| URL: | https://yepdownload.com/regshot |
| Full analysis: | https://app.any.run/tasks/72b46e18-c986-4e56-b123-eca11e8c66bd |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | January 01, 2021, 00:56:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 221C89FDF1A4AC102C06091F0B46BC5C |
| SHA1: | 20E1A6938F6D88E2CFD91009CE7FC8554ECAB3AC |
| SHA256: | D777CCD8DFA3295DF3ECFCFE4C5A7D20F8DF9E99C18075DB833A1E0BD6B48F46 |
| SSDEEP: | 3:N8/KKKU:2CKKU |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3519047299532960747 --renderer-client-id=27 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1316 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 588 | "C:\Users\admin\Downloads\AntiMalware_Setup.exe" | C:\Users\admin\Downloads\AntiMalware_Setup.exe | chrome.exe | ||||||||||||
User: admin Company: Zemana Ltd. Integrity Level: MEDIUM Description: Advanced Malware Protection Exit code: 0 Version: 3.2.27 Modules
| |||||||||||||||
| 700 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3149332025001608412 --renderer-client-id=26 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4388 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 788 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14778734108210829182 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2176 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 892 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7135286173662312111 --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3412 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2828 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1264 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=11074261314549696466 --mojo-platform-channel-handle=4268 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1388 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=2171087770998649561 --mojo-platform-channel-handle=1452 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1456 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6123581305561589153 --renderer-client-id=32 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4352 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1532 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16600822034490871395 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3604 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (968) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2820-13253936177080125 |
Value: 259 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (2820) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FEE7331-B04.pma | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6fabe89e-7bfe-403c-8d59-8d3b1c838ae8.tmp | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF1545dc.TMP | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF1544a4.TMP | text | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF1544b3.TMP | text | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF1546a7.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | regshot-1-9-0-en-win_0654906155.exe | POST | 200 | 13.224.195.32:80 | http://df2gms67ann7.cloudfront.net/ | US | — | — | malicious |
2208 | regshot-1-9-0-en-win_0654906155.exe | POST | 200 | 13.224.195.32:80 | http://df2gms67ann7.cloudfront.net/ | US | — | — | malicious |
3056 | regshot-1-9-0-en-win_0654906155.exe | POST | 200 | 13.224.195.32:80 | http://df2gms67ann7.cloudfront.net/ | US | — | — | malicious |
2208 | regshot-1-9-0-en-win_0654906155.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQC%2F8UqksxhNuVrE%2FyJIkN74 | US | der | 472 b | whitelisted |
2208 | regshot-1-9-0-en-win_0654906155.exe | POST | 200 | 143.204.101.128:80 | http://d25o8a75dj1x6r.cloudfront.net/ | US | text | 920 b | whitelisted |
2208 | regshot-1-9-0-en-win_0654906155.exe | POST | 200 | 13.224.195.32:80 | http://df2gms67ann7.cloudfront.net/ | US | — | — | malicious |
2208 | regshot-1-9-0-en-win_0654906155.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
2368 | iexplore.exe | GET | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | US | der | 1.66 Kb | whitelisted |
2368 | iexplore.exe | GET | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | US | der | 1.66 Kb | whitelisted |
2368 | iexplore.exe | GET | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCEuKAq1blmBJ | US | der | 1.74 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1388 | chrome.exe | 67.207.92.67:443 | yepdownload.com | Digital Ocean, Inc. | US | unknown |
1388 | chrome.exe | 91.199.212.52:80 | crt.sectigo.com | Comodo CA Ltd | GB | suspicious |
1388 | chrome.exe | 172.217.16.195:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
1388 | chrome.exe | 2.16.106.171:80 | www.download.windowsupdate.com | Akamai International B.V. | — | whitelisted |
1388 | chrome.exe | 172.217.23.130:443 | pagead2.googlesyndication.com | Google Inc. | US | whitelisted |
1388 | chrome.exe | 195.181.175.52:443 | cdn.sendpulse.com | Datacamp Limited | DE | suspicious |
1388 | chrome.exe | 87.250.250.119:443 | mc.yandex.ru | YANDEX LLC | RU | whitelisted |
1388 | chrome.exe | 216.58.207.40:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
1388 | chrome.exe | 172.217.18.110:443 | clients1.google.com | Google Inc. | US | whitelisted |
1388 | chrome.exe | 172.217.23.142:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
yepdownload.com |
| whitelisted |
accounts.google.com |
| shared |
crt.sectigo.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
cdn.sendpulse.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
mc.yandex.ru |
| whitelisted |
clients1.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2208 | regshot-1-9-0-en-win_0654906155.exe | A Network Trojan was detected | ADWARE [PTsecurity] InstallCore |
3056 | regshot-1-9-0-en-win_0654906155.exe | A Network Trojan was detected | ADWARE [PTsecurity] InstallCore |
Process | Message |
|---|---|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:18,835 [INFO ] [1] [Zemana.AntiMalware.UI.Program.Main] Line: 55 - ################################# SYSTEM INITIALIZED #################################
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:18,960 [INFO ] [1] [Zemana.AntiMalware.UI.Program.Main] Line: 55 - v3.2.27 is launching...
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,007 [INFO ] [1] [Zemana.AntiMalware.UI.Services.CommandHandler.CreateOrShowRunningUIInstance] Line: 245 - ================= Running command C:\Program Files\Zemana\AntiMalware\AntiMalware.exe /SL5=$30204,12312908,121344,C:\Users\admin\Downloads\AntiMalware_Setup.exe /SPAWNWND=$20206 /NOTIFYWND=$801D0 /INSTALLER /SELECTEDLANG x0409 /AUTOUPLOAD =================
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,675 [INFO ] [1] [Zemana.AntiMalware.Core.Localization.Translator.Initialize] Line: 111 - Translator has been initialized.
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,695 [INFO ] [1] [Zemana.AntiMalware.Core.Notifications.Notifier.Initialize] Line: 26 - Notifier has been initialized.
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,710 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.GetCurrentLanguageCode] Line: 1494 - The setup selected language has ben set by translator. SelectedLang: en-US
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,710 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.SetThreadCulture] Line: 694 - Thread culture has ben set to en-US
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,820 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.ApplyLocalization] Line: 706 - Translation has been applied
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:19,820 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.RebrandApplication] Line: 891 - Zemana AntiMalware is being initialized... AppId: 2
|
AntiMalware.exe | AMLogger: 2021-01-01 00:59:20,148 [INFO ] [1] [Zemana.AntiMalware.Core.Reporting.ScanReporter..ctor] Line: 34 - Creating initial scan report directory... Directory: C:\Users\admin\AppData\Local\Zemana\AntiMalware\reports
|