| File name: | setup_win.exe.exe |
| Full analysis: | https://app.any.run/tasks/526eeda4-e2f1-4cb4-b10b-5b80783cf260 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | October 27, 2021, 03:27:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 8A1E3856C9E928C99139C7FA235D3B5E |
| SHA1: | E1DE22DDDAB8313E0F4D1A266A1DC098E3577137 |
| SHA256: | DD0A55714D433909F1C9B7D1CD4FF2FC6A2A3F8837249105AF89BB31A732D9B7 |
| SSDEEP: | 49152:/G5UfgBTFurx12F+zAaSHV2wopAma07VDWktrGuDUlv/9TNU0LXeRINBNt:/G5QgC1lEBHVDoVa0R6mBUl9u0KRkt |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:04:18 20:54:06+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 104448 |
| InitializedDataSize: | 35328 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x148d4 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.4.5.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileVersion: | 6.4.5.0 |
| ProductVersion: | 1.0.0.0 |
| CompanyName: | IC001 |
| FileDescription: | Software Installation |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright © Adaware 2021 |
| OriginalFileName: | GenericSetup.exe |
| ProductName: | InstallCapital |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 532 | C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp" | C:\Windows\system32\cmd.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1044 | sc.exe create "McAfee WebAdvisor" binPath= "\"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe\"" start= auto DisplayName= "McAfee WebAdvisor" | C:\Windows\system32\sc.exe | — | installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1788 | .\GenericSetup.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\GenericSetup.exe | setup_win.exe.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Software Installation Exit code: 0 Version: 1.4.1.5119 Modules
| |||||||||||||||
| 1844 | "C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe" | C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe | services.exe | ||||||||||||
User: SYSTEM Company: McAfee, LLC Integrity Level: SYSTEM Description: McAfee WebAdvisor Exit code: 0 Version: 4,1,1,641 Modules
| |||||||||||||||
| 1876 | "C:\Users\admin\AppData\Local\Temp\setup_win.exe.exe" | C:\Users\admin\AppData\Local\Temp\setup_win.exe.exe | Explorer.EXE | ||||||||||||
User: admin Company: IC001 Integrity Level: HIGH Description: Software Installation Exit code: 0 Version: 6.4.5.0 Modules
| |||||||||||||||
| 1936 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\Downloads\vlc-3.0.14-win64.exe"" | C:\Windows\system32\cmd.exe | — | GenericSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2120 | regsvr32.exe /s "C:\Program Files\McAfee\WebAdvisor\win32\DownloadScan.dll" | C:\Windows\system32\regsvr32.exe | — | installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2188 | sc.exe start "McAfee WebAdvisor" | C:\Windows\system32\sc.exe | — | installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2544 | "C:\Program Files\McAfee\Temp563236837\installer.exe" /setOem:Affid=91213 /s /thirdparty /upgrade | C:\Program Files\McAfee\Temp563236837\installer.exe | installer.exe | ||||||||||||
User: admin Company: McAfee, LLC Integrity Level: HIGH Description: McAfee WebAdvisor Exit code: 0 Version: 4,1,1,641 Modules
| |||||||||||||||
| 3028 | regsvr32.exe /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll" | C:\Windows\system32\regsvr32.exe | — | installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6 | |||
| (PID) Process: | (1788) GenericSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4 |
| Operation: | write | Name: | Blob |
Value: 5C0000000100000004000000000800007E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703070400000001000000100000004BE2C99196650CF40E5A9392A00AFEB22000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6 | |||
| (PID) Process: | (3944) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor |
| Operation: | write | Name: | UUID |
Value: {52500CFF-A115-4911-80FC-A44938731433} | |||
| (PID) Process: | (3944) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor |
| Operation: | write | Name: | InstallerFlags |
Value: 1 | |||
| (PID) Process: | (3944) saBSI.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\BundleConfig.json | text | |
MD5:— | SHA256:— | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\images\logo.png | image | |
MD5:C5B6429D92236C5399A1727BEAFA3C76 | SHA256:A0B587C2977237BF44181E5559F08D7D33E190F1D62E7C1A2B46B691BDF9A4E6 | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\DownloadPage.html | html | |
