/ | unknown | — | — | unknown |
2128 | Eset 授權獲取器 v1.2.exe | GET | 301 | 15.197.204.56:80 | http://www.for-ever.cn/lander | unknown | — | — | unknown |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCAX5fWHFN5qv | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 172.217.18.3:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.starfieldtech.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCAzkUhA%3D%3D | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.starfieldtech.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQUwPiEZQ6%2FsVZNPaFToNfxx8ZwqAQUfAwyH6fZMH%2FEfWijYqihzqsHWycCAQc%3D | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 172.217.18.3:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | GET | 200 | 142.250.186.131:80 | http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDcoK%2FxnLAb6BIF1Rb7Ythv | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2668 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | 15.197.204.56:80 | www.for-ever.cn | AMAZON-02 | US | unknown |
2128 | Eset 授權獲取器 v1.2.exe | 15.197.204.56:443 | www.for-ever.cn | AMAZON-02 | US | unknown |
2128 | Eset 授權獲取器 v1.2.exe | 192.124.249.23:80 | ocsp.godaddy.com | SUCURI-SEC | US | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | 142.250.185.68:443 | www.google.com | GOOGLE | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2128 | Eset 授權獲取器 v1.2.exe | 2.21.239.4:443 | img1.wsimg.com | AKAMAI-AS | TR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.for-ever.cn |
| unknown |
ocsp.godaddy.com |
| whitelisted |
www.google.com |
| whitelisted |
img1.wsimg.com |
| whitelisted |
ocsp.starfieldtech.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
crl.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |