File name:

CTBrowserSetup.exe

Full analysis: https://app.any.run/tasks/2c12c168-1f13-449c-bbe8-d85cde46539b
Verdict: Malicious activity
Analysis date: July 27, 2024, 06:18:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

A0FAB21C52FB92A79BC492D2EB91D1D6

SHA1:

03D14DA347C554669916D60E24BEE1B540C2822E

SHA256:

E10F9D22CDBC39874CE875FD8031C3DB26F58DAF20EE8AE6A82DE9ED2DFC7863

SSDEEP:

49152:VaFSMmQsOZgebSEjpj24R76kPmDzgsnQnddt4FwR+Viv6WwJrY701QnE60:VOCJEnj26ukshQnnYVWcy0GE60

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CTBrowserSetup.exe (PID: 3168)
      • ctu6808.tmp (PID: 2396)
      • setup.exe (PID: 6284)
      • browser.exe (PID: 7984)
    • Changes the autorun value in the registry

      • setup.exe (PID: 6284)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • CTBrowserSetup.exe (PID: 3168)
      • chrmstp.exe (PID: 6764)
    • Reads security settings of Internet Explorer

      • CTBrowserSetup.exe (PID: 3168)
      • CTBrowserSetup.exe (PID: 1128)
      • chrmstp.exe (PID: 6764)
      • ShellExperienceHost.exe (PID: 4560)
    • Application launched itself

      • CTBrowserSetup.exe (PID: 3168)
      • setup.exe (PID: 6284)
      • setup.exe (PID: 2248)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 4104)
      • chrmstp.exe (PID: 1904)
      • chrmstp.exe (PID: 6764)
    • Starts application with an unusual extension

      • CTBrowserSetup.exe (PID: 1128)
    • Checks Windows Trust Settings

      • CTBrowserSetup.exe (PID: 1128)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 6284)
      • ctu6808.tmp (PID: 2396)
      • browser.exe (PID: 7984)
    • Creates a software uninstall entry

      • setup.exe (PID: 6284)
    • Searches for installed software

      • setup.exe (PID: 6284)
    • The process checks if it is being run in the virtual environment

      • browser.exe (PID: 5124)
  • INFO

    • Reads the computer name

      • CTBrowserSetup.exe (PID: 3168)
      • CTBrowserSetup.exe (PID: 1128)
      • ctu6808.tmp (PID: 2396)
      • setup.exe (PID: 6284)
      • setup.exe (PID: 2248)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 4104)
      • CryptoTabUpdater.exe (PID: 2424)
      • browser.exe (PID: 7136)
      • browser.exe (PID: 1468)
      • chrmstp.exe (PID: 1904)
      • chrmstp.exe (PID: 6764)
      • browser.exe (PID: 5728)
      • ShellExperienceHost.exe (PID: 4560)
      • browser.exe (PID: 5400)
    • Checks proxy server information

      • slui.exe (PID: 6076)
      • CTBrowserSetup.exe (PID: 1128)
      • browser.exe (PID: 5124)
    • Process checks computer location settings

      • CTBrowserSetup.exe (PID: 3168)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 5736)
      • browser.exe (PID: 5716)
      • browser.exe (PID: 6640)
      • browser.exe (PID: 4832)
      • browser.exe (PID: 4580)
      • browser.exe (PID: 7568)
      • browser.exe (PID: 6412)
      • browser.exe (PID: 7764)
    • Reads the software policy settings

      • slui.exe (PID: 6076)
      • CTBrowserSetup.exe (PID: 1128)
      • CryptoTabUpdater.exe (PID: 2424)
    • Checks supported languages

      • CTBrowserSetup.exe (PID: 3168)
      • CTBrowserSetup.exe (PID: 1128)
      • ctu6808.tmp (PID: 2396)
      • setup.exe (PID: 6284)
      • setup.exe (PID: 2952)
      • setup.exe (PID: 2248)
      • setup.exe (PID: 2824)
      • browser.exe (PID: 4104)
      • browser.exe (PID: 2976)
      • CryptoTabUpdater.exe (PID: 2424)
      • browser.exe (PID: 1468)
      • browser.exe (PID: 7136)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 6640)
      • browser.exe (PID: 4832)
      • browser.exe (PID: 6764)
      • browser.exe (PID: 4580)
      • browser.exe (PID: 1356)
      • browser.exe (PID: 5736)
      • browser.exe (PID: 5716)
      • browser.exe (PID: 1464)
      • chrmstp.exe (PID: 1904)
      • chrmstp.exe (PID: 2956)
      • chrmstp.exe (PID: 4468)
      • chrmstp.exe (PID: 6764)
      • browser.exe (PID: 4704)
      • browser.exe (PID: 6672)
      • browser.exe (PID: 6056)
      • browser.exe (PID: 5728)
      • browser.exe (PID: 1768)
      • ShellExperienceHost.exe (PID: 4560)
      • browser.exe (PID: 6412)
      • browser.exe (PID: 7264)
      • browser.exe (PID: 7520)
      • browser.exe (PID: 7304)
      • browser.exe (PID: 7212)
      • browser.exe (PID: 7348)
      • browser.exe (PID: 4788)
      • browser.exe (PID: 3588)
      • browser.exe (PID: 4852)
      • browser.exe (PID: 7540)
      • browser.exe (PID: 7568)
      • browser.exe (PID: 7764)
      • browser.exe (PID: 7480)
      • browser.exe (PID: 7236)
      • browser.exe (PID: 5400)
      • browser.exe (PID: 6268)
      • browser.exe (PID: 5964)
      • browser.exe (PID: 7984)
    • UPX packer has been detected

