File name:

Eset 授權獲取器 v1.2.exe

Full analysis: https://app.any.run/tasks/b0c0c8ad-ec72-4cb4-a062-f9f483abae85
Verdict: Malicious activity
Analysis date: July 07, 2025, 00:28:20
OS: Windows 10 Professional (build: 19044, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

7EF45C06F75051E22DCB075B4F91A548

SHA1:

82AC43C4FF94A4B3CFC213A9C0552FA922ABF42D

SHA256:

BA0467FBE4AB0157B4EDC1F07A8E272FAB6B21AD00573B3740AC52200149E0BA

SSDEEP:

12288:6Rl0Lba4qPwKU9S0WVaA+a4qPwKU9S0WVaAKSa0k:5Pa48wKWUIA+a48wKWUIAB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads security settings of Internet Explorer

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads Internet Explorer settings

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
  • INFO

    • The sample compiled with english language support

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Creates files or folders in the user directory

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the computer name

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Checks supported languages

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Create files in a temporary directory

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Checks proxy server information

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the machine GUID from the registry

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
    • Reads the software policy settings

      • Eset 授權獲取器 v1.2.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:01:22 10:22:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 122880
InitializedDataSize: 122880
UninitializedDataSize: -
EntryPoint: 0x1228
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.9
ProductVersionNumber: 1.0.0.9
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Developed by avi01
CompanyName: ForumW.org
FileDescription: Get ESET Logins!
ProductName: ESET Login Finder by avi01!!
FileVersion: 1.00.0009
ProductVersion: 1.00.0009
InternalName: Eset Login Viewer v1.2
OriginalFileName: Eset Login Viewer v1.2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eset 授權獲取器 v1.2.exe

Process information

PID
CMD
Path
Indicators
Parent process
2128"C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe" C:\Users\admin\AppData\Local\Temp\Eset 授權獲取器 v1.2.exe
explorer.exe
User:
admin
Company:
ForumW.org
Integrity Level:
MEDIUM
Description:
Get ESET Logins!
Version:
1.00.0009
Modules
Images
c:\users\admin\appdata\local\temp\eset 授權獲取器 v1.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
2 498
Read events
2 493
Write events
5
Delete events
0

Modification events

(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(2128) Eset 授權獲取器 v1.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
Executable files
0
Suspicious files
37
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\nod32[1].htmhtml
MD5:E89F75F918DBDCEE28604D4E09DD71D7
SHA256:6DC9C7FC93BB488BB0520A6C780A8D3C0FB5486A4711ACA49B4C53FAC7393023
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:932CCB614B981B8372842E32ECC781A5
SHA256:1835D96689BD49692C0439345CA2BEFD3973C4EAFEDF8DBF0CA6E26E55CEC5F3
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26binary
MD5:9AF475F79BD1CCD7DA7629D0B08AE555
SHA256:BE9B7B49258A24603003E242C2FEBE27BB29DF9357A1C7F7F65209DD08F1E464
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\lander[1].htmhtml
MD5:16DFF4693375CD8384B70A191C5544F5
SHA256:DEA09FDDD4FF3B71A103768AC2271DDC07561B065D9262355DD3A81FFDAF160B
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59730952BA026034B98B214466DE1BEC_B82D0A54BE553CEFAEAC7EB404524ABCbinary
MD5:E1780092A53512868B8D9F9A936F94B9
SHA256:2A96A230C2FDE55FB488FF342E6C8DDA3147A1034A3D2C2DB4C151C4621E0AC2
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\main.f144a171[1].jsbinary
MD5:5C7F20AC0EA14926819B3AB6C277E4AE
SHA256:D49A262E19C792A411F7D535F408CBC0D52262D8725A0A0DED4E97449BA1FDDB
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59730952BA026034B98B214466DE1BEC_B82D0A54BE553CEFAEAC7EB404524ABCbinary
MD5:C4BDB78B6D652CCE059D20B3C2D466F5
SHA256:91273E6004DCC07684196C6DF4A78374B2E186412A6D8E416323A59F53F00A63
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BC2602F5489CFE3E69F81C6328A4C17C_849A9AE095E451B9FFDF6A58F3A98E26binary
MD5:4CD80BDD13FD4243B20D1EED4C5535F4
SHA256:D2493D98CFF5B5BF3A9D2508E6B98DE3CCFEDFBE9325030354CCA5F321BC71E0
2128Eset 授權獲取器 v1.2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\lander[1].htmhtml
MD5:3BABF07AA574D8763DD61FE5051E77D9
SHA256:58DFE0949D0E101E2A90A31B314129B7A748EE64B204493082206EADE70E1762
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
37
DNS requests
29
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2128
Eset 授權獲取器 v1.2.exe
GET
200
15.197.204.56:80
http://www.for-ever.cn/nod32/
unknown
unknown
2128
Eset 授權獲取器 v1.2.exe
GET
301
15.197.204.56:80
http://www.for-ever.cn/lander
unknown
unknown
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCAX5fWHFN5qv
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQUwPiEZQ6%2FsVZNPaFToNfxx8ZwqAQUfAwyH6fZMH%2FEfWijYqihzqsHWycCAQc%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCAzkUhA%3D%3D
unknown
whitelisted
2128
Eset 授權獲取器 v1.2.exe
GET
200
142.250.186.131:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDcoK%2FxnLAb6BIF1Rb7Ythv
unknown
whitelisted
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2668
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2128
Eset 授權獲取器 v1.2.exe
15.197.204.56:80
www.for-ever.cn
AMAZON-02
US
unknown
2128
Eset 授權獲取器 v1.2.exe
15.197.204.56:443
www.for-ever.cn
AMAZON-02
US
unknown
2128
Eset 授權獲取器 v1.2.exe
192.124.249.23:80
ocsp.godaddy.com
SUCURI-SEC
US
whitelisted
2128
Eset 授權獲取器 v1.2.exe
142.250.185.68:443
www.google.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
2128
Eset 授權獲取器 v1.2.exe
2.21.239.4:443
img1.wsimg.com
AKAMAI-AS
TR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.for-ever.cn
  • 15.197.204.56
unknown
ocsp.godaddy.com
  • 192.124.249.23
  • 192.124.249.22
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.24
whitelisted
www.google.com
  • 142.250.185.68
whitelisted
img1.wsimg.com
  • 2.21.239.4
  • 2.21.239.21
whitelisted
ocsp.starfieldtech.com
  • 192.124.249.23
  • 192.124.249.41
  • 192.124.249.22
  • 192.124.249.36
  • 192.124.249.24
whitelisted
c.pki.goog
  • 172.217.18.3
whitelisted
o.pki.goog
  • 142.250.186.131
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info