download:

mobilego_setup_full818.exe

Full analysis: https://app.any.run/tasks/ec01dc44-a13e-412b-929f-00fecb1c6d0f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 09, 2019, 15:21:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CD54815ECD7A61E546C8DD18AF166480

SHA1:

4781E415B820F2F3EED081FD161F8B122283BCCD

SHA256:

DD44F2CDAC33273DA74C822BA66278112E50DDEB5E54597E182AD2D3ADE06DC3

SSDEEP:

12288:2w8Jiq97i32bkQoTHHYn5iwh6lc+EmWlWYwU0fClaLM9UtfvHB1+jiEPv:aw9QoTQiwh6lc+Em9Yw0WIUFvv+GE3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • mobilego_full818.exe (PID: 620)
      • WAFSetup.exe (PID: 920)
      • WsAppService.exe (PID: 1584)
      • URLReqService.exe (PID: 1828)
      • MobileGo.exe (PID: 2584)
    • Writes to a start menu file

      • mobilego_full818.tmp (PID: 908)
    • Downloads executable files from the Internet

      • mobilego_setup_full818.exe (PID: 1424)
    • Loads dropped or rewritten executable

      • RegAsm.exe (PID: 3560)
      • RegAsm.exe (PID: 2824)
      • RegAsm.exe (PID: 1692)
      • RegAsm.exe (PID: 388)
      • RegAsm.exe (PID: 2476)
      • RegAsm.exe (PID: 3888)
      • InstallUtil.exe (PID: 3624)
      • WsAppService.exe (PID: 1584)
      • RegAsm.exe (PID: 712)
      • RegAsm.exe (PID: 2692)
      • RegAsm.exe (PID: 3436)
      • RegAsm.exe (PID: 892)
      • RegAsm.exe (PID: 2356)
      • RegAsm.exe (PID: 1460)
      • RegAsm.exe (PID: 2968)
      • URLReqService.exe (PID: 1828)
      • mscorsvw.exe (PID: 3876)
      • mscorsvw.exe (PID: 3976)
      • mscorsvw.exe (PID: 2996)
      • mscorsvw.exe (PID: 3588)
      • MobileGo.exe (PID: 2584)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1528)
    • Changes settings of System certificates

      • WsAppService.exe (PID: 1584)
      • RegAsm.exe (PID: 712)
      • CertUtil.exe (PID: 2060)
    • Loads the Task Scheduler COM API

      • ngen.exe (PID: 3660)
      • ngen.exe (PID: 3496)
      • ngen.exe (PID: 1472)
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • mobilego_setup_full818.exe (PID: 1424)
    • Creates files in the user directory

      • mobilego_full818.tmp (PID: 908)
    • Executable content was dropped or overwritten

      • WAFSetup.exe (PID: 920)
      • mobilego_full818.exe (PID: 620)
      • WAFSetup.tmp (PID: 3972)
      • mobilego_full818.tmp (PID: 908)
      • WsAppService.exe (PID: 1584)
      • mscorsvw.exe (PID: 2996)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2776)
    • Reads the Windows organization settings

      • WAFSetup.tmp (PID: 3972)
      • mobilego_full818.tmp (PID: 908)
    • Creates or modifies windows services

      • mobilego_full818.tmp (PID: 908)
    • Reads Windows owner or organization settings

      • WAFSetup.tmp (PID: 3972)
      • mobilego_full818.tmp (PID: 908)
    • Reads internet explorer settings

      • mobilego_setup_full818.exe (PID: 1424)
    • Reads Internet Cache Settings

      • mobilego_setup_full818.exe (PID: 1424)
      • RegAsm.exe (PID: 2476)
    • Creates files in the Windows directory

      • WAFSetup.tmp (PID: 3972)
      • InstallUtil.exe (PID: 3624)
      • WsAppService.exe (PID: 1584)
      • ngen.exe (PID: 3660)
      • ngen.exe (PID: 3496)
      • ngen.exe (PID: 1472)
      • InstallUtil.exe (PID: 3632)
      • CertUtil.exe (PID: 2060)
      • ngen.exe (PID: 1912)
      • mscorsvw.exe (PID: 2996)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2776)
    • Creates files in the program directory

