File name:

CTBrowserSetup_CQgou0Geym.exe

Full analysis: https://app.any.run/tasks/2e669b3a-530c-476e-a715-c17ca210752b
Verdict: Malicious activity
Analysis date: February 17, 2024, 22:06:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

A0FAB21C52FB92A79BC492D2EB91D1D6

SHA1:

03D14DA347C554669916D60E24BEE1B540C2822E

SHA256:

E10F9D22CDBC39874CE875FD8031C3DB26F58DAF20EE8AE6A82DE9ED2DFC7863

SSDEEP:

49152:VaFSMmQsOZgebSEjpj24R76kPmDzgsnQnddt4FwR+Viv6WwJrY701QnE60:VOCJEnj26ukshQnnYVWcy0GE60

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • ctuAA37.tmp (PID: 3996)
      • setup.exe (PID: 2408)
    • Changes the autorun value in the registry

      • setup.exe (PID: 2408)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
    • Application launched itself

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • setup.exe (PID: 2408)
      • setup.exe (PID: 2364)
      • browser.exe (PID: 2724)
      • browser.exe (PID: 1768)
      • chrmstp.exe (PID: 3320)
      • chrmstp.exe (PID: 3376)
    • Reads the Internet Settings

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • browser.exe (PID: 1768)
      • CryptoTabUpdater.exe (PID: 2240)
    • Reads settings of System Certificates

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • CryptoTabUpdater.exe (PID: 2240)
      • browser.exe (PID: 1768)
    • Adds/modifies Windows certificates

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
    • Executable content was dropped or overwritten

      • ctuAA37.tmp (PID: 3996)
      • setup.exe (PID: 2408)
    • Creates a software uninstall entry

      • setup.exe (PID: 2408)
    • Checks Windows Trust Settings

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
    • Starts application with an unusual extension

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
    • Searches for installed software

      • setup.exe (PID: 2408)
    • Reads the date of Windows installation

      • setup.exe (PID: 2364)
      • chrmstp.exe (PID: 3320)
    • Connects to unusual port

      • browser.exe (PID: 2468)
  • INFO

    • Checks supported languages

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • setup.exe (PID: 2408)
      • setup.exe (PID: 2908)
      • ctuAA37.tmp (PID: 3996)
      • setup.exe (PID: 2364)
      • browser.exe (PID: 1768)
      • browser.exe (PID: 2724)
      • setup.exe (PID: 2440)
      • browser.exe (PID: 2468)
      • browser.exe (PID: 1308)
      • CryptoTabUpdater.exe (PID: 2240)
      • browser.exe (PID: 1544)
      • browser.exe (PID: 984)
      • browser.exe (PID: 3504)
      • browser.exe (PID: 1036)
      • browser.exe (PID: 1124)
      • browser.exe (PID: 3052)
      • browser.exe (PID: 2268)
      • browser.exe (PID: 908)
      • browser.exe (PID: 1484)
      • browser.exe (PID: 2808)
      • chrmstp.exe (PID: 2612)
      • chrmstp.exe (PID: 3320)
      • browser.exe (PID: 3412)
      • chrmstp.exe (PID: 3396)
      • browser.exe (PID: 3080)
      • chrmstp.exe (PID: 3376)
      • browser.exe (PID: 2160)
      • browser.exe (PID: 1168)
      • browser.exe (PID: 3764)
      • browser.exe (PID: 1092)
      • browser.exe (PID: 3732)
      • browser.exe (PID: 2576)
      • browser.exe (PID: 1796)
      • browser.exe (PID: 3312)
      • browser.exe (PID: 2376)
      • browser.exe (PID: 3836)
      • browser.exe (PID: 3956)
      • browser.exe (PID: 2532)
      • browser.exe (PID: 3852)
      • browser.exe (PID: 3928)
      • browser.exe (PID: 1192)
      • browser.exe (PID: 2056)
      • browser.exe (PID: 1040)
      • browser.exe (PID: 2564)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 2100)
      • browser.exe (PID: 3072)
      • browser.exe (PID: 3324)
      • browser.exe (PID: 932)
      • browser.exe (PID: 3992)
      • browser.exe (PID: 1544)
      • browser.exe (PID: 3376)
      • browser.exe (PID: 2764)
      • browser.exe (PID: 4016)
      • browser.exe (PID: 1812)
      • browser.exe (PID: 1836)
      • browser.exe (PID: 2624)
      • browser.exe (PID: 2800)
      • browser.exe (PID: 3884)
      • browser.exe (PID: 2988)
      • browser.exe (PID: 2512)
      • browser.exe (PID: 3212)
      • browser.exe (PID: 4012)
      • browser.exe (PID: 2208)
    • Reads the computer name

