| URL: | https://stamp.iwin.com:443/msnugm3/v1/5502524219256337855/sallys-salon---beauty-secrets-platinum-edition/51/0/sallys-salon---beauty-secrets-platinum-editionSetup.exe |
| Full analysis: | https://app.any.run/tasks/1b2bec89-2404-42b7-a804-ef74ad733d58 |
| Verdict: | Malicious activity |
| Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
| Analysis date: | January 14, 2019, 15:27:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | F058F307877B581A1906684BC1A05506 |
| SHA1: | F10C65FC454FB29FB186C32317A67F0C6783841B |
| SHA256: | CA73CB0E47DC5D7604A6765F72143974F87BBE7492F9FB70292380F1D5DA7BB0 |
| SSDEEP: | 3:N8cD4STdwa8WpmCRZdQNlrWCWAG2lQTZKDHrWCWAG2lQ+AyL4A:2cjTdz8iBjElr6jhT0DHr6jh+AY4A |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1016 | "C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe" -config.uri=https://ugm3-msn.iwin.com/ -config.channel="20000009" -config.sku="FIRST_INSTALL" -config.iwinrequest="PF/5502524219256337855/sallys-salon---beauty-secrets-platinum-edition/51/0" | C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe | GamesManagerInstaller.exe | ||||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: Download Games Manager Exit code: 0 Version: 3.6.1.532 Modules
| |||||||||||||||
| 1348 | "C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe" --type=gpu-process --no-sandbox --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\debug.log" --user-agent="Mozilla/5.0 (Windows NT) Version/3.6.1.532 GamesManager/3.6.1.532 20000009 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --disable-direct-composition --use-gl=swiftshader-webgl --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,22,23,24,27,49,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --disable-accelerated-video-decode --gpu-vendor-id=0x1234 --gpu-device-id=0x1111 --gpu-driver-vendor="Google Inc." --gpu-driver-version=3.3.0.2 --gpu-driver-date=2017/04/07 --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\debug.log" --user-agent="Mozilla/5.0 (Windows NT) Version/3.6.1.532 GamesManager/3.6.1.532 20000009 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --service-request-channel-token=F455FF80FF072C0506F29561C159061B --mojo-platform-channel-handle=2604 /prefetch:2 | C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe | GamesManager.exe | ||||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: Download Games Manager Exit code: 3221226356 Version: 3.6.1.532 Modules
| |||||||||||||||
| 1512 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\sallys-salon---beauty-secrets-platinum-editionSetup[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | — | iexplore.exe | |||||||||||
User: admin Company: iWin inc. Integrity Level: MEDIUM Description: MsnStreaming Games Downloader Exit code: 3221226540 Version: 1.0.6.0 Modules
| |||||||||||||||
| 1812 | "C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe" --type=gpu-process --no-sandbox --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\debug.log" --user-agent="Mozilla/5.0 (Windows NT) Version/3.6.1.532 GamesManager/3.6.1.532 20000009 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --disable-direct-composition --use-gl=swiftshader-webgl --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,22,23,24,27,49,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --disable-accelerated-video-decode --gpu-vendor-id=0x1234 --gpu-device-id=0x1111 --gpu-driver-vendor="Google Inc." --gpu-driver-version=3.3.0.2 --gpu-driver-date=2017/04/07 --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\debug.log" --user-agent="Mozilla/5.0 (Windows NT) Version/3.6.1.532 GamesManager/3.6.1.532 20000009 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --service-request-channel-token=6EC5BE119F12D13D054DF1197A2A7836 --mojo-platform-channel-handle=2820 /prefetch:2 | C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe | GamesManager.exe | ||||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: Download Games Manager Exit code: 3221226356 Version: 3.6.1.532 Modules
| |||||||||||||||
| 2036 | "C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe" --type=renderer --no-sandbox --service-pipe-token=E6E55EFD01DD09C39285A601B5419BAB --lang=en-US --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\debug.log" --user-agent="Mozilla/5.0 (Windows NT) Version/3.6.1.532 GamesManager/3.6.1.532 20000009 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=E6E55EFD01DD09C39285A601B5419BAB --renderer-client-id=2 --mojo-platform-channel-handle=1548 /prefetch:1 | C:\Users\admin\AppData\Local\GamesManager_iWin_MSN\GamesManager.exe | — | GamesManager.exe | |||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: Download Games Manager Exit code: 0 Version: 3.6.1.532 Modules
| |||||||||||||||
| 2484 | "C:\Users\admin\AppData\Local\Programs\MSN-Games-Notifier\MSN Games Notifier.exe" --type=renderer --no-sandbox --primordial-pipe-token=B4F960977E415B28067C1C235554631E --lang=en-US --node-integration=true --preload="C:\Users\admin\AppData\Local\Programs\MSN-Games-Notifier\resources\app.asar\app\external.js" --hidden-page --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --service-request-channel-token=B4F960977E415B28067C1C235554631E --renderer-client-id=3 --mojo-platform-channel-handle=1316 /prefetch:1 | C:\Users\admin\AppData\Local\Programs\MSN-Games-Notifier\MSN Games Notifier.exe | — | MSN Games Notifier.exe | |||||||||||
