download:

EcV01.04.R.exe

Full analysis: https://app.any.run/tasks/398c7d5d-db49-461b-a2d9-25923a3356d3
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: September 29, 2020, 13:36:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
trojan
goldenspy
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

DC363CBC7660992D9642C9F560373375

SHA1:

AB398F6DF5DCC79980C4F04178C5449C6CB30DA6

SHA256:

E596D6AF81ECBB9FB5903C85ECACADE2AA806482FCB6700699E69E676D342B0C

SSDEEP:

98304:GZIBWhFJsEWltJ+UpVvOB7x1TmgAo9HqrRSKNXmsDYkixpi5vuWs5sjSCaOkU:khFJlWlGftx0YPKNXDDziCJuW8C5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • EcV01.04.R.exe (PID: 3420)
      • PluginManagerSetup.exe (PID: 308)
      • PluginSetup.exe (PID: 2480)
      • XYRZSetup.exe (PID: 2996)
      • xyrzsvc.exe (PID: 3356)
      • SignToolSetup.exe (PID: 1720)
      • xyrzsvc.exe (PID: 2408)
      • xyrzsvc.exe (PID: 3896)
      • xyrzsvc.exe (PID: 1432)
      • SignTool.exe (PID: 584)
      • xyrzsvc.exe (PID: 3524)
      • Au_.exe (PID: 3936)
    • Application was dropped or rewritten from another process

      • PluginSetup.exe (PID: 2480)
      • Plugin.exe (PID: 2464)
      • XSDPlugin.exe (PID: 3968)
      • MPlugin.exe (PID: 3768)
      • XSDMPlugin.exe (PID: 2848)
      • MPlugin.exe (PID: 3932)
      • Plugin.exe (PID: 3556)
      • XSDMPlugin.exe (PID: 2052)
      • XSDPlugin.exe (PID: 3380)
      • XYRZSetup.exe (PID: 2996)
      • MPlugin.exe (PID: 340)
      • Plugin.exe (PID: 1992)
      • XSDMPlugin.exe (PID: 3944)
      • XSDPlugin.exe (PID: 2228)
      • SignToolSetup.exe (PID: 1720)
      • xyrzsvc.exe (PID: 2408)
      • xyrzsvc.exe (PID: 3356)
      • xyrzsvc.exe (PID: 3896)
      • xyrzsvc.exe (PID: 1432)
      • SignTool.exe (PID: 584)
      • xyrzsvc.exe (PID: 3524)
      • xyrzsvc.exe (PID: 3544)
      • uninst.exe (PID: 1980)
      • uninst.exe (PID: 2420)
      • uninst.exe (PID: 668)
      • Au_.exe (PID: 3936)
      • uninst.exe (PID: 2980)
      • uninst.exe (PID: 996)
      • uninst.exe (PID: 3344)
      • Au_.exe (PID: 1152)
      • Bu_.exe (PID: 4092)
      • uninst.exe (PID: 3064)
      • uninst.exe (PID: 996)
      • Au_.exe (PID: 2928)
      • Bu_.exe (PID: 3932)
      • Cu_.exe (PID: 3600)
    • Changes the autorun value in the registry

      • SignToolSetup.exe (PID: 1720)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • EcV01.04.R.exe (PID: 3420)
      • PluginManagerSetup.exe (PID: 308)
      • PluginSetup.exe (PID: 2480)
      • Plugin.exe (PID: 1992)
      • XSDPlugin.exe (PID: 2228)
    • Starts itself from another location

      • EcV01.04.R.exe (PID: 3420)
      • uninst.exe (PID: 668)
      • uninst.exe (PID: 3344)
      • uninst.exe (PID: 996)
    • Executable content was dropped or overwritten

      • EcV01.04.R.exe (PID: 3420)
      • PluginSetup.exe (PID: 2480)
      • PluginManagerSetup.exe (PID: 308)
      • XYRZSetup.exe (PID: 2996)
      • SignToolSetup.exe (PID: 1720)
      • uninst.exe (PID: 668)
      • Au_.exe (PID: 3936)
      • uninst.exe (PID: 3344)
      • uninst.exe (PID: 996)
    • Creates a software uninstall entry

      • PluginSetup.exe (PID: 2480)
      • SignToolSetup.exe (PID: 1720)
    • Executed as Windows Service

      • Plugin.exe (PID: 1992)
      • MPlugin.exe (PID: 340)
      • XSDMPlugin.exe (PID: 3944)
      • XSDPlugin.exe (PID: 2228)
      • xyrzsvc.exe (PID: 1432)
    • Creates files in the program directory