      • CTBrowserSetup_CQgou0Geym.exe (PID: 3864)
      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • setup.exe (PID: 2408)
      • ctuAA37.tmp (PID: 3996)
      • browser.exe (PID: 1768)
      • browser.exe (PID: 2724)
      • setup.exe (PID: 2364)
      • CryptoTabUpdater.exe (PID: 2240)
      • browser.exe (PID: 2268)
      • browser.exe (PID: 2468)
      • browser.exe (PID: 1544)
      • chrmstp.exe (PID: 3376)
      • chrmstp.exe (PID: 3320)
      • browser.exe (PID: 3052)
      • browser.exe (PID: 3212)
    • Reads the machine GUID from the registry

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • setup.exe (PID: 2364)
      • setup.exe (PID: 2408)
      • browser.exe (PID: 1768)
      • CryptoTabUpdater.exe (PID: 2240)
      • browser.exe (PID: 3052)
      • chrmstp.exe (PID: 3320)
      • browser.exe (PID: 3212)
    • Create files in a temporary directory

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • ctuAA37.tmp (PID: 3996)
      • browser.exe (PID: 1768)
    • Creates files or folders in the user directory

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • setup.exe (PID: 2364)
      • browser.exe (PID: 1768)
      • CryptoTabUpdater.exe (PID: 2240)
      • browser.exe (PID: 2468)
      • chrmstp.exe (PID: 3320)
    • Creates files in the program directory

      • setup.exe (PID: 2408)
      • setup.exe (PID: 2364)
      • browser.exe (PID: 1768)
      • chrmstp.exe (PID: 3320)
      • chrmstp.exe (PID: 3376)
    • Reads the software policy settings

      • CTBrowserSetup_CQgou0Geym.exe (PID: 2840)
      • CryptoTabUpdater.exe (PID: 2240)
    • Process checks computer location settings

      • browser.exe (PID: 1768)
      • browser.exe (PID: 3504)
      • browser.exe (PID: 2808)
      • browser.exe (PID: 984)
      • browser.exe (PID: 1036)
      • browser.exe (PID: 3732)
      • browser.exe (PID: 1192)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 1544)
      • browser.exe (PID: 2512)
      • browser.exe (PID: 1836)
      • browser.exe (PID: 3884)
      • browser.exe (PID: 2624)
      • browser.exe (PID: 2800)
      • browser.exe (PID: 2988)
      • browser.exe (PID: 4012)
      • browser.exe (PID: 2208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:01 13:16:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2789376
InitializedDataSize: 36864
UninitializedDataSize: 7159808
EntryPoint: 0x97d680
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.6
ProductVersionNumber: 1.0.0.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: CryptoTabInstaller
FileVersion: 1.0.0.6
LegalCopyright: Copyright (C) CRYPTOCOMPANY OU 2023
ProductName: CryptoTabInstaller
ProductVersion: 1.0.0.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
66
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ctbrowsersetup_cqgou0geym.exe no specs ctbrowsersetup_cqgou0geym.exe ctuaa37.tmp setup.exe setup.exe no specs setup.exe no specs setup.exe no specs browser.exe browser.exe browser.exe cryptotabupdater.exe browser.exe no specs browser.exe browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs chrmstp.exe no specs browser.exe no specs chrmstp.exe no specs chrmstp.exe no specs browser.exe no specs chrmstp.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
908"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3764 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
932"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4308 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2084 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:1C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1036"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3120 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:1C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1040"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4500 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1092"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4312 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1124"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3364 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1168"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3756 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:8C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1192"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=renderer --extension-process --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --mojo-platform-channel-handle=4612 --field-trial-handle=1260,i,16642817876665306854,15613879992211033935,131072 /prefetch:1C:\Program Files\CryptoTab Browser\Application\browser.exebrowser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
LOW
Description:
CryptoTab Browser
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1308"C:\Program Files\CryptoTab Browser\Application\browser.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\CryptoTab Browser\User Data" /prefetch:7 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\CryptoTab Browser\User Data\Crashpad" --annotation=plat=Win32 "--annotation=prod=CryptoTab Browser" --annotation=ver=109.0.5414.120 --initial-client-data=0x110,0x114,0x118,0xe4,0x11c,0x1554488,0x1554498,0x15544a4C:\Program Files\CryptoTab Browser\Application\browser.exe
browser.exe
User:
admin
Company:
The Chromium and CryptoTab Browser Authors
Integrity Level:
HIGH
Description:
CryptoTab Browser
Exit code:
1
Version:
109.0.5414.120
Modules
Images
c:\program files\cryptotab browser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\cryptotab browser\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
21 498
Read events
21 193
Write events
292
Delete events
13

Modification events

(PID) Process:(3864) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3864) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3864) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3864) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:CABD2A79A1076A31F21D253635CB039D4329A5E8
Value:
(PID) Process:(2840) CTBrowserSetup_CQgou0Geym.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Operation:writeName:Blob
Value:
0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
Executable files
13
Suspicious files
297
Text files
688
Unknown types
169

