| File name: | EndpointBasecamp.exe |
| Full analysis: | https://app.any.run/tasks/2069550a-8cd0-4d82-a32f-d543b6309ccd |
| Verdict: | Malicious activity |
| Analysis date: | December 21, 2023, 06:45:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 0D7C7C0F7378BA23E7A02ED701C25D19 |
| SHA1: | 4393C7A7A87A036DB13A1FDBAC6B069448C6EBB7 |
| SHA256: | C61821D97B2C6CE257C9A0B0F7E7E8E55C339D99E4767C9B0828B0BFE2C78168 |
| SSDEEP: | 98304:auHwdMBKHiEUEnByICOyjYUt9e41pD2GFrk22Crno+WnSOMHZGOWfUzkdy/I:C |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:02 10:51:01+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 2985472 |
| InitializedDataSize: | 936448 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x254812 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
| FileVersionNumber: | 1.1.0.3970 |
| ProductVersionNumber: | 1.1.0.3970 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build, Special build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | Trend Micro Endpoint Basecamp |
| FileVersion: | 1.1.0.3970 |
| ProductVersion: | 1.1 |
| ProductName: | Trend Micro Endpoint Basecamp |
| CompanyName: | Trend Micro Inc. |
| LegalCopyright: | Copyright (C) 2023 Trend Micro Incorporated. All rights reserved. |
| LegalTrademarks: | Copyright (C) Trend Micro Inc. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | "C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\EndpointBasecamp.exe" /service | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | services.exe | ||||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 1316 | "C:\Windows\temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exe" --install --env prod --region eu1 --install-path "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta" --log-path "C:\Program Files\Trend Micro\Endpoint Basecamp\log" | C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exe | EndpointBasecamp.exe | ||||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Cloud Endpoint Telemetry Service Web Installer Exit code: 0 Version: 1.1.0.1120 Modules
| |||||||||||||||
| 1388 | "C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\modules\\wsc\\WSCommunicator.exe" /service | C:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc\WSCommunicator.exe | services.exe | ||||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Facilitates communication between endpoints and Trend Micro web servers Exit code: 0 Version: 1.1.0.3590 Modules
| |||||||||||||||
| 1528 | "C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk h6KwwM4GW2KquTdRZ1BM | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | — | WSCommunicator.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 1592 | "C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk q22TkH190SRPGLgbQVW5 | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | — | TelemetryAgentServiceWebInstaller.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exe" --service --env="prod" --region="eu1" --log-path="C:\Program Files\Trend Micro\Endpoint Basecamp\log" | C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Telemetry Agent Service Exit code: 0 Version: 1.1.0.1120 Modules
| |||||||||||||||
| 2040 | "C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe" | C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe | — | explorer.exe | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: MEDIUM Description: Trend Micro Endpoint Basecamp Exit code: 3221226540 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe" | C:\Users\admin\AppData\Local\Temp\EndpointBasecamp.exe | explorer.exe | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 2312 | "C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe" /xbc_auth_sdk ZJROchm5TBQElWL4LpOa | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | — | CETASvc.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.3970 Modules
| |||||||||||||||
| 2736 | "C:\Windows\temp\ZU3vljaZcq7\zFWbOLwpMy5\WSCommunicator.exe" /install "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc" | C:\Windows\Temp\ZU3vljaZcq7\zFWbOLwpMy5\WSCommunicator.exe | — | EndpointBasecamp.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Facilitates communication between endpoints and Trend Micro web servers Exit code: 4294967295 Version: 1.1.0.3590 Modules
| |||||||||||||||
| (PID) Process: | (2256) EndpointBasecamp.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2256) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4 |
| Operation: | write | Name: | Blob |
Value: 7E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703072000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6 | |||
| (PID) Process: | (2256) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6 | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | device_id |
