| download: | epicsetup.exe |
| Full analysis: | https://app.any.run/tasks/dd6e7d6c-66a6-4954-a199-7f91720df9d3 |
| Verdict: | Malicious activity |
| Analysis date: | June 04, 2018, 12:57:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 607B6DA10B6DDB74610D8FD72AC85ADC |
| SHA1: | C76FABD1ABDDFCD7BD9307C04685674F009BBC6D |
| SHA256: | E46853CAAF6ADF679F3BDB116761AA7EF199F148641CFF7EC9D76FD67EF5305F |
| SSDEEP: | 49152:9aECKpr/+dFlBRdngJI1YRKa8YuYnlVobKb:sEt/+dXBRdngGa8UnlVoOb |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:05:24 11:16:53+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 333312 |
| InitializedDataSize: | 1491968 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1000 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.27.13 |
| ProductVersionNumber: | 1.3.27.13 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug, Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Epic Privacy Browser |
| FileDescription: | Epic Privacy Browser Installer Setup |
| FileVersion: | 1.3.27.13 |
| InternalName: | Epic Privacy Browser Installer Setup |
| LegalCopyright: | Copyright 2007-2010 Google Inc. |
| OriginalFileName: | EpicUpdateSetup.exe |
| ProductName: | Epic Privacy Browser Installer |
| ProductVersion: | 1.3.27.13 |
| LanguageId: | en |
| Debug: | - |
| PrivateBuild: | - |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 24-May-2017 09:16:53 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Epic Privacy Browser |
| FileDescription: | Epic Privacy Browser Installer Setup |
| FileVersion: | 1.3.27.13 |
| InternalName: | Epic Privacy Browser Installer Setup |
| LegalCopyright: | Copyright 2007-2010 Google Inc. |
| OriginalFilename: | EpicUpdateSetup.exe |
| ProductName: | Epic Privacy Browser Installer |
| ProductVersion: | 1.3.27.13 |
| LanguageId: | en |
| Debug: | - |
| PrivateBuild: | - |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 24-May-2017 09:16:53 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00051561 | 0x00051600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.20794 |
.rdata | 0x00053000 | 0x00010FEC | 0x00011000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.47829 |
.data | 0x00064000 | 0x00002EFC | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.42225 |
.rsrc | 0x00067000 | 0x001562D0 | 0x00156400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99021 |
.reloc | 0x001BE000 | 0x00003C28 | 0x00003E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.64679 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.09285 | 738 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 4.13669 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.91985 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.83772 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 3.68656 | 1640 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 4.50268 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
101 | 2.86669 | 90 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
102 | 7.99988 | 1369007 | Latin 1 / Western European | UNKNOWN | B |
1321 | 3.64009 | 422 | Latin 1 / Western European | Serbian - Serbia (Cyrillic) | RT_STRING |
ADVAPI32.dll |
KERNEL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 340 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe" /uninstall | C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe | EpicUpdate.exe | ||||||||||||
User: admin Company: Epic Privacy Browser Integrity Level: MEDIUM Description: Epic Privacy Browser Installer Exit code: 0 Version: 1.3.27.13 Modules
| |||||||||||||||
| 708 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=renderer --field-trial-handle=1624 --primordial-pipe-token=B4D6FBF118101B5B65E29B801F7A4120 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,parseHTMLOnMainThreadCoalesceChunks=false,parseHTMLOnMainThreadSyncTokenize=false,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=B4D6FBF118101B5B65E29B801F7A4120 --renderer-client-id=20 --mojo-platform-channel-handle=5356 /prefetch:1 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 1360 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=renderer --field-trial-handle=1624 --primordial-pipe-token=231C7C8D79772BCD7DC51DE02CA5048D --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,parseHTMLOnMainThreadCoalesceChunks=false,parseHTMLOnMainThreadSyncTokenize=false,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=231C7C8D79772BCD7DC51DE02CA5048D --renderer-client-id=3 --mojo-platform-channel-handle=1640 /prefetch:1 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 1968 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=renderer --field-trial-handle=1624 --primordial-pipe-token=EEF580DBC96FACB1E997D0D303D5CCB8 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,parseHTMLOnMainThreadCoalesceChunks=false,parseHTMLOnMainThreadSyncTokenize=false,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=EEF580DBC96FACB1E997D0D303D5CCB8 --renderer-client-id=23 --mojo-platform-channel-handle=2876 /prefetch:1 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 2092 | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdate.exe /installsource taggedmi /install "appguid={A3AA2AD6-C357-4BB3-9625-6550647D956D}&appname=Epic&needsadmin=False&lang=en" | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdate.exe | epicsetup.exe | ||||||||||||
User: admin Company: Epic Privacy Browser Integrity Level: MEDIUM Description: Epic Privacy Browser Installer Exit code: 0 Version: 1.3.27.13 Modules
| |||||||||||||||
| 2168 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=renderer --field-trial-handle=1624 --primordial-pipe-token=11647314868B9CF6B2853C3957BE6352 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,parseHTMLOnMainThreadCoalesceChunks=false,parseHTMLOnMainThreadSyncTokenize=false,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=11647314868B9CF6B2853C3957BE6352 --renderer-client-id=18 --mojo-platform-channel-handle=4428 /prefetch:1 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 2192 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=renderer --field-trial-handle=1624 --primordial-pipe-token=A6911BD7BBC6F594978CA22B584A0AEA --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,parseHTMLOnMainThreadCoalesceChunks=false,parseHTMLOnMainThreadSyncTokenize=false,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=A6911BD7BBC6F594978CA22B584A0AEA --renderer-client-id=4 --mojo-platform-channel-handle=1752 /prefetch:1 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 2196 | C:\Users\admin\AppData\Local\Temp\CR_8023B.tmp\setup.exe --type=crashpad-handler /prefetch:7 "--database=C:\Users\admin\AppData\Local\Epic Privacy Browser\User Data\Crashpad" --annotation=channel= --annotation=plat=Win32 --annotation=prod=Epic --annotation=ver=62.0.3202.94 --initial-client-data=0xf0,0xf4,0xf8,0xe4,0x100,0xce92f0,0xce9300,0xce9310 | C:\Users\admin\AppData\Local\Temp\CR_8023B.tmp\setup.exe | — | setup.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: MEDIUM Description: Epic Privacy Browser Installer Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 2328 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=utility --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir_3828_21704" --service-request-channel-token=8A7BA942B22A6BDBDD6925C26A05120C --mojo-platform-channel-handle=2944 --ignored=" --type=renderer " /prefetch:8 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| 2396 | "C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe" --type=utility --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir_3828_24051" --service-request-channel-token=49ABBBF5FA6ACC6820FF66E1F2C271BE --mojo-platform-channel-handle=2848 --ignored=" --type=renderer " /prefetch:8 | C:\Users\admin\AppData\Local\Epic Privacy Browser\Application\epic.exe | — | epic.exe | |||||||||||
User: admin Company: Hidden Reflex Authors Integrity Level: LOW Description: Epic Privacy Bowser Exit code: 0 Version: 62.0.3202.94 Modules
| |||||||||||||||
| (PID) Process: | (2092) EpicUpdate.exe | Key: | HKEY_CURRENT_USER\Software\Epic Privacy Browser\Installer |
| Operation: | write | Name: | path |
Value: C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe | |||
| (PID) Process: | (2092) EpicUpdate.exe | Key: | HKEY_CURRENT_USER\Software\Epic Privacy Browser\Installer\Clients\{B852E7B1-908A-48EF-9576-CBE23654D907} |
| Operation: | write | Name: | pv |
Value: 1.3.27.13 | |||
