File name: | mt4setup.exe |
Full analysis: | https://app.any.run/tasks/56717594-add1-4653-8d4e-004a6627389f |
Verdict: | Malicious activity |
Analysis date: | December 06, 2018, 03:36:42 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | 7B8932B4736E937CD8D54FDCB53951CF |
SHA1: | 274C6DDEBD32264DAAF04557C777B863343D0E23 |
SHA256: | D9D6914DE366AFF54F569D4F66A89E9880CBCA636FB6BD556AE5260E4D87A2AA |
SSDEEP: | 24576:hGSLzjDbuQzky9B310b6a9/ZhbyPQkbEpjwTda6KPUdYlCrF8JN:hFLjyQzkyN0bZFZhuPipjwhaEY8h6N |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
ProductVersion: | 5.0.0.1882 |
---|---|
ProductName: | Setup |
OriginalFileName: | Setup |
LegalTrademarks: | MetaTrader |
LegalCopyright: | © 2000-2018, MetaQuotes Software Corp. |
InternalName: | Setup |
FileVersion: | 5.0.0.1882 |
FileDescription: | Setup |
CompanyName: | MetaQuotes Software Corp. |
Comments: | https://www.metaquotes.net |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.0.0.1882 |
FileVersionNumber: | 5.0.0.1882 |
Subsystem: | Windows GUI |
SubsystemVersion: | 5.1 |
ImageVersion: | - |
OSVersion: | 5.1 |
EntryPoint: | 0x30e980 |
UninitializedDataSize: | 2215936 |
InitializedDataSize: | 159744 |
CodeSize: | 987136 |
LinkerVersion: | 14.14 |
PEType: | PE32 |
TimeStamp: | 1970:01:14 07:43:12+01:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3492 | "C:\Users\admin\AppData\Local\Temp\mt4setup.exe" | C:\Users\admin\AppData\Local\Temp\mt4setup.exe | — | explorer.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 5.0.0.1882 | ||||
2124 | "C:\Users\admin\AppData\Local\Temp\mt4setup.exe" | C:\Users\admin\AppData\Local\Temp\mt4setup.exe | mt4setup.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: Setup Exit code: 1 Version: 5.0.0.1882 | ||||
3100 | "C:\Program Files\MetaTrader\terminal.exe" /install | C:\Program Files\MetaTrader\terminal.exe | mt4setup.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: MetaTrader 5 Client Terminal Exit code: 0 Version: 5.0.0.1940 | ||||
3468 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | mt4setup.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
2540 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3468 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3868 | "C:\Windows\explorer.exe" "C:\Program Files\MetaTrader\terminal.exe" | C:\Windows\explorer.exe | — | mt4setup.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3404 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3784 | "C:\Program Files\MetaTrader\terminal.exe" | C:\Program Files\MetaTrader\terminal.exe | explorer.exe | |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader 5 Client Terminal Version: 5.0.0.1940 | ||||
3608 | "C:\Program Files\MetaTrader\metaeditor.exe" /compile:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /time:0 /flg:0 /stop:se3560_1313921 | C:\Program Files\MetaTrader\metaeditor.exe | — | terminal.exe |
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Version: 5.0.0.1940 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\CabAE73.tmp | — | |
MD5:— | SHA256:— | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\TarAE74.tmp | — | |
MD5:— | SHA256:— | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\CabAF31.tmp | — | |
MD5:— | SHA256:— | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\TarAF32.tmp | — | |
MD5:— | SHA256:— | |||
2124 | mt4setup.exe | C:\Program Files\MetaTrader\metaeditor.exe | — | |
MD5:— | SHA256:— | |||
2124 | mt4setup.exe | C:\Program Files\MetaTrader\Bases\Default\History\USDJPY\2018.hcc | binary | |
MD5:97EBCF46EA7BB7760C5E8F455C77BF12 | SHA256:CC361DA9E6479DE6FB9FB7BD94B7A2B44E8AA1462437E5F2185ED6301C8A29BB | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 | binary | |
MD5:FC89F0E1C493C102544FF24302EDD473 | SHA256:42A6E0136914E9993F62EE9B3C134B567AFB3A58F67E521D2F1BD23658E9C140 | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt5clw.png | compressed | |
MD5:88B91937D29A0BC666A694784E12C448 | SHA256:73C95A3D2DA09B3F6B49C8858C1815D69877D1662551EC34BE2DA8AD7EF75A4C | |||
2124 | mt4setup.exe | C:\Program Files\MetaTrader\Bases\Default\History\GBPUSD\2018.hcc | binary | |
MD5:0F3100FDAC01537F86A7EA1C7AA0E188 | SHA256:1CA08AD74CC9A20FCCB966BE6D002C50EE45DCFD55C2E2614159B208899E7021 | |||
2124 | mt4setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 | compressed | |
MD5:A902CF373E02F7DC34F456ED7449279C | SHA256:EA0C12AEDEA644678014991A96534145E85AA12CD8955396DFDC98A4FC96F0D5 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2124 | mt4setup.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2124 | mt4setup.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
3468 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2124 | mt4setup.exe | 47.74.14.49:443 | — | Alibaba (China) Technology Co., Ltd. | JP | unknown |
2124 | mt4setup.exe | 47.95.9.170:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2124 | mt4setup.exe | 88.212.244.84:443 | — | Servers.com, Inc. | RU | unknown |
2124 | mt4setup.exe | 104.41.54.220:443 | — | Microsoft Corporation | BR | whitelisted |
2124 | mt4setup.exe | 119.235.249.82:443 | — | PT. Raja Sepadan Abadi | ID | unknown |
2124 | mt4setup.exe | 47.52.161.165:443 | — | Alibaba (China) Technology Co., Ltd. | HK | unknown |
2124 | mt4setup.exe | 47.100.195.238:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2124 | mt4setup.exe | 78.140.180.86:443 | content.mql5.com | Webzilla B.V. | NL | suspicious |
2124 | mt4setup.exe | 138.201.201.91:443 | c.mql5.com | Hetzner Online GmbH | DE | unknown |
2124 | mt4setup.exe | 120.79.203.118:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
Domain | IP | Reputation |
---|---|---|
content.mql5.com |
| suspicious |
www.download.windowsupdate.com |
| whitelisted |
www.mql5.com |
| suspicious |
www.bing.com |
| whitelisted |
c.mql5.com |
| suspicious |
connect.facebook.net |
| whitelisted |
msg1.mql5.com |
| unknown |
api1.mql5.com |
| suspicious |
msg2.mql5.com |
| unknown |
access.metatrader5.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
3784 | terminal.exe | unknown | SURICATA TCPv4 invalid checksum |