File name:

huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe

Full analysis: https://app.any.run/tasks/d484b74e-8410-472f-99a5-32bd908281d2
Verdict: Malicious activity
Analysis date: November 09, 2024, 17:53:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
arch-exec
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

84CA7D78C290BB2A8A7EDBA4BC45E6DC

SHA1:

6B79F22A4AFEA283FEA509D65BD9D57D7536A4B1

SHA256:

DA47F863395E977AF7AC1C927AEB21E48B7E4D3CA505E663C228430266625959

SSDEEP:

49152:jdixrq3BdwrRFNyzV/1g4L9iW8ImsCRoPOUjSdGnJHvJKSJajQ1PsQTzesle5YBw:grq3BdwNex/1XiFds+oP3jSYnJxKLujr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 4792)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 764)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • installer.exe (PID: 6280)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6260)
      • devsetup64.exe (PID: 6492)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 6212)
      • drvinst.exe (PID: 6716)
      • drvinst.exe (PID: 1588)
      • drvinst.exe (PID: 6460)
      • drvinst.exe (PID: 6320)
      • drvinst.exe (PID: 6704)
      • drvinst.exe (PID: 7152)
    • Reads security settings of Internet Explorer

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 6564)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • saBSI.exe (PID: 5372)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • installer.exe (PID: 6260)
    • Reads the Windows owner or organization settings

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
    • The process creates files with name similar to system file names

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • installer.exe (PID: 6260)
    • Checks Windows Trust Settings

      • saBSI.exe (PID: 5372)
      • drvinst.exe (PID: 3020)
      • installer.exe (PID: 6260)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 6212)
    • The process verifies whether the antivirus software is installed

      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6280)
      • installer.exe (PID: 6260)
    • Adds/modifies Windows certificates

      • saBSI.exe (PID: 5372)
    • The process drops C-runtime libraries

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
    • Executes application which crashes

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
    • Process drops legitimate windows executable

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • installer.exe (PID: 6260)
      • devsetup64.exe (PID: 6492)
      • drvinst.exe (PID: 1588)
      • drvinst.exe (PID: 6460)
    • Drops a system driver (possible attempt to evade defenses)

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • devsetup64.exe (PID: 6492)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 6212)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 6704)
      • drvinst.exe (PID: 6320)
      • drvinst.exe (PID: 6716)
      • drvinst.exe (PID: 7152)
    • Creates/Modifies COM task schedule object

      • installer.exe (PID: 6260)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 1588)
      • drvinst.exe (PID: 6212)
    • Creates a software uninstall entry

      • installer.exe (PID: 6260)
    • Starts CMD.EXE for commands execution

      • updater.exe (PID: 7664)
      • servicehost.exe (PID: 1028)
    • Executes as Windows Service

      • servicehost.exe (PID: 1028)
      • HuaweiHiSuiteService64.exe (PID: 7952)
    • Hides command output

      • cmd.exe (PID: 7712)
  • INFO

    • Checks supported languages

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 4792)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 6564)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 764)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6280)
      • installer.exe (PID: 6260)
      • DriverSetup.exe (PID: 6496)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • devsetup64.exe (PID: 6492)
      • drvinst.exe (PID: 6212)
      • drvinst.exe (PID: 1588)
    • Create files in a temporary directory

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 4792)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 764)
      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6260)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • devsetup64.exe (PID: 6492)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
    • Reads the computer name

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 6564)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe (PID: 764)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • saBSI.exe (PID: 5372)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • installer.exe (PID: 6260)
      • devsetup64.exe (PID: 6492)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 6212)
    • Process checks computer location settings

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 6564)
      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
    • Reads the software policy settings

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6260)
      • WerFault.exe (PID: 7108)
      • WerFault.exe (PID: 4812)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • drvinst.exe (PID: 6212)
      • drvinst.exe (PID: 1588)
    • Reads the machine GUID from the registry

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • saBSI.exe (PID: 5372)
      • drvinst.exe (PID: 3020)
      • drvinst.exe (PID: 1568)
      • installer.exe (PID: 6260)
      • drvinst.exe (PID: 6212)
      • drvinst.exe (PID: 1588)
    • Checks proxy server information