      • RegAsm.exe (PID: 2476)
      • RegAsm.exe (PID: 3888)
      • RegAsm.exe (PID: 388)
      • InstallUtil.exe (PID: 3624)
      • WsAppService.exe (PID: 1584)
      • RegAsm.exe (PID: 712)
      • RegAsm.exe (PID: 2692)
      • RegAsm.exe (PID: 892)
      • RegAsm.exe (PID: 2968)
      • RegAsm.exe (PID: 1460)
      • RegAsm.exe (PID: 3436)
      • RegAsm.exe (PID: 3960)
      • InstallUtil.exe (PID: 3632)
      • dw20.exe (PID: 2200)
    • Creates COM task schedule object

      • RegAsm.exe (PID: 2476)
      • RegAsm.exe (PID: 388)
      • RegAsm.exe (PID: 712)
      • RegAsm.exe (PID: 2692)
      • RegAsm.exe (PID: 3436)
      • RegAsm.exe (PID: 892)
      • RegAsm.exe (PID: 1460)
      • RegAsm.exe (PID: 2968)
      • RegAsm.exe (PID: 3960)
    • Reads Environment values

      • RegAsm.exe (PID: 2476)
    • Modifies the open verb of a shell class

      • RegAsm.exe (PID: 388)
      • mobilego_full818.tmp (PID: 908)
    • Adds / modifies Windows certificates

      • WsAppService.exe (PID: 1584)
      • RegAsm.exe (PID: 712)
    • Removes files from Windows directory

      • WsAppService.exe (PID: 1584)
      • CertUtil.exe (PID: 2060)
      • mscorsvw.exe (PID: 2996)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2776)
    • Searches for installed software

      • RegAsm.exe (PID: 2476)
    • Loads Python modules

      • URLReqService.exe (PID: 1828)
    • Starts Internet Explorer

      • mobilego_setup_full818.exe (PID: 1424)
  • INFO

    • Loads dropped or rewritten executable

      • mobilego_full818.tmp (PID: 908)
      • WAFSetup.tmp (PID: 3972)
    • Application was dropped or rewritten from another process

      • mobilego_full818.tmp (PID: 908)
      • WAFSetup.tmp (PID: 3972)
    • Dropped object may contain Bitcoin addresses

      • mobilego_full818.tmp (PID: 908)
    • Creates a software uninstall entry

      • mobilego_full818.tmp (PID: 908)
    • Creates files in the program directory

      • WAFSetup.tmp (PID: 3972)
      • mobilego_full818.tmp (PID: 908)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1784)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1784)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1784)
    • Changes internet zones settings

      • iexplore.exe (PID: 3120)
    • Creates files in the user directory

      • iexplore.exe (PID: 1784)
    • Application was crashed

      • MobileGo.exe (PID: 2584)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1784)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (16.3)
.exe | Win64 Executable (generic) (14.5)
.dll | Win32 Dynamic Link Library (generic) (3.4)
.exe | Win32 Executable (generic) (2.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:01 05:42:12+02:00
PEType: PE32
LinkerVersion: 9
CodeSize: 451072
InitializedDataSize: 522752
UninitializedDataSize: -
EntryPoint: 0x51167
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.9.2
ProductVersionNumber: 2.0.9.2
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: mobilego_setup_full818.exe
FileVersion: 2.0.9.2
LegalCopyright: Copyright©2017 Wondershare. All rights reserved.
ProductName: MobileGo
ProductVersion: 8.5.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
40
Malicious processes
31
Suspicious processes
1