Value: 61ae4650-cd2a-406b-8a40-60b6b5a7c3bd | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys |
| Operation: | write | Name: | proxy_username |
Value: TjetSA== | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\SecurityKeys |
| Operation: | write | Name: | proxy_password |
Value: x8RV8Q== | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | sg_proxy_source |
Value: 0 | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | gcs_source |
Value: 0 | |||
| (PID) Process: | (668) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | gcs_allow_fallback |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2256 | EndpointBasecamp.exe | C:\Program Files\Trend Micro\Endpoint Basecamp\log\EndpointBasecamp.log | text | |
MD5:7A55CFCFADF24FA2643E6EDAB9138FC1 | SHA256:BE9E1D6E4D399D2888E92129727FB42A24B211F5FAA996CCE3FF6DDC62FA86C1 | |||
| 2736 | WSCommunicator.exe | C:\Program Files\Trend Micro\Endpoint Basecamp\modules\wsc\WSCommunicator.exe | executable | |
MD5:97B91FF671D7B5E8B8D1DFF9B2BA9F5D | SHA256:0D38AE62A521F541A1DE07601A424E9DDAF6E4D64A1CBA2F3167E50A7C111BD7 | |||
| 1316 | TelemetryAgentServiceWebInstaller.exe | C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\Telemetry Agent\CETASvc.exe | executable | |
MD5:6B7BC6D69732719E31C6D798BC453F2D | SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D | |||
| 1316 | TelemetryAgentServiceWebInstaller.exe | C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta\CETASvc.exe | executable | |
MD5:6B7BC6D69732719E31C6D798BC453F2D | SHA256:3D7C3D52664693D11DA67431FE907464B847952E66D19AEC69D1281083593A1D | |||
| 1316 | TelemetryAgentServiceWebInstaller.exe | C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\Telemetry Agent\TAProfile.json | binary | |
MD5:098D61CCD5895ECC8E58B1FFDED1FA0B | SHA256:3BC60426FEFC731EF80842A8414ADAE029EE78E8BA1D53881B829ECC8D87AA48 | |||
| 1316 | TelemetryAgentServiceWebInstaller.exe | C:\Program Files\Trend Micro\Endpoint Basecamp\log\CETASvcInstDebug.log | text | |
MD5:52AB4B30F0043911E52B6E3E391820A2 | SHA256:A171C415E94BEB5611867A34682327EC36E981EB552128C03F7E3781F14A1A78 | |||
| 2256 | EndpointBasecamp.exe | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | executable | |
MD5:0D7C7C0F7378BA23E7A02ED701C25D19 | SHA256:C61821D97B2C6CE257C9A0B0F7E7E8E55C339D99E4767C9B0828B0BFE2C78168 | |||
| 668 | EndpointBasecamp.exe | C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\dllXbcSdk.dll | executable | |
MD5:3DFB22ED3A8F325762BFE5C4D5E8E5AF | SHA256:7B6733744E775AE89802F2C78548CE45C7F165B6F28B1D4145A67F00B77C7790 | |||
| 668 | EndpointBasecamp.exe | C:\Windows\Temp\Xf6kyGJwQyH\F0pfDbw0HtJ\TelemetryAgentServiceWebInstaller.exe | executable | |
MD5:3A269C8176103B7EEB22936A06358B66 | SHA256:0A6F55E93FE8A45D2A55AF21CBD6400AEC0828D82EF4F0D31C1EFA8E66537C4B | |||
| 668 | EndpointBasecamp.exe | C:\Windows\temp\ZU3vljaZcq7\Eoud2YEt22Q.zip | compressed | |
MD5:0C73A8A425AA2099A99638E686AAF4F2 | SHA256:838ECDA35F69AB9B06ACFBA61CC48B0CCE1A908A4A9324A1503F0A0E601B3570 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
488 | lsass.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c | unknown | — | — | unknown |
— | — | GET | 200 | 18.66.142.79:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D | unknown | binary | 1.39 Kb | unknown |
— | — | GET | 200 | 18.245.65.219:80 | http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAqKI3XBPoe2QOcL3wAx%2Ffc%3D | unknown | binary | 471 b | unknown |
— | — | GET | 200 | 18.66.142.79:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | unknown | binary | 1.51 Kb | unknown |
488 | lsass.exe | GET | 200 | 108.138.2.195:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | unknown | binary | 2.02 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2256 | EndpointBasecamp.exe | 52.29.235.202:443 | api-eu1.xbc.trendmicro.com | AMAZON-02 | DE | unknown |
668 | EndpointBasecamp.exe | 52.57.168.46:443 | api-eu1.xbc.trendmicro.com | AMAZON-02 | DE | unknown |
2256 | EndpointBasecamp.exe | 52.57.168.46:443 | api-eu1.xbc.trendmicro.com | AMAZON-02 | DE | unknown |
668 | EndpointBasecamp.exe | 13.32.27.31:443 | release-us1.mgcp.trendmicro.com | AMAZON-02 | US | unknown |
1316 | TelemetryAgentServiceWebInstaller.exe | 13.32.27.34:443 | release-us1.mgcp.trendmicro.com | AMAZON-02 | US | unknown |
668 | EndpointBasecamp.exe | 52.29.235.202:443 | api-eu1.xbc.trendmicro.com | AMAZON-02 | DE | unknown |
668 | EndpointBasecamp.exe | 13.32.27.34:443 | release-us1.mgcp.trendmicro.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
api-eu1.xbc.trendmicro.com |
| unknown |
release-us1.mgcp.trendmicro.com |
| unknown |
a1bz7u2flvp09t-ats.iot.eu-central-1.amazonaws.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.r2m01.amazontrust.com |
| whitelisted |