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • saBSI.exe (PID: 5372)
      • WerFault.exe (PID: 7108)
      • WerFault.exe (PID: 4812)
    • The process uses the downloaded file

      • huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp (PID: 5580)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
    • Creates files in the program directory

      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6280)
      • installer.exe (PID: 6260)
      • DriverSetup.exe (PID: 6496)
      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • devsetup64.exe (PID: 6492)
    • Sends debugging messages

      • saBSI.exe (PID: 5372)
      • installer.exe (PID: 6260)
    • Creates files or folders in the user directory

      • huawei-hisuite-14.0.0.320-installer.exe (PID: 6028)
      • WerFault.exe (PID: 4812)
      • WerFault.exe (PID: 7108)
    • Reads CPU info

      • devsetup64.exe (PID: 6492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.40.1.8969
ProductVersionNumber: 2.40.1.8969
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 2.40.1.8969
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 3.1.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
186
Monitored processes
44
Malicious processes
14
Suspicious processes
3

Behavior graph

Click at the process to see the details
start huawei-hisuite-14.0.0.320-installer_j-pjlf3.exe huawei-hisuite-14.0.0.320-installer_j-pjlf3.tmp no specs huawei-hisuite-14.0.0.320-installer_j-pjlf3.exe huawei-hisuite-14.0.0.320-installer_j-pjlf3.tmp sabsi.exe huawei-hisuite-14.0.0.320-installer.exe installer.exe werfault.exe installer.exe werfault.exe sppextcomobj.exe no specs slui.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs driversetup.exe no specs devsetup64.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe no specs servicehost.exe uihost.exe no specs updater.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs slui.exe ricontool.exe no specs hsservice.exe no specs huaweihisuiteservice64.exe huaweihisuiteservice64.exe no specs hisuite.exe

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Users\admin\AppData\Local\Temp\huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe" /SPAWNWND=$7020C /NOTIFYWND=$5028A C:\Users\admin\AppData\Local\Temp\huawei-hisuite-14.0.0.320-installer_j-PJlf3.exe
huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softonic International SA
Exit code:
3221226525
Version:
2.40.1.8969
Modules
Images
c:\users\admin\appdata\local\temp\huawei-hisuite-14.0.0.320-installer_j-pjlf3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1028"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe"C:\Program Files\McAfee\WebAdvisor\servicehost.exe
services.exe
User:
SYSTEM
Company:
McAfee, LLC
Integrity Level:
SYSTEM
Description:
McAfee WebAdvisor(service)
Version:
4,1,1,975
Modules
Images
c:\program files\mcafee\webadvisor\servicehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1168C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1280\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1332\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1452"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1568DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{b5e9e100-eaba-c64f-a098-0872046e422b}\hw_quser.inf" "9" "4e7d516cb" "00000000000000F0" "WinSta0\Default" "00000000000001E0" "208" "C:\Program Files (x86)\HiSuite\driver\all\Driver\X64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1588DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{e8c4f6b3-b37d-7547-b8d1-93b19b81af17}\hw_goadb.inf" "9" "4237dd3af" "00000000000001F8" "WinSta0\Default" "0000000000000208" "208" "C:\Program Files (x86)\HiSuite\driver\all\Driver\X64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1884"C:\Program Files (x86)\HiSuite\HandSetService\HSService.exe" -installC:\Program Files (x86)\HiSuite\HandSetService\HSService.exehuawei-hisuite-14.0.0.320-installer.exe
User:
admin
Integrity Level:
HIGH
Description:
RunDCSer 应用程序
Exit code:
0
Version:
22.0.0.3
Modules
Images
c:\program files (x86)\hisuite\handsetservice\hsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2660DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{a9291101-0322-3449-8145-1bced2767760}\mtp.inf" "9" "459032b5b" "0000000000000190" "WinSta0\Default" "0000000000000214" "208" "C:\Program Files (x86)\HiSuite\driver\all\Driver\X64"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
66 612
Read events
66 340
Write events
249
Delete events
23

