File name:

EndpointBasecamp.exe

Full analysis: https://app.any.run/tasks/2069550a-8cd0-4d82-a32f-d543b6309ccd
Verdict: Malicious activity
Analysis date: December 21, 2023, 06:45:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

0D7C7C0F7378BA23E7A02ED701C25D19

SHA1:

4393C7A7A87A036DB13A1FDBAC6B069448C6EBB7

SHA256:

C61821D97B2C6CE257C9A0B0F7E7E8E55C339D99E4767C9B0828B0BFE2C78168

SSDEEP:

98304:auHwdMBKHiEUEnByICOyjYUt9e41pD2GFrk22Crno+WnSOMHZGOWfUzkdy/I:C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • EndpointBasecamp.exe (PID: 2256)
      • EndpointBasecamp.exe (PID: 668)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • WSCommunicator.exe (PID: 2736)
  • SUSPICIOUS

    • Reads the Internet Settings

      • EndpointBasecamp.exe (PID: 2256)
    • Executes as Windows Service

      • EndpointBasecamp.exe (PID: 668)
      • CETASvc.exe (PID: 1928)
      • WSCommunicator.exe (PID: 1388)
    • Reads settings of System Certificates

      • EndpointBasecamp.exe (PID: 2256)
    • The process verifies whether the antivirus software is installed

      • EndpointBasecamp.exe (PID: 668)
      • EndpointBasecamp.exe (PID: 2256)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • EndpointBasecamp.exe (PID: 1592)
      • EndpointBasecamp.exe (PID: 2312)
      • WSCommunicator.exe (PID: 2736)
      • WSCommunicator.exe (PID: 1388)
      • EndpointBasecamp.exe (PID: 1528)
      • CETASvc.exe (PID: 1928)
    • Adds/modifies Windows certificates

      • EndpointBasecamp.exe (PID: 2256)
    • Checks Windows Trust Settings

      • EndpointBasecamp.exe (PID: 668)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • EndpointBasecamp.exe (PID: 1592)
      • CETASvc.exe (PID: 1928)
      • EndpointBasecamp.exe (PID: 2312)
      • WSCommunicator.exe (PID: 2736)
      • WSCommunicator.exe (PID: 1388)
      • EndpointBasecamp.exe (PID: 1528)
  • INFO

    • Reads the machine GUID from the registry

      • EndpointBasecamp.exe (PID: 2256)
      • EndpointBasecamp.exe (PID: 668)
      • EndpointBasecamp.exe (PID: 1592)
      • CETASvc.exe (PID: 1928)
      • EndpointBasecamp.exe (PID: 2312)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • WSCommunicator.exe (PID: 2736)
      • WSCommunicator.exe (PID: 1388)
      • EndpointBasecamp.exe (PID: 1528)
    • Checks supported languages

      • EndpointBasecamp.exe (PID: 2256)
      • EndpointBasecamp.exe (PID: 668)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • EndpointBasecamp.exe (PID: 1592)
      • CETASvc.exe (PID: 1928)
      • EndpointBasecamp.exe (PID: 2312)
      • WSCommunicator.exe (PID: 2736)
      • WSCommunicator.exe (PID: 1388)
      • EndpointBasecamp.exe (PID: 1528)
    • Reads the computer name

      • EndpointBasecamp.exe (PID: 2256)
      • EndpointBasecamp.exe (PID: 668)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • CETASvc.exe (PID: 1928)
      • EndpointBasecamp.exe (PID: 1592)
      • EndpointBasecamp.exe (PID: 2312)
      • WSCommunicator.exe (PID: 2736)
      • WSCommunicator.exe (PID: 1388)
      • EndpointBasecamp.exe (PID: 1528)
    • Creates files in the program directory

      • EndpointBasecamp.exe (PID: 2256)
      • TelemetryAgentServiceWebInstaller.exe (PID: 1316)
      • CETASvc.exe (PID: 1928)
      • WSCommunicator.exe (PID: 2736)
    • Reads product name

      • EndpointBasecamp.exe (PID: 668)
      • EndpointBasecamp.exe (PID: 2256)
      • CETASvc.exe (PID: 1928)
    • Reads Environment values

