| File name: | CocCocSetup.exe |
| Full analysis: | https://app.any.run/tasks/8934cb6b-8bd1-46c5-9890-c1a4d021f564 |
| Verdict: | Malicious activity |
| Analysis date: | March 03, 2024, 23:43:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D5AB873FF69DE7079642378D0A1F8E88 |
| SHA1: | 50B6011902A50194DBA7418C723312A1D0D1D711 |
| SHA256: | D5791EEF0ABD4D7699CA6128C5475A64B206EEF2B946F47DED2F0EFFC691D182 |
| SSDEEP: | 49152:omRWWWryA56l2F6xb4xJexZAA+by0yFZD2I4HE6NZSr2mPIExmlSqrik6f89RNi:FMlrl8l2F6x7ZZQyFZD2IDPd9HJk6f8k |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:05:18 07:03:31+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 94720 |
| InitializedDataSize: | 857600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x56a6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.7.1.19 |
| ProductVersionNumber: | 2.7.1.19 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Coc Coc Co., Ltd. |
| FileDescription: | CocCoc Update Setup |
| FileVersion: | 2.7.1.19 |
| InternalName: | CocCoc Update Setup |
| LegalCopyright: | Copyright 2018 Google LLC |
| OriginalFileName: | CocCocUpdateSetup.exe |
| ProductName: | CocCoc Update |
| ProductVersion: | 2.7.1.19 |
| LanguageId: | en |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1836 | "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /handoff "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=en&client={XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}&brand=XXXX" /installsource taggedmi /sessionid "{211260B7-B550-4DFB-9F30-265314E81F24}" | C:\Program Files\CocCoc\Update\CocCocUpdate.exe | CocCocUpdate.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 2304 | "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /regsvc | C:\Program Files\CocCoc\Update\CocCocUpdate.exe | CocCocUpdate.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 2692 | "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /svc | C:\Program Files\CocCoc\Update\CocCocUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Coc Coc Co., Ltd. Integrity Level: SYSTEM Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3428 | "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /regserver | C:\Program Files\CocCoc\Update\CocCocUpdate.exe | CocCocUpdate.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3464 | "C:\Program Files\CocCoc\Temp\GUMFD6B.tmp\CocCocUpdate.exe" /installsource taggedmi /install "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=en&client={XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}&brand=XXXX" /installelevated | C:\Program Files\CocCoc\Temp\GUMFD6B.tmp\CocCocUpdate.exe | CocCocUpdateSetup.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3500 | "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjIuNy4xLjE5IiBzaGVsbF92ZXJzaW9uPSIyLjcuMS4xOSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsyMTEyNjBCNy1CNTUwLTRERkItOUYzMC0yNjUzMTRFODFGMjR9IiB1c2VyaWQ9IkRBRDJFMjlGLUE0MzYtNDIxQi1BRkE3LUY3N0Q5MDhGNThBRiIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0ie0M2NjFFMDI3LTQ0ODEtNDA3QS04OUNBLTQyQjFGOENDNDFGMH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjIuNy4xLjE5IiBsYW5nPSJlbiIgYnJhbmQ9IlhYWFgiIGNsaWVudD0ie1hYWFhYWFhYLVhYWFgtWFhYWC1YWFhYLVhYWFhYWFhYWFhYWH0iPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTAzMSIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Program Files\CocCoc\Update\CocCocUpdate.exe | CocCocUpdate.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3656 | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdate.exe /installsource taggedmi /install "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=en&client={XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}&brand=XXXX" | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdate.exe | CocCocSetup.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: MEDIUM Description: CocCoc Update Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\CocCocSetup.exe" | C:\Users\admin\AppData\Local\Temp\CocCocSetup.exe | explorer.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: MEDIUM Description: CocCoc Update Setup Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| 3948 | "C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateSetup.exe" /installsource taggedmi /install "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=en&client={XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}&brand=XXXX" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateSetup.exe | CocCocUpdate.exe | ||||||||||||