      • CTBrowserSetup.exe (PID: 1128)
    • Creates files or folders in the user directory

      • CTBrowserSetup.exe (PID: 1128)
      • setup.exe (PID: 2248)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 1468)
      • chrmstp.exe (PID: 6764)
      • browser.exe (PID: 5400)
    • Reads the machine GUID from the registry

      • CTBrowserSetup.exe (PID: 1128)
      • CryptoTabUpdater.exe (PID: 2424)
      • browser.exe (PID: 5124)
      • browser.exe (PID: 5400)
      • browser.exe (PID: 7136)
    • Create files in a temporary directory

      • ctu6808.tmp (PID: 2396)
      • browser.exe (PID: 5124)
    • Creates files in the program directory

      • setup.exe (PID: 6284)
      • setup.exe (PID: 2248)
      • browser.exe (PID: 5124)
      • chrmstp.exe (PID: 1904)
      • chrmstp.exe (PID: 6764)
    • Reads Microsoft Office registry keys

      • browser.exe (PID: 5124)
      • chrmstp.exe (PID: 1904)
      • OpenWith.exe (PID: 8024)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 8024)
      • notepad.exe (PID: 8140)
    • Reads Environment values

      • browser.exe (PID: 7136)
    • Manual execution by a user

      • WinRAR.exe (PID: 7940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:01 13:16:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2789376
InitializedDataSize: 36864
UninitializedDataSize: 7159808
EntryPoint: 0x97d680
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.6
ProductVersionNumber: 1.0.0.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: CryptoTabInstaller
FileVersion: 1.0.0.6
LegalCopyright: Copyright (C) CRYPTOCOMPANY OU 2023
ProductName: CryptoTabInstaller
ProductVersion: 1.0.0.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
208
Monitored processes
54
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ctbrowsersetup.exe no specs THREAT ctbrowsersetup.exe slui.exe slui.exe no specs ctu6808.tmp setup.exe setup.exe no specs setup.exe no specs setup.exe no specs browser.exe browser.exe browser.exe cryptotabupdater.exe browser.exe no specs browser.exe browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs shellexperiencehost.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs openwith.exe no specs notepad.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs winrar.exe no specs browser.exe

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\AppData\Local\Temp\CTBrowserSetup.exe" C:\Users\admin\AppData\Local\Temp\CTBrowserSetup.exe
CTBrowserSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
CryptoTabInstaller
Exit code:
0
Version:
1.0.0.6
Modules
Images
c:\users\admin\appdata\local\temp\ctbrowsersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1356"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=2288,i,8574832487540417554,6306294920131063579,524288 --field-trial-handle=3092,i,6340617125450694236,7007698893222937940,262144 --variations-seed-version --mojo-platform-channel-handle=3004 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Version:
125.0.6422.113
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\125.0.6422.113\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1464"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=5564,i,18295322028154929912,7474733228781175154,524288 --field-trial-handle=5544,i,6340617125450694236,7007698893222937940,262144 --variations-seed-version --mojo-platform-channel-handle=5476 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
125.0.6422.113
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\125.0.6422.113\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1468"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=network --no-pre-read-main-dll --start-stack-profiler --metrics-shmem-handle=2136,i,9360425400075852070,13452785614960381950,524288 --field-trial-handle=2152,i,6340617125450694236,7007698893222937940,262144 --variations-seed-version --mojo-platform-channel-handle=2148 /prefetch:3C:\Program Files\CryptoTab Browser\Application\browser.exe
browser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Version:
125.0.6422.113
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\cryptotab browser\application\125.0.6422.113\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1768"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=6416,i,451625820202124326,11272725256625637778,524288 --field-trial-handle=5556,i,6340617125450694236,7007698893222937940,262144 --variations-seed-version --mojo-platform-channel-handle=5720 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
125.0.6422.113
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\125.0.6422.113\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1904"C:\Program Files\CryptoTab Browser\Application\125.0.6422.113\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --force-configure-user-settingsC:\Program Files\CryptoTab Browser\Application\125.0.6422.113\Installer\chrmstp.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
HIGH
Description:
CryptoTab Browser Installer
Exit code:
0
Version:
125.0.6422.113
Modules
Images
c:\program files\cryptotab browser\application\125.0.6422.113\installer\chrmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2248"C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exe" --system-level --verbose-logging --create-shortcuts=0 --install-level=1C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exesetup.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
HIGH
Description:
CryptoTab Browser Installer
Exit code:
73
Version:
125.0.6422.113
Modules
Images
c:\users\admin\appdata\local\temp\cr_e2800.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2396"C:\Users\admin\AppData\Local\Temp\ctu6808.tmp" --verbose-logging --system-level --enable-autorunC:\Users\admin\AppData\Local\Temp\ctu6808.tmp
CTBrowserSetup.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
HIGH
Description:
CryptoTab Browser Installer
Exit code:
0
Version:
125.0.6422.113
Modules
Images
c:\users\admin\appdata\local\temp\ctu6808.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2424"C:\Program Files\CryptoTab Browser\Application\CryptoTabUpdater.exe" --installC:\Program Files\CryptoTab Browser\Application\CryptoTabUpdater.exe
CTBrowserSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
CryptoTabUpdater
Exit code:
0
Version:
1.0.0.6
Modules
Images
c:\program files\cryptotab browser\application\cryptotabupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcrypt.dll
2824C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --annotation=plat=Win64 "--annotation=prod=CryptoTab Browser" --annotation=ver=125.0.6422.113 --initial-client-data=0x278,0x27c,0x280,0x254,0x284,0x7ff7b91449c0,0x7ff7b91449cc,0x7ff7b91449d8C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exesetup.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
HIGH
Description:
CryptoTab Browser Installer
Exit code:
0
Version:
125.0.6422.113
Modules
Images
c:\users\admin\appdata\local\temp\cr_e2800.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
24 435
Read events
24 204
Write events
223
Delete events
8