      • EndpointBasecamp.exe (PID: 668)
      • CETASvc.exe (PID: 1928)
      • EndpointBasecamp.exe (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:02 10:51:01+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2985472
InitializedDataSize: 936448
UninitializedDataSize: -
EntryPoint: 0x254812
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.1.0.3970
ProductVersionNumber: 1.1.0.3970
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Trend Micro Endpoint Basecamp
FileVersion: 1.1.0.3970
ProductVersion: 1.1
ProductName: Trend Micro Endpoint Basecamp
CompanyName: Trend Micro Inc.
LegalCopyright: Copyright (C) 2023 Trend Micro Incorporated. All rights reserved.
LegalTrademarks: Copyright (C) Trend Micro Inc.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
10
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start endpointbasecamp.exe endpointbasecamp.exe telemetryagentservicewebinstaller.exe endpointbasecamp.exe no specs cetasvc.exe no specs endpointbasecamp.exe no specs wscommunicator.exe no specs wscommunicator.exe endpointbasecamp.exe no specs endpointbasecamp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\EndpointBasecamp.exe" /serviceC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe
services.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1316"C:\Windows\temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exe" --install --env prod --region eu1 --install-path "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta" --log-path "C:\Program Files\Trend Micro\Endpoint Basecamp\log"C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exe
EndpointBasecamp.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Cloud Endpoint Telemetry Service Web Installer
Exit code:
0
Version:
1.1.0.1120
Modules
Images
c:\windows\temp\xf6kygjwqyh\f0pfdbw0htj\telemetryagentservicewebinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1388"C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\modules\\wsc\\WSCommunicator.exe" /serviceC:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc\WSCommunicator.exe
services.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Facilitates communication between endpoints and Trend Micro web servers
Exit code:
0
Version:
1.1.0.3590
Modules
Images
c:\program files\trend micro\endpoint basecamp\modules\wsc\wscommunicator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1528"C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk h6KwwM4GW2KquTdRZ1BMC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeWSCommunicator.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1592"C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk q22TkH190SRPGLgbQVW5C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeTelemetryAgentServiceWebInstaller.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1928"C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exe" --service --env="prod" --region="eu1" --log-path="C:\Program Files\Trend Micro\Endpoint Basecamp\log"C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exeservices.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Telemetry Agent Service
Exit code:
0
Version:
1.1.0.1120
Modules
Images
c:\program files\trend micro\endpoint basecamp\modules\ceta\cetasvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2040"C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe" C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exeexplorer.exe
User:
admin
Company:
Trend Micro Inc.
Integrity Level:
MEDIUM
Description:
Trend Micro Endpoint Basecamp
Exit code:
3221226540
Version:
1.1.0.3970
Modules
Images
c:\users\admin\appdata\local\temp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
2256"C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe" C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe
explorer.exe
User:
admin
Company:
Trend Micro Inc.
Integrity Level:
HIGH
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\users\admin\appdata\local\temp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2312"C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk ZJROchm5TBQElWL4LpOaC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeCETASvc.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Trend Micro Endpoint Basecamp
Exit code:
0
Version:
1.1.0.3970
Modules
Images
c:\program files\trend micro\endpoint basecamp\endpointbasecamp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2736"C:\Windows\temp\ZU3vljaZcq7\zFWbOLwpMy5\WSCommunicator.exe" /install "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc"C:\Windows\Temp\ZU3vljaZcq7\zFWbOLwpMy5\WSCommunicator.exeEndpointBasecamp.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Facilitates communication between endpoints and Trend Micro web servers
Exit code:
4294967295
Version:
1.1.0.3590
Modules
Images
c:\windows\temp\zu3vljazcq7\zfwbolwpmy5\wscommunicator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
46 447
Read events
46 300
Write events
147
Delete events
0