User: admin Company: Coc Coc Co., Ltd. Integrity Level: HIGH Description: CocCoc Update Setup Exit code: 0 Version: 2.7.1.19 Modules
| |||||||||||||||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | usagestats |
Value: 1 | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update\ClientState\{C0CC0CBB-47DD-46FF-A04D-7011A06486E1} |
| Operation: | write | Name: | usagestats |
Value: 1 | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update |
| Operation: | delete value | Name: | eulaaccepted |
Value: | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files\CocCoc\Update\CocCocUpdate.exe | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files\CocCoc\Update\CocCocUpdate.exe" /uninstall | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 2.7.1.19 | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | name |
Value: Cốc Cốc Update | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CocCoc\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 2.7.1.19 | |||
| (PID) Process: | (3464) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CocCocUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (2304) CocCocUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\CocCocUpdate.exe |
| Operation: | write | Name: | AppID |
Value: {4F0B9D69-B942-4483-8AF9-5FB23CE35CA0} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdate.exe | executable | |
MD5:4D8EFE5A192709B079D40B8934D69589 | SHA256:8A0638F6CF0EA15A57F1EBCC596214393DE5D3074C1E6CB3D3D5EF631B14D803 | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateOnDemand.exe | executable | |
MD5:F23EE51635368E62CC7EC14FE017DEF9 | SHA256:A59D55C412329BDFF3C72BED8A4CAD1F58069B67733AE6449FCFFC8D305F7B2A | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateComRegisterShell64.exe | executable | |
MD5:2784770CFE7B48C069D40AE2126544A9 | SHA256:86D5070EA80102907E3892893E352C870A2DB7872C7EFAD94AA10A7FCD1C2A0D | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\psuser_64.dll | executable | |
MD5:6AA714AE21EADA6E61DF0BB87ED507D0 | SHA256:23BDC4552EE0E9049E486EEF0C1E320B4746065A2702EB484253B1F6541C3C39 | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateCore.exe | executable | |
MD5:44B2CA9478F534BF2BFA5671FEAE6384 | SHA256:37F9E42FD693031E3DA1CE6F8828B849D4F8D1C9A608157F92EB63CDA0726BD0 | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\coccocpdateres_en.dll | executable | |
MD5:FDEE1CEEBA1A489DF82AFF39FEA71AC8 | SHA256:681F10ADA6CC7D7E7E15D5254008B761F3717BC722CDAFDAED6A0FF2598889A5 | |||
| 3700 | CocCocSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFA7D.tmp\CocCocUpdateSetup.exe | executable | |
MD5:D5AB873FF69DE7079642378D0A1F8E88 | SHA256:D5791EEF0ABD4D7699CA6128C5475A64B206EEF2B946F47DED2F0EFFC691D182 | |||
| 3656 | CocCocUpdate.exe | C:\ProgramData\CocCoc\uid | text | |
MD5:2212DB4106CF08D6B8CB90EEAE7C3970 | SHA256:0C99459160A970DB1CE308AAA47108F11435DACA9A520F8813C7DC9059590FFD | |||
| 3656 | CocCocUpdate.exe | C:\Users\admin\AppData\Roaming\CocCoc\uid | text | |
MD5:EB6F987AB6286B600130E1FA812CBB70 | SHA256:800A597952D5114A29D4E6A972F207BD7D6561A04CDC018B2EE8D850B0D9D59A | |||
| 3948 | CocCocUpdateSetup.exe | C:\Program Files\CocCoc\Temp\GUMFD6B.tmp\CocCocCrashHandler.exe | executable | |
MD5:05491DFAE4AA9A902FC3599EF5E68CC7 | SHA256:9EA57FD4294F01D9A1500C6902CFB8A5499B852DF2B20B1B33708957D86790BC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3500 | CocCocUpdate.exe | POST | 200 | 123.30.175.98:80 | http://browser.coccoc.com/service/update2 | unknown | xml | 235 b | unknown |
2692 | CocCocUpdate.exe | POST | 200 | 123.30.175.98:80 | http://browser.coccoc.com/service/update2?cup2key=5:1494026822&cup2hreq=bb2279160e33d23f217283394d77d51383ed3cbc8f210bb3d08299e0e5fc751b | unknown | xml | 878 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3500 | CocCocUpdate.exe | 123.30.175.98:80 | browser.coccoc.com | VNPT Corp | VN | unknown |
2692 | CocCocUpdate.exe | 123.30.175.98:80 | browser.coccoc.com | VNPT Corp | VN | unknown |
1348 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
856 | svchost.exe | 123.30.175.11:443 | files.coccoc.com | VNPT Corp | VN | unknown |
856 | svchost.exe | 123.30.177.125:443 | files-cdn.coccoc.com | VNPT Corp | VN | unknown |
Domain | IP | Reputation |
|---|---|---|
browser.coccoc.com |
| unknown |
files.coccoc.com |
| unknown |
files-cdn.coccoc.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3500 | CocCocUpdate.exe | Not Suspicious Traffic | ET POLICY COCCOC Browser (VN) Installed |
2692 | CocCocUpdate.exe | Not Suspicious Traffic | ET POLICY COCCOC Browser (VN) Installed |