Behavior graph

Click at the process to see the details
download and start start drop and start drop and start drop and start drop and start mobilego_setup_full818.exe nfwchk.exe no specs mobilego_full818.exe mobilego_full818.tmp wafsetup.exe wafsetup.tmp regasm.exe no specs regasm.exe regasm.exe regasm.exe no specs regasm.exe regasm.exe no specs installutil.exe no specs wsappservice.exe ngen.exe no specs ngen.exe no specs ngen.exe no specs regasm.exe regasm.exe no specs regasm.exe no specs regasm.exe no specs regasm.exe no specs regasm.exe no specs regasm.exe no specs regasm.exe no specs installutil.exe no specs ngen.exe no specs urlreqservice.exe no specs certutil.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe mobilego.exe iexplore.exe iexplore.exe dw20.exe no specs mobilego_setup_full818.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
388"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" "C:\Program Files\Wondershare\WAF\2.4.2.223\WsAppClient.exe" /codebase /tlb:"C:\Program Files\Wondershare\WAF\WsAppClient.tlb" /nologoC:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWAFSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.6.1055.0 built by: NETFXREL2
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
620"C:\Users\Public\Documents\Wondershare\mobilego_full818.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-MobileGo.log" /installpath: "C:\Program Files\Wondershare\MobileGo\" /DIR="C:\Program Files\Wondershare\MobileGo\"C:\Users\Public\Documents\Wondershare\mobilego_full818.exe
mobilego_setup_full818.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
Wondershare MobileGo
Exit code:
0
Version:
8.5.0.109
Modules
Images
c:\users\public\documents\wondershare\mobilego_full818.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
712"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "C:\Program Files\Wondershare\MobileGo\MobileGo.exe" /codebase /tlbC:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
mobilego_full818.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
892"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "C:\Program Files\Wondershare\MobileGo\MGNotification.exe" /codebase /tlbC:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exemobilego_full818.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
908"C:\Users\admin\AppData\Local\Temp\is-R9JQ5.tmp\mobilego_full818.tmp" /SL5="$60146,58754225,322560,C:\Users\Public\Documents\Wondershare\mobilego_full818.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-MobileGo.log" /installpath: "C:\Program Files\Wondershare\MobileGo\" /DIR="C:\Program Files\Wondershare\MobileGo\"C:\Users\admin\AppData\Local\Temp\is-R9JQ5.tmp\mobilego_full818.tmp
mobilego_full818.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-r9jq5.tmp\mobilego_full818.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
920"C:\Program Files\Wondershare\MobileGo\WAFSetup.exe" /VERYSILENTC:\Program Files\Wondershare\MobileGo\WAFSetup.exe
mobilego_full818.tmp
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
Wondershare Passport
Exit code:
0
Version:
2.4.2.223
Modules
Images
c:\program files\wondershare\mobilego\wafsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1424"C:\Users\admin\AppData\Local\Temp\mobilego_setup_full818.exe" C:\Users\admin\AppData\Local\Temp\mobilego_setup_full818.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
mobilego_setup_full818.exe
Exit code:
0
Version:
2.0.9.2
Modules
Images
c:\users\admin\appdata\local\temp\mobilego_setup_full818.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1460"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "C:\Program Files\Wondershare\MobileGo\WsMediaInfo.exe" /codebase /tlbC:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exemobilego_full818.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1472"C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe" install "C:\Program Files\Wondershare\MobileGo\WUL.Diagrams.dll" /silent /NoDependencies /queueC:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exemobilego_full818.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\ngen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1528C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1a4 -InterruptEvent 0 -NGENProcess 1a0 -Pipe 1a8 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.6.1055.0 built by: NETFXREL2
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\ole32.dll
Total events
3 855
Read events
1 882
Write events
1 929
Delete events
44

Modification events

(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:
Value:
sku-ween
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:818
Value:
sku-ween
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact
Operation:writeName:ClientSign
Value:
{C4BA3647-0000-0QM0-0001-5254004A04AF}
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF
Operation:writeName:ClientSign
Value:
{C4BA3647-0000-0QM0-0001-5254004A04AF}
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mobilego_setup_full818_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mobilego_setup_full818_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mobilego_setup_full818_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1424) mobilego_setup_full818.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mobilego_setup_full818_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
197
Suspicious files
35
Text files
189
Unknown types
30

