| URL: | http://www.mediafire.com/file/qldyddn48ffzrwn/BMW+Standard+Tools+2.12.rar |
| Full analysis: | https://app.any.run/tasks/5587fdf1-5a37-44ac-b6fc-1845046b2d27 |
| Verdict: | Malicious activity |
| Analysis date: | May 02, 2019, 22:12:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 89541F05F20611CB46BC9EE533CF812E |
| SHA1: | 72E920411851E0423891D3CBD2BBA678AC909586 |
| SHA256: | E06BB3D7E641642382471BEB5C9F8560E7979CAE31B9EB8C36758D6F462EA1CE |
| SSDEEP: | 3:N1KJS4w3eGUoQq3Dm+oyZoEBGUbUX:Cc4w3eG8q3S+o1EB/UX |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 588 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3888 --on-initialized-event-handle=308 --parent-handle=312 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 808 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14062609751235198334 --mojo-platform-channel-handle=6160 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 876 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14956340544507894595 --mojo-platform-channel-handle=3384 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 892 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=8788986143574911879 --mojo-platform-channel-handle=2016 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 892 | "C:\NCSEXPER\BIN\NCSEXPER.exe" | C:\NCSEXPER\BIN\NCSEXPER.exe | — | explorer.exe | |||||||||||
User: admin Company: Softing Project Services GmbH Integrity Level: MEDIUM Description: NCS-Expertentool Exit code: 0 Version: 4.0.1.0 Modules
| |||||||||||||||
| 1060 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=6632360934180166340 --mojo-platform-channel-handle=6404 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1256 | net stop carserver | C:\Windows\system32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1476 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=14130454634220161862 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14130454634220161862 --renderer-client-id=27 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6352 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1520 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=964,7684098884706590447,18307735252959577817,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=17152363334188467644 --mojo-platform-channel-handle=944 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1536 | "C:\Users\admin\AppData\Local\Temp\is-QG0UF.tmp\Standard_Tools_Setup_2.12.tmp" /SL5="$501D4,33407133,54272,C:\Users\admin\Downloads\BMW Standard Tools 2.12\BMW Standard Tools 2.12\Standard_Tools_Setup_2.12.exe" /SPAWNWND=$500EC /NOTIFYWND=$501E6 | C:\Users\admin\AppData\Local\Temp\is-QG0UF.tmp\Standard_Tools_Setup_2.12.tmp | Standard_Tools_Setup_2.12.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3488-13197474229333984 |
Value: 0 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3880-13201308737581875 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\b347af01-10c4-42f9-bebe-2f24cd9b4336.tmp | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3880 | chrome.exe | GET | 200 | 172.217.22.14:80 | http://translate.google.com/translate_a/element.js?cb=googFooterTranslate | US | text | 726 b | whitelisted |
3880 | chrome.exe | GET | 200 | 104.19.194.29:80 | http://www.mediafire.com/templates/linkto/ads.php?o=0&d=1&t=0 | US | html | 3.25 Kb | shared |
3880 | chrome.exe | GET | 200 | 104.18.92.64:80 | http://cdn.engine.addroplet.com/Scripts/infinity.js.aspx?guid=5ff0fb62-0643-4ff1-aaee-c737f9ffc0e0 | US | text | 71.6 Kb | whitelisted |
3880 | chrome.exe | GET | 200 | 104.19.194.29:80 | http://www.mediafire.com/js/prebid1.30.0.js | US | text | 35.6 Kb | shared |