Modification events

(PID) Process:(2256) EndpointBasecamp.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2256) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
7E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703072000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(2256) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:device_id
Value:
61ae4650-cd2a-406b-8a40-60b6b5a7c3bd
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys
Operation:writeName:proxy_username
Value:
TjetSA==
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys
Operation:writeName:proxy_password
Value:
x8RV8Q==
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:sg_proxy_source
Value:
0
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:gcs_source
Value:
0
(PID) Process:(668) EndpointBasecamp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService
Operation:writeName:gcs_allow_fallback
Value:
1
Executable files
9
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2256EndpointBasecamp.exeC:\Program Files\Trend Micro\Endpoint Basecamp\log\EndpointBasecamp.logtext
MD5:7A55CFCFADF24FA2643E6EDAB9138FC1
SHA256:BE9E1D6E4D399D2888E92129727FB42A24B211F5FAA996CCE3FF6DDC62FA86C1
2736WSCommunicator.exeC:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc\WSCommunicator.exeexecutable
MD5:97B91FF671D7B5E8B8D1DFF9B2BA9F5D
SHA256:0D38AE62A521F541A1DE07601A424E9DDAF6E4D64A1CBA2F3167E50A7C111BD7
1316TelemetryAgentServiceWebInstaller.exeC:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\Telemetry Agent\CETASvc.exeexecutable
MD5:6B7BC6D69732719E31C6D798BC453F2D
SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D
1316TelemetryAgentServiceWebInstaller.exeC:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exeexecutable
MD5:6B7BC6D69732719E31C6D798BC453F2D
SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D
1316TelemetryAgentServiceWebInstaller.exeC:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\Telemetry Agent\TAProfile.jsonbinary
MD5:098D61CCD5895ECC8E58B1FFDED1FA0B
SHA256:3BC60426FEFC731EF80842A8414ADAE029EE78E8BA1D53881B829ECC8D87AA48
1316TelemetryAgentServiceWebInstaller.exeC:\Program Files\Trend Micro\Endpoint Basecamp\log\CETASvcInstDebug.logtext
MD5:52AB4B30F0043911E52B6E3E391820A2
SHA256:A171C415E94BEB5611867A34682327EC36E981EB552128C03F7E3781F14A1A78
2256EndpointBasecamp.exeC:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exeexecutable
MD5:0D7C7C0F7378BA23E7A02ED701C25D19
SHA256:C61821D97B2C6CE257C9A0B0F7E7E8E55C339D99E4767C9B0828B0BFE2C78168
668EndpointBasecamp.exeC:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\dllXbcSdk.dllexecutable
MD5:3DFB22ED3A8F325762BFE5C4D5E8E5AF
SHA256:7B6733744E775AE89802F2C78548CE45C7F165B6F28B1D4145A67F00B77C7790
668EndpointBasecamp.exeC:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exeexecutable
MD5:3A269C8176103B7EEB22936A06358B66
SHA256:0A6F55E93FE8A45D2A55AF21CBD6400AEC0828D82EF4F0D31C1EFA8E66537C4B
668EndpointBasecamp.exeC:\Windows\temp\ZU3vljaZcq7\Eoud2YEt22Q.zipcompressed
MD5:0C73A8A425AA2099A99638E686AAF4F2
SHA256:838ECDA35F69AB9B06ACFBA61CC48B0CCE1A908A4A9324A1503F0A0E601B3570
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
32
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
488
lsass.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c
unknown
unknown
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.39 Kb
unknown
GET
200
18.245.65.219:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAqKI3XBPoe2QOcL3wAx%2Ffc%3D
unknown
binary
471 b
unknown
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.51 Kb
unknown
488
lsass.exe
GET
200
108.138.2.195:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2256
EndpointBasecamp.exe
52.29.235.202:443
api-eu1.xbc.trendmicro.com
AMAZON-02
DE
unknown
668
EndpointBasecamp.exe
52.57.168.46:443
api-eu1.xbc.trendmicro.com
AMAZON-02
DE
unknown
2256
EndpointBasecamp.exe
52.57.168.46:443
api-eu1.xbc.trendmicro.com
AMAZON-02
DE
unknown
668
EndpointBasecamp.exe
13.32.27.31:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown
1316
TelemetryAgentServiceWebInstaller.exe
13.32.27.34:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown
668
EndpointBasecamp.exe
52.29.235.202:443
api-eu1.xbc.trendmicro.com
AMAZON-02
DE
unknown
668
EndpointBasecamp.exe
13.32.27.34:443
release-us1.mgcp.trendmicro.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
api-eu1.xbc.trendmicro.com
  • 52.29.235.202
  • 3.121.243.152
  • 52.57.168.46
  • 3.121.83.106
unknown
release-us1.mgcp.trendmicro.com
  • 13.32.27.31
  • 13.32.27.22
  • 13.32.27.63
  • 13.32.27.34
unknown
a1bz7u2flvp09t-ats.iot.eu-central-1.amazonaws.com
  • 52.29.210.59
  • 3.121.14.25
  • 3.120.195.138
  • 52.57.166.21
  • 3.122.144.72
  • 3.123.216.51
  • 3.122.1.23
  • 3.122.82.143
  • 2a01:578:13::341d:8515
  • 2a01:578:13::378:4e3d
  • 2a01:578:13::341:f302
  • 2a01:578:13::34d:14c
  • 2a01:578:13::341d:34c
  • 2a01:578:13::37d:1d91
  • 2a01:578:13::379:3efd
  • 2a01:578:13::37a:484e
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
o.ss2.us
  • 108.138.2.195
  • 108.138.2.173
  • 108.138.2.107
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
ocsp.r2m01.amazontrust.com
  • 18.245.65.219
whitelisted

Threats

No threats detected
No debug info