Modification events

(PID) Process:(3168) CTBrowserSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3168) CTBrowserSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3168) CTBrowserSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3168) CTBrowserSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_setup
Value:
2.5.4
(PID) Process:(6284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_setup_path
Value:
C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exe
(PID) Process:(6284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_level
Value:
admin
(PID) Process:(2952) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_setup
Value:
2.5.4
(PID) Process:(2952) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_setup_path
Value:
C:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\setup.exe
(PID) Process:(2952) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\CryptoTab Browser
Operation:writeName:current_version_level
Value:
admin
Executable files
11
Suspicious files
462
Text files
532
Unknown types
246

Dropped files

PID
Process
Filename
Type
1128CTBrowserSetup.exeC:\Users\admin\AppData\Local\Temp\ctu6808.tmp
MD5:
SHA256:
2396ctu6808.tmpC:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:3DFCA46E00FFA4795C72A41375F159D3
SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E
6284setup.exeC:\Program Files\CryptoTab Browser\Application\125.0.6422.113\Installer\chrome.7z
MD5:
SHA256:
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A0FA1F65064CF150DE396085518F123Bbinary
MD5:BCDCD02E5C856265C927CA04EE671781
SHA256:EAB6050C4982C4C081303D66F0040D3BEEE0D3BFC2346B80392861FB2DF2B676
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:7FB5FA1534DCF77F2125B2403B30A0EE
SHA256:33A39E9EC2133230533A686EC43760026E014A3828C703707ACBC150FE40FD6F
2396ctu6808.tmpC:\Users\admin\AppData\Local\Temp\CR_E2800.tmp\SETUP.EX_compressed
MD5:218E001A4C957CCFFC680D9222812A24
SHA256:3EEE72568C33729EDAF79D89C8BD7B4996DE8CA10A4CF874B9293BD626C7579B
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A0FA1F65064CF150DE396085518F123Bbinary
MD5:DAD16E6C9F0E217BA6D2499EE560467A
SHA256:D707A4318DD578A6FF79BCC633231257C5BD608ED67081C7F286577440F73936
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:44B77EB2582C7F3200C6739481CBDB32
SHA256:1B697CD17784189D87B4F3DB4BDDBFF9D95C6315DBF575AD54D4F4307920B067
1128CTBrowserSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:971C514F84BBA0785F80AA1C23EDFD79
SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
89
DNS requests
60
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1128
CTBrowserSetup.exe
GET
200
2.19.120.159:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSziYNbJkqGRhEBT7rZV7drew%3D%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6916
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1128
CTBrowserSetup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1128
CTBrowserSetup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
3156
svchost.exe
GET
304
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4340
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5368
SearchApp.exe
2.19.120.29:443
www.bing.com
Akamai International B.V.
DE
unknown
5812
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2616
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 2.19.120.29
  • 2.19.120.21
whitelisted
google.com
  • 142.250.185.206
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.45
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
Process
Message
browser.exe
[0727/061953.153:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\CryptoTab Browser\User Data\Crashpad: The system cannot find the path specified. (0x3)
browser.exe
[0727/061953.168:ERROR:registration_protocol_win.cc(136)] TransactNamedPipe: The pipe has been ended. (0x6D)
browser.exe
[0727/061953.168:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\CryptoTab Browser\User Data\Crashpad: The system cannot find the path specified. (0x3)