| File name: | fcpro_2.3.3.6635_web_installer.exe |
| Full analysis: | https://app.any.run/tasks/85af3e69-5141-41af-a886-037f0f30a6dc |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2024, 12:48:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | AD2075584B0FBF7479191D19741EB0E7 |
| SHA1: | 9D8C2F69BAEA60F5FA8DCCC0325F6EEE378338F7 |
| SHA256: | DB61F83E41631D0710FE62BC3F1A67C21CED65D74FDA549BE4BFD6E8F3469161 |
| SSDEEP: | 49152:9BEZGDA+947lScGeQNTty6l/7LjpfYln4gl3f274+ERV49f5j881fhtj8B3F/oCm:ryGrqkA+TtyY/7pY5LleaRQ18KTkFlE7 |
| .exe | | | Inno Setup installer (71.1) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (9.1) |
| .scr | | | Windows screen saver (8.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.2) |
| .exe | | | Win32 Executable (generic) (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 40448 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa5f8 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.3.3.6635 |
| ProductVersionNumber: | 2.3.3.6635 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Viavi |
| FileDescription: | |
| FileVersion: | 2.3.3.6635 |
| LegalCopyright: | |
| ProductName: | |
| ProductVersion: | 2.3.3.6635 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1776 | "C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe | fcpro_2.3.3.6635_web_installer.tmp | ||||||||||||
User: admin Company: Viavi Integrity Level: HIGH Description: Exit code: 0 Version: 2.3.3.6635 Modules
| |||||||||||||||
| 2232 | "C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe" /checkinternet | C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe | fcpro_2.3.3.6635_web_installer.tmp | ||||||||||||
User: admin Company: JDSU Integrity Level: HIGH Description: WebInstallerEngine Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2752 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" /codebase "C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\..\is-temp\InstallerUtils.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | fcpro_2.3.3.6635_web_installer.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\is-T17MB.tmp\fcpro_2.3.3.6635_web_installer.tmp" /SL5="$19013E,1271752,56832,C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-T17MB.tmp\fcpro_2.3.3.6635_web_installer.tmp | fcpro_2.3.3.6635_web_installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3180 | "C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe" download /log "C:\Program Files\Viavi\FiberChekPRO\WebInstaller.log" /dest "C:\Users\admin\AppData\Local\Temp\FiberChekPRO\WebInstaller" /urlbase "https://jdsufit.blob.core.windows.net/fiberchekpro/versions/2.3.3" /app "C:\Program Files\Viavi\FiberChekPRO" /index "C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\InstallerFileIndex.xml" /title "Downloading Required Files" /edition STD /components FiberChekPRO Automation /ownerhandle 1900978 | C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe | fcpro_2.3.3.6635_web_installer.tmp | ||||||||||||
User: admin Company: JDSU Integrity Level: HIGH Description: WebInstallerEngine Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3212 | "netsh.exe" advfirewall firewall add rule name=FCProWebInstaller dir=out program="C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe" profile=any action=allow | C:\Windows\System32\netsh.exe | — | fcpro_2.3.3.6635_web_installer.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3240 | "C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe" | C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe | explorer.exe | ||||||||||||
User: admin Company: Viavi Integrity Level: MEDIUM Description: Exit code: 0 Version: 2.3.3.6635 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\is-6730I.tmp\fcpro_2.3.3.6635_web_installer.tmp" /SL5="$E0170,1271752,56832,C:\Users\admin\AppData\Local\Temp\fcpro_2.3.3.6635_web_installer.exe" | C:\Users\admin\AppData\Local\Temp\is-6730I.tmp\fcpro_2.3.3.6635_web_installer.tmp | — | fcpro_2.3.3.6635_web_installer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2964) fcpro_2.3.3.6635_web_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 940B0000E8E032D31F67DA01 | |||
| (PID) Process: | (2964) fcpro_2.3.3.6635_web_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 52E70411E43CFE14AFE85C3CCF9E4AC04AAE321EFCA5508F342E2016A73CE6A5 | |||
