| File name: | mt4setup.exe |
| Full analysis: | https://app.any.run/tasks/56717594-add1-4653-8d4e-004a6627389f |
| Verdict: | Malicious activity |
| Analysis date: | December 06, 2018, 03:36:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 7B8932B4736E937CD8D54FDCB53951CF |
| SHA1: | 274C6DDEBD32264DAAF04557C777B863343D0E23 |
| SHA256: | D9D6914DE366AFF54F569D4F66A89E9880CBCA636FB6BD556AE5260E4D87A2AA |
| SSDEEP: | 24576:hGSLzjDbuQzky9B310b6a9/ZhbyPQkbEpjwTda6KPUdYlCrF8JN:hFLjyQzkyN0bZFZhuPipjwhaEY8h6N |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1970:01:14 07:43:12+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.14 |
| CodeSize: | 987136 |
| InitializedDataSize: | 159744 |
| UninitializedDataSize: | 2215936 |
| EntryPoint: | 0x30e980 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.0.1882 |
| ProductVersionNumber: | 5.0.0.1882 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | https://www.metaquotes.net |
| CompanyName: | MetaQuotes Software Corp. |
| FileDescription: | Setup |
| FileVersion: | 5.0.0.1882 |
| InternalName: | Setup |
| LegalCopyright: | © 2000-2018, MetaQuotes Software Corp. |
| LegalTrademarks: | MetaTrader |
| OriginalFileName: | Setup |
| ProductName: | Setup |
| ProductVersion: | 5.0.0.1882 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2124 | "C:\Users\admin\AppData\Local\Temp\mt4setup.exe" | C:\Users\admin\AppData\Local\Temp\mt4setup.exe | mt4setup.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: Setup Exit code: 1 Version: 5.0.0.1882 Modules
| |||||||||||||||
| 2540 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3468 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3100 | "C:\Program Files\MetaTrader\terminal.exe" /install | C:\Program Files\MetaTrader\terminal.exe | mt4setup.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: HIGH Description: MetaTrader 5 Client Terminal Exit code: 0 Version: 5.0.0.1940 Modules
| |||||||||||||||
| 3404 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3468 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | mt4setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3492 | "C:\Users\admin\AppData\Local\Temp\mt4setup.exe" | C:\Users\admin\AppData\Local\Temp\mt4setup.exe | — | explorer.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 5.0.0.1882 Modules
| |||||||||||||||
| 3608 | "C:\Program Files\MetaTrader\metaeditor.exe" /compile:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /time:0 /flg:0 /stop:se3560_1313921 | C:\Program Files\MetaTrader\metaeditor.exe | — | terminal.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaEditor Exit code: 0 Version: 5.0.0.1940 Modules
| |||||||||||||||
| 3784 | "C:\Program Files\MetaTrader\terminal.exe" | C:\Program Files\MetaTrader\terminal.exe | explorer.exe | ||||||||||||
User: admin Company: MetaQuotes Software Corp. Integrity Level: MEDIUM Description: MetaTrader 5 Client Terminal Exit code: 0 Version: 5.0.0.1940 Modules
| |||||||||||||||
| 3868 | "C:\Windows\explorer.exe" "C:\Program Files\MetaTrader\terminal.exe" | C:\Windows\explorer.exe | — | mt4setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3492) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: 166A8DBE-D313-T-181206 | |||
| (PID) Process: | (3492) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | Install.Time |
Value: 1544067419 | |||
| (PID) Process: | (3492) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: 9FB01C5F-175C-F-180725 | |||
| (PID) Process: | (3492) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3492) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2124) mt4setup.exe | Key: | HKEY_CURRENT_USER\Software\MetaQuotes Software |
| Operation: | write | Name: | ID |
Value: 9FB01C5F-175C-F-180725 | |||
| (PID) Process: | (2124) mt4setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2124) mt4setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Operation: | write | Name: | Blob |
Value: 0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D4620000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8 | |||
| (PID) Process: | (2124) mt4setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510 | |||
| (PID) Process: | (2124) mt4setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000410352DC0FF7501B16F0028EBA6F45C51900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF424030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131D00000001000000100000004558D512EECB27464920897DE7B66053140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589100B000000010000001E000000440053005400200052006F006F00740020004300410020005800330000006200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD6770739090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C0F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D20000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\CabAE73.tmp | — | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\TarAE74.tmp | — | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\CabAF31.tmp | — | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Local\Temp\TarAF32.tmp | — | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Program Files\MetaTrader\metaeditor.exe | — | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt5clwide.png | compressed | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt5clwdata.png | compressed | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Program Files\MetaTrader\metatester.exe | executable | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt5clw.png | compressed | |
MD5:— | SHA256:— | |||
| 2124 | mt4setup.exe | C:\Program Files\MetaTrader\Bases\Default\History\EURUSD\2018.hcc | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3468 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
2124 | mt4setup.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
2124 | mt4setup.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2124 | mt4setup.exe | 47.74.14.49:443 | — | Alibaba (China) Technology Co., Ltd. | JP | unknown |
2124 | mt4setup.exe | 47.95.9.170:443 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2124 | mt4setup.exe | 88.212.244.84:443 | — | Servers.com, Inc. | RU | unknown |
2124 | mt4setup.exe | 119.235.249.82:443 | — | PT. Raja Sepadan Abadi | ID | unknown |
2124 | mt4setup.exe | 160.119.248.158:443 | — | HETZNER | ZA | unknown |
2124 | mt4setup.exe | 139.99.161.172:443 | — | OVH SAS | AU | unknown |
2124 | mt4setup.exe | 142.0.194.252:443 | — | Servers.com, Inc. | US | unknown |
2124 | mt4setup.exe | 104.41.54.220:443 | — | Microsoft Corporation | BR | whitelisted |
2124 | mt4setup.exe | 206.221.189.58:443 | — | Choopa, LLC | US | unknown |
2124 | mt4setup.exe | 138.201.201.91:443 | c.mql5.com | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
content.mql5.com |
| suspicious |
www.download.windowsupdate.com |
| whitelisted |
www.mql5.com |
| suspicious |
www.bing.com |
| whitelisted |
c.mql5.com |
| suspicious |
connect.facebook.net |
| whitelisted |
msg1.mql5.com |
| unknown |
api1.mql5.com |
| suspicious |
msg2.mql5.com |
| unknown |
access.metatrader5.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3784 | terminal.exe | unknown | SURICATA TCPv4 invalid checksum |