MD5:FACE1F2993D5DF8BEB0C37B2E9617993 | SHA256:3C9658136C893B7027F05B54296445C2858565AA30745D9B179839CC23F7497B | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\app.ico | image | |
MD5:4003EFA6E7D44E2CBD3D7486E2E0451A | SHA256:EFFD42C5E471EA3792F12538BF7C982A5CDA4D25BFBFFAF51EED7E09035F4508 | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\images\warning48x48.png | image | |
MD5:D3361CF0D689A1B34D84F483D60BA9C9 | SHA256:56739925AADA73F9489F9A6B72BFAAA92892B27D20F4D221380BA3EAE17F1442 | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\GenericSetup.exe.config | xml | |
MD5:FB0F6EC442C72190B9A27BDFD53563BB | SHA256:99C598E9B85A47F0FBDE66A7FED7EB896A15CA2AF869EBB2007B2A2CE64C14FD | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\tis\Log.tis | text | |
MD5:CEF7A21ACF607D44E160EAC5A21BDF67 | SHA256:73ED0BE73F408AB8F15F2DA73C839F86FEF46D0A269607330B28F9564FAE73C7 | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\images\bg.png | image | |
MD5:8EA330DEF408BB6B3BBC67A50857E20E | SHA256:852D4712E8D7109E71E5AB508712192148A2FA2D80146684A6356FE7D10C5BCB | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\FinishPage.html | html | |
MD5:6EEF560F70E4DD79B823C888E7C38E57 | SHA256:B25DBD7FA802FD2CEB1800EB8CD2BDE205CB7AAB5B56C4C054725F92C888591B | |||
| 1876 | setup_win.exe.exe | C:\Users\admin\AppData\Local\Temp\7zS4570BB2B\Resources\DownloadFolderPage.html | html | |
MD5:9DEA08DCA124C9CA58A082E62220ABEE | SHA256:00724E06138C68EB7AB40CDF3275CC7DB45698F10A98AC8C78B5F6582393F64C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1788 | GenericSetup.exe | HEAD | 200 | 104.16.235.79:80 | http://sdl.adaware.com/cdn/saBSI.exe | US | — | — | whitelisted |
1788 | GenericSetup.exe | GET | — | 104.16.235.79:80 | http://sdl.adaware.com/cdn/saBSI.exe | US | — | — | whitelisted |
1788 | GenericSetup.exe | GET | 200 | 104.16.235.79:80 | http://sdl.adaware.com/cdn/saBSI.exe | US | executable | 1.06 Mb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1788 | GenericSetup.exe | 104.16.235.79:443 | h2oapi.adaware.com | Cloudflare Inc | US | shared |
1788 | GenericSetup.exe | 104.18.88.101:443 | flow.lavasoft.com | Cloudflare Inc | US | shared |
1788 | GenericSetup.exe | 104.16.236.79:443 | h2oapi.adaware.com | Cloudflare Inc | US | shared |
1788 | GenericSetup.exe | 109.205.222.4:443 | mirror.zetup.net | Zetup AB | SE | unknown |
1788 | GenericSetup.exe | 104.16.235.79:80 | h2oapi.adaware.com | Cloudflare Inc | US | shared |
2544 | installer.exe | 104.111.242.161:443 | home.mcafee.com | Akamai International B.V. | NL | suspicious |
3716 | updater.exe | 2.18.233.229:443 | sadownload.mcafee.com | Akamai International B.V. | — | whitelisted |
1844 | ServiceHost.exe | 104.208.16.0:443 | cu1pehnswad01.servicebus.windows.net | Microsoft Corporation | US | unknown |
3716 | updater.exe | 104.208.16.0:443 | cu1pehnswad01.servicebus.windows.net | Microsoft Corporation | US | unknown |
2544 | installer.exe | 104.208.16.0:443 | cu1pehnswad01.servicebus.windows.net | Microsoft Corporation | US | unknown |
Domain | IP | Reputation |
|---|---|---|
h2oapi.adaware.com |
| malicious |
www.google.com |
| malicious |
flow.lavasoft.com |
| whitelisted |
sos.adaware.com |
| whitelisted |
mirror.zetup.net |
| unknown |
sdl.adaware.com |
| whitelisted |
cu1pehnswad01.servicebus.windows.net |
| whitelisted |
sadownload.mcafee.com |
| whitelisted |
home.mcafee.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
1788 | GenericSetup.exe | A Network Trojan was detected | ET INFO Suspicious Windows NT version 9 User-Agent |
1788 | GenericSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1788 | GenericSetup.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
1788 | GenericSetup.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
1788 | GenericSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1788 | GenericSetup.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
1788 | GenericSetup.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
Process | Message |
|---|---|
GenericSetup.exe | Error: File not found - genericsetup.wrappers.sciter:console.tis
|
GenericSetup.exe | at sciter:init-script.tis
|
GenericSetup.exe | |
GenericSetup.exe | |
GenericSetup.exe | file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
|
GenericSetup.exe | Error: File not found - genericsetup.wrappers.sciter:console.tis
|
GenericSetup.exe | at sciter:init-script.tis
|
GenericSetup.exe | |
GenericSetup.exe | |
GenericSetup.exe | file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
|