Dropped files

PID
Process
Filename
Type
1424mobilego_setup_full818.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe
MD5:
SHA256:
1424mobilego_setup_full818.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe.config
MD5:
SHA256:
1424mobilego_setup_full818.exeC:\Users\Public\Documents\Wondershare\mobilego_full818.exe.~P2S
MD5:
SHA256:
1424mobilego_setup_full818.exeC:\Users\Public\Documents\Wondershare\mobilego_full818.exe
MD5:
SHA256:
908mobilego_full818.tmpC:\Users\admin\AppData\Local\Temp\is-H7NGK.tmp\is-O8E06.tmp
MD5:
SHA256:
908mobilego_full818.tmpC:\Users\admin\AppData\Local\Temp\is-H7NGK.tmp\FixHelperV1_2_6_updateBug
MD5:
SHA256:
908mobilego_full818.tmpC:\Program Files\Wondershare\MobileGo\is-52TVJ.tmp
MD5:
SHA256:
908mobilego_full818.tmpC:\Program Files\Wondershare\MobileGo\is-O19VR.tmp
MD5:
SHA256:
908mobilego_full818.tmpC:\Program Files\Wondershare\MobileGo\is-85QHC.tmp
MD5:
SHA256:
908mobilego_full818.tmpC:\Program Files\Wondershare\MobileGo\is-OJRQB.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
98
TCP/UDP connections
90
DNS requests
25
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.106:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.113:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.112:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
GET
2.16.186.56:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.56:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.64:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
GET
63.159.217.165:80
http://dlinst.wondershare.com/player/style/orbit-1.3.0.css
US
suspicious
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.65:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.66:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
1424
mobilego_setup_full818.exe
HEAD
200
2.16.186.88:80
http://download.wondershare.com/cbs_down/mobilego_full818.exe
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1424
mobilego_setup_full818.exe
2.16.186.56:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
47.91.67.36:80
platform.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
1424
mobilego_setup_full818.exe
2.16.186.64:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
63.159.217.165:80
dlinst.wondershare.com
QUANTIL, INC
US
unknown
1424
mobilego_setup_full818.exe
2.16.186.65:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
2.16.186.66:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
2.16.186.88:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
2.16.186.99:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
2.16.186.106:80
download.wondershare.com
Akamai International B.V.
whitelisted
1424
mobilego_setup_full818.exe
2.16.186.112:80
download.wondershare.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
platform.wondershare.com
  • 47.91.67.36
suspicious
download.wondershare.com
  • 2.16.186.106
  • 2.16.186.99
  • 2.16.186.112
  • 2.16.186.66
  • 2.16.186.56
  • 2.16.186.88
  • 2.16.186.65
  • 2.16.186.113
  • 2.16.186.64
  • 2.16.186.105
  • 2.16.186.97
  • 2.16.186.57
  • 2.16.186.115
  • 2.16.186.67
  • 2.16.186.50
  • 2.16.186.83
  • 72.247.182.98
  • 72.247.182.82
  • 184.25.116.72
  • 184.25.116.88
whitelisted
dlinst.wondershare.com
  • 63.159.217.165
suspicious
us.wondershare.com
unknown
was.wondershare.com
  • 203.130.48.150
  • 203.130.48.151
unknown
was-stats.wondershare.com
  • 63.159.217.174
suspicious
ocsp.verisign.com
  • 23.37.43.27
whitelisted
sf.symcd.com
  • 23.37.43.27
whitelisted
www.download.windowsupdate.com
  • 8.248.119.254
  • 8.253.207.121
  • 67.27.234.126
  • 67.27.159.254
  • 67.27.157.126
whitelisted
cbs.wondershare.com
  • 47.91.89.199
  • 47.91.76.37
  • 47.91.89.20
  • 47.91.91.66
whitelisted

Threats

PID
Process
Class
Message
1424
mobilego_setup_full818.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1424
mobilego_setup_full818.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.
RegAsm.exe
Cannot delete a subkey tree because the subkey does not exist.