| (PID) Process: | (2964) fcpro_2.3.3.6635_web_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39275528-A2A6-4382-A040-2593C0E8D2A7}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39275528-A2A6-4382-A040-2593C0E8D2A7}\InprocServer32 |
| Operation: | write | Name: | Class |
Value: JDSU.FIT.FiberChek.Installer.InstallerUtils | |||
| (PID) Process: | (2752) RegAsm.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39275528-A2A6-4382-A040-2593C0E8D2A7}\InprocServer32 |
| Operation: | write | Name: | Assembly |
Value: InstallerUtils, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | fcpro_2.3.3.6635_web_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-temp\InstallerUtils.exe | executable | |
MD5:A168DDB6468850FE27FF4FF8FA6702CA | SHA256:9367922593DED69C8D6D6F26B8F550BCF301B0E9A467209916D35ABB01787052 | |||
| 3180 | WebInstallerEngine.exe | C:\Users\admin\AppData\Local\Temp\FiberChekPRO\WebInstaller\Database\ConnectorDefinitions\MPO 16x1.fccon | xml | |
MD5:199376AD70A0F6519F07AE1744631EDE | SHA256:CAA441FE28CDCB65B4A4392D06D7D296C474472661525F439103937E67FCF7DB | |||
| 2964 | fcpro_2.3.3.6635_web_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\InstallerUtils.exe.config | xml | |
MD5:B126772B9539EB6054A301E92CE94C0E | SHA256:3E943A74C70F7C89DD1D14F1F3084BAF6B4D4F79F6FAF7F0E2906EBD0AA06ED4 | |||
| 1776 | fcpro_2.3.3.6635_web_installer.exe | C:\Users\admin\AppData\Local\Temp\is-T17MB.tmp\fcpro_2.3.3.6635_web_installer.tmp | executable | |
MD5:2C10DB017057DCE22651243244E4FEE6 | SHA256:E442E83C27E94BC37EB6C02411A88EDD8CB83777D50312B9EF7BFC214C4CC7B2 | |||
| 2964 | fcpro_2.3.3.6635_web_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\InstallerUtils.exe | executable | |
MD5:A168DDB6468850FE27FF4FF8FA6702CA | SHA256:9367922593DED69C8D6D6F26B8F550BCF301B0E9A467209916D35ABB01787052 | |||
| 2964 | fcpro_2.3.3.6635_web_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-BBJPU.tmp\WebInstallerEngine.exe.config | xml | |
MD5:B126772B9539EB6054A301E92CE94C0E | SHA256:3E943A74C70F7C89DD1D14F1F3084BAF6B4D4F79F6FAF7F0E2906EBD0AA06ED4 | |||
| 3180 | WebInstallerEngine.exe | C:\Users\admin\AppData\Local\Temp\FiberChekPRO\WebInstaller\Database\ConnectorDefinitions\MPO 12x1.fccon | xml | |
MD5:AEB32391A0F51BA7D4C78CE48F331474 | SHA256:B703B02FD23E81EF08BBC4ACFB3AADEE17D9BAF77CA6EECEE8D7BE1A60CB8B7C | |||
| 3180 | WebInstallerEngine.exe | C:\Users\admin\AppData\Local\Temp\FiberChekPRO\WebInstaller\Database\ConnectorDefinitions\MPO 12x2.fccon | xml | |
MD5:230009D0DB1A01ABFB9A06A07E6E58A9 | SHA256:74D0B1C82673FEA24852CB7B518C48A0149F9071B48CCE751319AB35E3C3A4E3 | |||
| 3240 | fcpro_2.3.3.6635_web_installer.exe | C:\Users\admin\AppData\Local\Temp\is-6730I.tmp\fcpro_2.3.3.6635_web_installer.tmp | executable | |
MD5:2C10DB017057DCE22651243244E4FEE6 | SHA256:E442E83C27E94BC37EB6C02411A88EDD8CB83777D50312B9EF7BFC214C4CC7B2 | |||
| 3180 | WebInstallerEngine.exe | C:\Users\admin\AppData\Local\Temp\FiberChekPRO\WebInstaller\Database\ConnectorDefinitions\Simplex.fccon | xml | |
MD5:A0E4BB95B890583C829626BBB730C576 | SHA256:8FBB9668C68EA14B273C5E221D4FE824C1DC739DECA23D004C67933157A1ECB3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2232 | WebInstallerEngine.exe | 52.238.56.180:443 | jdsufit.blob.core.windows.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3180 | WebInstallerEngine.exe | 52.238.56.180:443 | jdsufit.blob.core.windows.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
jdsufit.blob.core.windows.net |
| unknown |
Process | Message |
|---|---|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:48:55.520 DEBUG: Starting WebInstallerEngine.exe
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.740 DEBUG: Starting WebInstallerEngine.exe
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.905 DEBUG: FileIndex has 491 files. Determined that 487 files are needed:
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 12x1.fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 12x2.fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 16x1.fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 16x2.fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 8x1.fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\MPO 8x2 [24].fccon"
|
WebInstallerEngine.exe | WebInstallerEngine: 2024-02-24 12:49:20.907 DEBUG: "Database\ConnectorDefinitions\Simplex.fccon"
|