3880 | chrome.exe | GET | 200 | 104.17.72.92:80 | http://engine.addroplet.com/Tag.engine?time=-60&id=5ff0fb62-0643-4ff1-aaee-c737f9ffc0e0&rand=799&ver=async&referrerUrl=&fingerPrint=123&abr=false&stdTime=0&fpe=1&bw=1280&bh=572&res=1280x720&curl=http%3A%2F%2Fwww.mediafire.com%2Ffile%2Fqldyddn48ffzrwn%2FBMW%2BStandard%2BTools%2B2.12.rar&kw=online%20storage%2Cfree%20storage%2Ccloud%20storage%2Ccollaboration%2Cbackup%20file%20sharing%2Cshare%20files%2Cphoto%20backup%2Cphoto%20sharing%2Cftp%20replacement%2Ccross%20platform%2Cremote%20access%2Cmobile%20access%2Csend%20large%20files%2Crecover%20files%2Cfile%20versioning%2Cundelete%2Cwindows%2Cpc%2Cmac%2Cos%20x%2Clinux%2Ciphone | US | text | 2.66 Kb | shared |
3880 | chrome.exe | GET | 200 | 2.16.186.51:80 | http://b.scorecardresearch.com/beacon.js?c1=8&c2=18203330&c3=1 | unknown | text | 708 b | whitelisted |
3880 | chrome.exe | GET | 200 | 104.18.92.64:80 | http://cdn.engine.addroplet.com/Scripts/MediaScripts/b.js?v=4 | US | text | 66.1 Kb | whitelisted |
3880 | chrome.exe | GET | 302 | 2.16.186.51:80 | http://b.scorecardresearch.com/b?c1=8&c2=18203330&rn=0.6006802448688517&c7=http%3A%2F%2Fwww.mediafire.com%2Ffile%2Fqldyddn48ffzrwn%2FBMW%2BStandard%2BTools%2B2.12.rar&c3=1&c4=&c5=&c6=&c10=&c15=&c16=&c8=BMW%20Standard%20Tools%202.12&c9=&cv=1.8 | unknown | compressed | 708 b | whitelisted |
3880 | chrome.exe | GET | 204 | 2.16.186.51:80 | http://b.scorecardresearch.com/b2?c1=8&c2=18203330&rn=0.6006802448688517&c7=http%3A%2F%2Fwww.mediafire.com%2Ffile%2Fqldyddn48ffzrwn%2FBMW%2BStandard%2BTools%2B2.12.rar&c3=1&c4=&c5=&c6=&c10=&c15=&c16=&c8=BMW%20Standard%20Tools%202.12&c9=&cv=1.8 | unknown | compressed | 708 b | whitelisted |
3880 | chrome.exe | GET | 200 | 104.19.194.29:80 | http://www.mediafire.com/file/qldyddn48ffzrwn/BMW+Standard+Tools+2.12.rar | US | html | 48.5 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3880 | chrome.exe | 74.125.140.154:443 | stats.g.doubleclick.net | Google Inc. | US | whitelisted |
3880 | chrome.exe | 172.217.23.162:443 | adservice.google.com | Google Inc. | US | whitelisted |
3880 | chrome.exe | 172.217.22.34:443 | adservice.google.co.uk | Google Inc. | US | whitelisted |
3880 | chrome.exe | 172.217.23.130:443 | securepubads.g.doubleclick.net | Google Inc. | US | whitelisted |
3880 | chrome.exe | 34.240.130.215:80 | ad.crwdcntrl.net | Amazon.com, Inc. | IE | unknown |
3880 | chrome.exe | 172.217.18.3:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3880 | chrome.exe | 104.19.194.29:80 | www.mediafire.com | Cloudflare Inc | US | shared |
3880 | chrome.exe | 172.217.22.14:80 | translate.google.com | Google Inc. | US | whitelisted |
3880 | chrome.exe | 172.217.23.168:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
3880 | chrome.exe | 104.19.195.29:80 | www.mediafire.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
www.mediafire.com |
| shared |
accounts.google.com |
| shared |
www.googletagmanager.com |
| whitelisted |
translate.google.com |
| whitelisted |
static.mediafire.com |
| shared |
download698.mediafire.com |
| suspicious |
facebook.com |
| whitelisted |
blog.mediafire.com |
| whitelisted |
google.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3880 | chrome.exe | Generic Protocol Command Decode | SURICATA HTTP unable to match response to request |
3880 | chrome.exe | Generic Protocol Command Decode | SURICATA HTTP unable to match response to request |
Process | Message |
|---|---|
INPALOAD.exe | CStdGateway::Shutdown Kill Gateway thread
|
INPALOAD.exe | CStdGateway::Shutdown Kill Gateway thread
|