Modification events

(PID) Process:(5580) huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E8070B0006000900110036002E000302010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(5580) huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000006DE8CA76D032DB01
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:UUID
Value:
{9FCF0A72-EA14-488C-8EFC-EF3DEA9FFEF5}
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallerFlags
Value:
1
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationStatus
Value:
PENDING
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationID
Value:
UNDEFINED
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:CountryCode
Value:
DE
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:NEW_USER_STATE
Value:
EXPIRED
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ABTEST
Value:
SYSTEM,STR,TRUE
(PID) Process:(5372) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ANY_FLOW
Value:
SYSTEM,STR,TRUE
Executable files
254
Suspicious files
395
Text files
2 468
Unknown types
16

Dropped files

PID
Process
Filename
Type
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\is-AKIKV.tmp
MD5:
SHA256:
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\huawei-hisuite-14.0.0.320-installer.exe
MD5:
SHA256:
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\Downloads\huawei-hisuite-14.0.0.320-installer.exe
MD5:
SHA256:
764huawei-hisuite-14.0.0.320-installer_j-PJlf3.exeC:\Users\admin\AppData\Local\Temp\is-SRTN1.tmp\huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpexecutable
MD5:0D9EFB045E9F1C7C5C088AD867FDEC44
SHA256:C9EFAF64F5069FA4BBBAE69169249EBF3E169A3A37D83A4D408D7314C423EB62
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4792huawei-hisuite-14.0.0.320-installer_j-PJlf3.exeC:\Users\admin\AppData\Local\Temp\is-A7U6N.tmp\huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpexecutable
MD5:0D9EFB045E9F1C7C5C088AD867FDEC44
SHA256:C9EFAF64F5069FA4BBBAE69169249EBF3E169A3A37D83A4D408D7314C423EB62
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\Y.pngimage
MD5:C199687E52F7393C941A143B45D78207
SHA256:0EB767424750B6F8C22AE5EBB105C5C37B3A047EED986FFA6DEBA53EFDC2142E
5372saBSI.exeC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\component0_extract\installer.exeexecutable
MD5:629D2550573F81D70A5278B70BFF3BA9
SHA256:A7EAFB85209B9E7AD2C3B867CC93D9E9E77B02DD7ADFA795A87E9C4A5DE83019
6028huawei-hisuite-14.0.0.320-installer.exeC:\Users\admin\AppData\Local\Temp\nsm7CB8.tmp\api_ms_win_core_console_l1_1_0.dllexecutable
MD5:316B785B14A36AE34FBE8DFBE0C43944
SHA256:622D879D3F03CF36FAEBFF42195674F540C30C36AD496C3B77F6C89C651D4448
5580huawei-hisuite-14.0.0.320-installer_j-PJlf3.tmpC:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\N.pngimage
MD5:1A01027365500D86730A737EB32CBF2A
SHA256:D79A97538B93179012A5EBEBDE873EDC18E30A0287953800F7AA7EA4F25724E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
64
DNS requests
38
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5324
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6100
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5324
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4812
WerFault.exe
GET
200
23.48.23.167:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4812
WerFault.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
23.218.209.163:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4700
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
184.86.251.15:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4700
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
  • 23.48.23.167
  • 23.48.23.145
  • 23.48.23.164
  • 23.48.23.177
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 23.218.209.163
  • 88.221.125.143
  • 23.52.120.96
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.133
  • 40.126.32.140
  • 40.126.32.76
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.134
whitelisted
www.bing.com
  • 184.86.251.15
  • 184.86.251.31
  • 184.86.251.9
  • 184.86.251.30
  • 184.86.251.16
  • 184.86.251.14
  • 184.86.251.29
  • 184.86.251.8
  • 184.86.251.7
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
th.bing.com
  • 2.19.96.59
  • 2.19.96.80
  • 2.19.96.8
  • 2.19.96.43
  • 2.19.96.115
  • 2.19.96.50
  • 2.19.96.89
  • 2.19.96.64
  • 2.19.96.49
whitelisted
go.microsoft.com
  • 2.19.86.20
whitelisted
d69gcyt8k9bu2.cloudfront.net
  • 18.239.38.143
  • 18.239.38.119
  • 18.239.38.96
  • 18.239.38.21
whitelisted

Threats

No threats detected
Process
Message
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-AKVI1.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003