| (PID) Process: | (2092) EpicUpdate.exe | Key: | HKEY_CURRENT_USER\Software\Epic Privacy Browser\Installer\Clients\{B852E7B1-908A-48EF-9576-CBE23654D907} |
| Operation: | write | Name: | name |
Value: Epic Update | |||
| (PID) Process: | (2092) EpicUpdate.exe | Key: | HKEY_CURRENT_USER\Software\Epic Privacy Browser\Installer\ClientState\{B852E7B1-908A-48EF-9576-CBE23654D907} |
| Operation: | write | Name: | pv |
Value: 1.3.27.13 | |||
| (PID) Process: | (2092) EpicUpdate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Epic Privacy Browser Installer |
Value: "C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe" /c | |||
| (PID) Process: | (2756) EpicUpdate.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{82610E6D-11CA-45A9-98B1-D03B9AEDBD13}\InprocHandler32 |
| Operation: | write | Name: | |
Value: C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\psuser.dll | |||
| (PID) Process: | (2756) EpicUpdate.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{82610E6D-11CA-45A9-98B1-D03B9AEDBD13}\InprocHandler32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (2756) EpicUpdate.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{84D964EE-0441-4A42-8146-0699AE05DDC3}\InprocServer32 |
| Operation: | write | Name: | |
Value: C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\psuser.dll | |||
| (PID) Process: | (2756) EpicUpdate.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{84D964EE-0441-4A42-8146-0699AE05DDC3}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (2756) EpicUpdate.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{9BA04732-4369-45EF-9DA1-90561134DE6D}\InProcServer32 |
| Operation: | write | Name: | |
Value: C:\Users\admin\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\psuser.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdateHelper.msi | executable | |
MD5:A39C5B57BB946852A41B21F540D54D2B | SHA256:E4207DAC538CEE89A84776482EECBF19F9F06ED2A75C6898D195B3183AE8B913 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdateBroker.exe | executable | |
MD5:E2C11186B9373FBC8D0F8C301BD5B867 | SHA256:117EC60AA324B6D0719B1FFBD70E346B1892C0A30A51B4FAC63ADEE8D120B6EA | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdate.exe | executable | |
MD5:BA86A3AD65404FC5E08078A638611F52 | SHA256:A722FA6E47F612DAE6A3B90838843A9ADD4AF52BF5E19ED025F9DF5332E444B9 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdate.dll | executable | |
MD5:AA8C6DB4925ADF7B02FF646E2A8D744F | SHA256:D9359E17DC24D47EFF57799DACF56401ADD24C34029048C905416AF6A2C182E3 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\psmachine.dll | executable | |
MD5:456547F13C9082D512E65BD73D1E306E | SHA256:5A7A95FBE52B34EDB6575170EBF11FC5A28BC892F763A7C6EF1882E90399D217 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdateres_ca.dll | executable | |
MD5:539724F4C4F6D0F6EEE4407F988162B9 | SHA256:A489173A0E13472FA212A96CAB4D7BC85254DB77F3CB1E5B29022588C5896D42 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdateres_bg.dll | executable | |
MD5:B808250A6900087DEFF5D2C585DE19FB | SHA256:33E24FC64C6EBD8EC5E97C1D8BEC88B0C6353A1551D526BFB0705DA555DE4FF0 | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdateres_ar.dll | executable | |
MD5:E9B4909C22C80AFF9E6A3948BA9F0A96 | SHA256:B5ECFD924F970165553B56EEBFC5BB898D54A39D1FDC93ADCFB372FACA44963A | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdateres_da.dll | executable | |
MD5:7D7861258E18A1FF34B49D354186757F | SHA256:8E503CD5A1807A82000AEA70ABC119C442216EAE4206B218F1B998A0C6F375FD | |||
| 3744 | epicsetup.exe | C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdateres_en.dll | executable | |
MD5:E80AF7A0FB03C11C3A325A832CE59F70 | SHA256:DFA59C2A8DFDDCFED059D611A3344892AFD2E0D4CE206B1396204BE75311770E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2568 | EpicUpdate.exe | POST | 200 | 128.199.39.15:80 | http://updates.epicbrowser.com/service/update2?w=3:DGB34g3mS2HClCDPKKv9qg-Mq4-nsoW-iBDZk9uzxWTm3oIzxpYt6vgllb9_p8x-ArYJmzRwm_CXm_b4UgJF4ziN6m4CyZp2LRxTkVi4KNXLzDaAzTlQocIKhJsmVJZVjs0eEC5wzV4_RHftbSevdtg6wSqRuQof_u6TnOH8uuQ | NL | xml | 869 b | whitelisted |
3828 | epic.exe | GET | 200 | 206.189.4.63:80 | http://updates.epicbrowser.com/extensions/newtab/newAdd.html | US | html | 729 b | whitelisted |