Dropped files

PID
Process
Filename
Type
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\Local\Temp\ctuAA37.tmp
MD5:
SHA256:
3996ctuAA37.tmpC:\Users\admin\AppData\Local\Temp\CR_0AAF6.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2408setup.exeC:\Program Files\CryptoTab Browser\Application\109.0.5414.120\Installer\chrome.7z
MD5:
SHA256:
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\Local\Temp\CabA7A5.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1495DD322A24490E2BF2FAABAE1C61binary
MD5:9AD2506CBF3E22953F48DD3A79EAC333
SHA256:52B255FE31E3D203E566240171D6B485F437BB919C9465BA46B624D9C413A86A
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\42CBB751D19F01A0756C9CBFF8AD6022binary
MD5:44344689C81D00AEF2DC75A0313F05E6
SHA256:6EC609E9A67A8B4F9953F5336B971B0EB8E60BE240C8D3D602136F8338F951E2
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:0CD42D475573C5B1B257B83E80FDC2BF
SHA256:46357E446629C05890D5486CC58B9B2D4CEA3C83F18EBE71B7056E348F017C85
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:199B1F37500D50AF16E8B753A69FECED
SHA256:6B97A4A4869DF652D9480491B7B0590FB79BAEB5054DEF7D30BD67BDDF5266AD
2840CTBrowserSetup_CQgou0Geym.exeC:\Users\admin\AppData\Local\Temp\TarA7A6.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
85
DNS requests
87
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2840
CTBrowserSetup_CQgou0Geym.exe
GET
304
178.79.238.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?03671427bed3c3b1
unknown
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
GET
200
69.192.161.44:80
http://x2.c.lencr.org/
unknown
binary
299 b
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
GET
200
95.101.54.106:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgToyGJ8lZcFshRoxqpnZXZ6AA%3D%3D
unknown
binary
503 b
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
GET
200
178.79.238.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6e523478e18dad91
unknown
compressed
65.2 Kb
unknown
2468
browser.exe
GET
200
172.217.16.206:80
http://clients2.google.com/time/1/current?cup2key=6:y7OKLIQsTerTo7pvas3q-ns1Alb7rmrgPXcYdrsLzXs&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
text
106 b
unknown
2468
browser.exe
GET
200
172.217.16.206:80
http://clients2.google.com/time/1/current?cup2key=6:0S2euPxuYni6xll4wUt_8L8DIwm_D9HNxf-j2cB1y2s&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
text
103 b
unknown
2240
CryptoTabUpdater.exe
GET
200
95.101.54.203:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOd8%2F6HvUcUw7YFSjO%2BKTLPqw%3D%3D
unknown
binary
503 b
unknown
2468
browser.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
unknown
binary
242 Kb
unknown
2468
browser.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
unknown
binary
242 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2840
CTBrowserSetup_CQgou0Geym.exe
185.173.160.142:443
update.cryptotabrowser.net
WorldStream B.V.
NL
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
178.79.238.128:80
ctldl.windowsupdate.com
LLNW
FR
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
95.101.54.106:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
188.114.97.3:443
dl.cryptotabrowser.net
CLOUDFLARENET
NL
unknown
2840
CTBrowserSetup_CQgou0Geym.exe
69.192.161.44:80
x2.c.lencr.org
AKAMAI-AS
DE
unknown
2240
CryptoTabUpdater.exe
185.173.160.142:443
update.cryptotabrowser.net
WorldStream B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
update.cryptotabrowser.net
  • 185.173.160.142
unknown
ctldl.windowsupdate.com
  • 178.79.238.128
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 95.101.54.106
  • 95.101.54.107
  • 95.101.54.114
  • 95.101.54.130
  • 95.101.54.203
  • 95.101.54.208
  • 2.16.202.123
shared
dl.cryptotabrowser.net
  • 188.114.97.3
  • 188.114.96.3
unknown
x2.c.lencr.org
  • 69.192.161.44
whitelisted
update.cryptobrowser.site
  • 185.173.160.143
  • 185.173.160.142
unknown
update.cryptobrowser.today
  • 185.173.160.142
  • 185.173.160.143
unknown
clients2.google.com
  • 172.217.16.206
whitelisted
redirector.gvt1.com
  • 142.250.185.206
whitelisted

Threats

No threats detected
Process
Message
browser.exe
[0217/220805.844:ERROR:crash_report_database_win.cc(614)] CreateDirectory C:\Users\admin\AppData\Local\CryptoTab Browser\User Data\Crashpad: The system cannot find the path specified. (0x3)
browser.exe
[0217/220805.844:ERROR:registration_protocol_win.cc(135)] TransactNamedPipe: The pipe has been ended. (0x6D)
browser.exe
[0217/220805.844:ERROR:crash_report_database_win.cc(614)] CreateDirectory C:\Users\admin\AppData\Local\CryptoTab Browser\User Data\Crashpad: The system cannot find the path specified. (0x3)