User: admin Company: iWin Inc. Integrity Level: HIGH Description: MSN Games Notifier Exit code: 0 Version: 1.0.81.81 Modules
| |||||||||||||||
| 2860 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\sallys-salon---beauty-secrets-platinum-editionSetup[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | iexplore.exe | ||||||||||||
User: admin Company: iWin inc. Integrity Level: HIGH Description: MsnStreaming Games Downloader Exit code: 0 Version: 1.0.6.0 Modules
| |||||||||||||||
| 2960 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3056 | C:\Windows\system32\reg.exe QUERY HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "MSN Games Notifier" | C:\Windows\system32\reg.exe | — | MSN Games Notifier.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3104 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2960 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {F1CBC05D-1810-11E9-91D7-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 3 | |||
| (PID) Process: | (2960) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E307010001000E000F001B003000BB00 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2960 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab6FC2.tmp | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar6FC3.tmp | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab6FD3.tmp | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar6FD4.tmp | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab70A1.tmp | — | |
MD5:— | SHA256:— | |||
| 3104 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar70A2.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF89283E366A15E026.TMP | — | |
MD5:— | SHA256:— | |||
| 2960 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF229A46085B8EE16F.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2860 | sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | GET | — | 52.222.150.36:80 | http://p.iwin.com/gm/live/UgmMsnInstaller.exe | US | — | — | shared |
3104 | iexplore.exe | GET | 200 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 55.2 Kb | whitelisted |
3104 | iexplore.exe | GET | 200 | 52.222.146.242:80 | http://x.ss2.us/x.cer | US | der | 1.27 Kb | whitelisted |
2960 | iexplore.exe | GET | 200 | 13.107.21.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2960 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3104 | iexplore.exe | 52.222.150.154:443 | stamp.iwin.com | Amazon.com, Inc. | US | unknown |
3104 | iexplore.exe | 2.16.186.81:80 | www.download.windowsupdate.com | Akamai International B.V. | — | whitelisted |
3104 | iexplore.exe | 52.222.146.242:80 | x.ss2.us | Amazon.com, Inc. | US | unknown |
2860 | sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | 52.222.150.36:80 | p.iwin.com | Amazon.com, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
stamp.iwin.com |
| malicious |
x.ss2.us |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
p.iwin.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
2860 | sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
2860 | sallys-salon---beauty-secrets-platinum-editionSetup[1].exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3936 | GamesManagerInstaller.exe | A Network Trojan was detected | ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers |
3748 | GamesManagerInstaller.exe | A Network Trojan was detected | ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers |
3936 | GamesManagerInstaller.exe | A Network Trojan was detected | ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers |
Process | Message |
|---|---|
GamesManager.exe | [0114/152857.615:INFO:CONSOLE(0)] "Creating Application Cache with manifest https://ugm3-msn.iwin.com/ugm.appcache", source: https://ugm3-msn.iwin.com/ (0)
|
GamesManager.exe | [0114/152857.616:INFO:CONSOLE(0)] "Application Cache Checking event", source: https://ugm3-msn.iwin.com/ (0)
|
GamesManager.exe | [0114/152857.723:INFO:CONSOLE(0)] "Application Cache Downloading event", source: https://ugm3-msn.iwin.com/ (0)
|
GamesManager.exe | [0114/152858.817:INFO:CONSOLE(5)] "onChecking: called", source: https://ugm3-msn.iwin.com/ (5)
|
GamesManager.exe | [0114/152858.817:INFO:CONSOLE(5)] "onDownloading: called", source: https://ugm3-msn.iwin.com/ (5)
|
GamesManager.exe | [0114/152858.817:INFO:CONSOLE(0)] "Application Cache Progress event (0 of 14) https://play.iwincdn.com/assets/ugm3-msn_iwin_com/loading-d6ce6f5dc2ca1d571cdc066c5db34c78f0e40ff9245add4f47be293088585efd.js", source: https://ugm3-msn.iwin.com/ (0)
|
GamesManager.exe | [0114/152927.831:INFO:CONSOLE(8)] "Timing out app cache attempts, moving user to next page", source: https://ugm3-msn.iwin.com/ (8)
|
GamesManager.exe | [0114/152928.272:INFO:CONSOLE(8)] "online at startup detected will push to online mode", source: https://ugm3-msn.iwin.com/ (8)
|
GamesManager.exe | [0114/152928.316:INFO:CONSOLE(8)] "going to /home", source: https://ugm3-msn.iwin.com/ (8)
|
GamesManager.exe | [0114/152928.316:INFO:CONSOLE(0)] "Application Cache Progress event (1 of 14) https://ugm3-msn.iwin.com/", source: https://ugm3-msn.iwin.com/ (0)
|