3828 | epic.exe | GET | 200 | 178.255.83.1:80 | http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBT0MXB3rveIElndnl0j8v4md2bQRgQUOdr%2FyigUiqh0Ewi55A6p0vp%2BnWkCEQCc%2FEFPFPMmH0T4XM1RpOGH | GB | der | 472 b | whitelisted |
3068 | EpicUpdate.exe | POST | 200 | 128.199.39.15:80 | http://updates.epicbrowser.com/service/update2 | NL | xml | 352 b | whitelisted |
3828 | epic.exe | GET | 200 | 178.255.83.1:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D | GB | der | 471 b | whitelisted |
— | — | GET | 200 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 52.5 Kb | whitelisted |
3576 | EpicUpdate.exe | GET | 404 | 128.199.39.15:80 | http://updates.epicbrowser.com/service/check2?appid=%7BB852E7B1-908A-48EF-9576-CBE23654D907%7D&appversion=1.3.27.13&applang=&machine=0&version=0.0.0.0&osversion=6.1&servicepack=Service%20Pack%201 | NL | html | 2.74 Kb | whitelisted |
3828 | epic.exe | GET | 200 | 178.255.83.1:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEAanQ4DU6%2F7UNbWj9%2BFqvdg%3D | GB | der | 727 b | whitelisted |
— | — | GET | 200 | 192.35.177.64:80 | http://apps.identrust.com/roots/dstrootcax3.p7c | US | cat | 893 b | shared |
2568 | EpicUpdate.exe | GET | 200 | 104.16.89.188:80 | http://crt.comodoca.com/COMODORSAAddTrustCA.crt | US | der | 1.37 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3068 | EpicUpdate.exe | 128.199.39.15:80 | updates.epicbrowser.com | Digital Ocean, Inc. | NL | unknown |
3576 | EpicUpdate.exe | 128.199.39.15:80 | updates.epicbrowser.com | Digital Ocean, Inc. | NL | unknown |
2568 | EpicUpdate.exe | 104.16.89.188:80 | crt.comodoca.com | Cloudflare Inc | US | shared |
3828 | epic.exe | 216.58.214.116:443 | chromium-i18n.appspot.com | Google Inc. | US | whitelisted |
3828 | epic.exe | 82.196.2.74:443 | epicbrowser.com | Digital Ocean, Inc. | NL | unknown |
3828 | epic.exe | 206.189.4.63:80 | updates.epicbrowser.com | — | US | unknown |
3828 | epic.exe | 216.58.208.46:443 | clients1.google.com | Google Inc. | US | whitelisted |
— | — | 62.113.194.2:443 | cdn.epicbrowser.com | 23media GmbH | DE | malicious |
— | — | 192.35.177.64:80 | apps.identrust.com | IdenTrust | US | malicious |
3624 | EpicUpdate.exe | 128.199.39.15:80 | updates.epicbrowser.com | Digital Ocean, Inc. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.epicbrowser.com |
| whitelisted |
crt.comodoca.com |
| whitelisted |
cdn.epicbrowser.com |
| malicious |
apps.identrust.com |
| shared |
www.download.windowsupdate.com |
| whitelisted |
www.google.com |
| malicious |
epicbrowser.com |
| unknown |
chromium-i18n.appspot.com |
| whitelisted |
www.epicbrowser.com |
| unknown |
translate.googleapis.com |
| whitelisted |
Process | Message |
|---|---|
EpicUpdate.exe | LOG_SYSTEM: [EpicUpdate:goopdate]: ERROR - Cannot create ETW log writer |
EpicUpdate.exe | [06/04/18 13:57:49.542][EpicUpdate:goopdate][2092:2060][OS][version: OS_WINDOWS_7][service pack: 1]
|
EpicUpdate.exe | [06/04/18 13:57:49.542][EpicUpdate:goopdate][2092:2060][GetNamedObjectAttributes][named_object=Global\ES-1-5-21-1302019708-1500728564-335382590-1000_Epic Privacy Browser_Installer_Report_Ids_Lock_57146B01-6A07-4b8d-A1D8-0C3AFC3B2F9B]
|
EpicUpdate.exe | [06/04/18 13:57:49.542][EpicUpdate:goopdate][2092:2060][DllEntry][C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\EpicUpdate.exe /installsource taggedmi /install "appguid={A3AA2AD6-C357-4BB3-9625-6550647D956D}&appname=Epic&needsadmin=False&lang=en"]
|
EpicUpdate.exe | [06/04/18 13:57:49.542][EpicUpdate:goopdate][2092:2060][Goopdate::Goopdate]
|
EpicUpdate.exe | [06/04/18 13:57:49.542][EpicUpdate:goopdate][2092:2060][Crash::InstallCrashHandler][is_machine 0]
|
EpicUpdate.exe | [06/04/18 13:57:49.557][EpicUpdate:goopdate][2092:2060][crash dir C:\Users\admin\AppData\Local\Epic Privacy Browser\CrashReports]
|
EpicUpdate.exe | [06/04/18 13:57:49.557][EpicUpdate:goopdate][2092:2060][exception handler has been installed]
|
EpicUpdate.exe | [06/04/18 13:57:49.557][EpicUpdate:goopdate][2092:2060][ThreadPool::ThreadPool]
|
EpicUpdate.exe | [06/04/18 13:57:49.557][EpicUpdate:goopdate][2092:2060][C:\Users\admin\AppData\Local\Temp\GUMFFEF.tmp\goopdate.dll][version 1.3.27.13][dbg][dev]
|