      • XYRZSetup.exe (PID: 2996)
      • xyrzsvc.exe (PID: 2408)
      • SignToolSetup.exe (PID: 1720)
      • SignTool.exe (PID: 584)
    • Removes files from Windows directory

      • PluginManagerSetup.exe (PID: 308)
      • EcV01.04.R.exe (PID: 3420)
      • Plugin.exe (PID: 1992)
      • XSDPlugin.exe (PID: 2228)
    • Starts CMD.EXE for commands execution

      • SignToolSetup.exe (PID: 1720)
      • Au_.exe (PID: 3936)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2284)
      • cmd.exe (PID: 2316)
    • Reads Internet Cache Settings

      • SignTool.exe (PID: 584)
    • Changes IE settings (feature browser emulation)

      • AcroRd32.exe (PID: 2780)
    • Application launched itself

      • taskmgr.exe (PID: 2428)
  • INFO

    • Manual execution by user

      • taskmgr.exe (PID: 2428)
      • AcroRd32.exe (PID: 2780)
      • cmd.exe (PID: 3792)
      • cmd.exe (PID: 324)
      • uninst.exe (PID: 3064)
      • uninst.exe (PID: 996)
    • Application launched itself

      • AcroRd32.exe (PID: 2780)
      • RdrCEF.exe (PID: 2768)
    • Reads the hosts file

      • RdrCEF.exe (PID: 2768)
    • Reads Internet Cache Settings

      • AcroRd32.exe (PID: 856)
      • AcroRd32.exe (PID: 2780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:06:18 23:33:23+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x3121
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 18-Jun-2009 21:33:23
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000C8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 18-Jun-2009 21:33:23
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00005A38
0x00005C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.40345
.rdata
0x00007000
0x00001190
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.17961
.data
0x00009000
0x0001AF58
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.61789
.ndata
0x00024000
0x00009000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0002D000
0x00000768
0x00000800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.62083

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.1936
727
UNKNOWN
English - United States
RT_MANIFEST
103
2.16096
20
UNKNOWN
English - United States
RT_GROUP_ICON
111
2.48825
96
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
VERSION.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
114
Monitored processes
53
Malicious processes
8
Suspicious processes
11

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start ecv01.04.r.exe pluginmanagersetup.exe pluginsetup.exe plugin.exe no specs mplugin.exe no specs xsdplugin.exe no specs xsdmplugin.exe no specs plugin.exe no specs mplugin.exe no specs xsdmplugin.exe no specs xsdplugin.exe no specs xyrzsetup.exe plugin.exe mplugin.exe no specs xsdmplugin.exe no specs xsdplugin.exe xyrzsvc.exe no specs xyrzsvc.exe no specs xyrzsvc.exe no specs signtoolsetup.exe xyrzsvc.exe cmd.exe no specs taskkill.exe no specs signtool.exe xyrzsvc.exe no specs xyrzsvc.exe no specs taskmgr.exe no specs acrord32.exe acrord32.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs cmd.exe no specs uninst.exe no specs uninst.exe no specs uninst.exe au_.exe cmd.exe no specs taskkill.exe no specs cmd.exe no specs uninst.exe no specs uninst.exe no specs uninst.exe au_.exe no specs bu_.exe no specs uninst.exe no specs uninst.exe au_.exe no specs bu_.exe no specs cu_.exe no specs taskmgr.exe uninst.exe no specs ecv01.04.r.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Windows\system32\PluginManager\PluginManagerSetup.exe" /S _?=C:\Windows\system32\PluginManagerC:\Windows\system32\PluginManager\PluginManagerSetup.exe
EcV01.04.R.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\pluginmanager\pluginmanagersetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
324"cmd.exe" /s /k pushd "C:\Program Files\XYRZ"C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
340C:\Windows\system32\PluginManager\MPlugin.exeC:\Windows\system32\PluginManager\MPlugin.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\windows\system32\pluginmanager\mplugin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
584"C:\Program Files\SignTool\SignTool.exe"C:\Program Files\SignTool\SignTool.exe
SignToolSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\program files\signtool\signtool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
668"C:\Program Files\SignTool\uninst.exe" /SC:\Program Files\SignTool\uninst.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\signtool\uninst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
856"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Program Files\SignTool\help.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
996"C:\Program Files\XYRZ\uninst.exe" /SC:\Program Files\XYRZ\uninst.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\program files\xyrz\uninst.exe
c:\systemroot\system32\ntdll.dll
996"C:\Program Files\XYRZ\uninst.exe" C:\Program Files\XYRZ\uninst.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\xyrz\uninst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1152"C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Au_.exe" /S _?=C:\Program Files\XYRZ\C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Au_.exeuninst.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225758
Modules
Images
c:\users\admin\appdata\local\temp\~nsu.tmp\au_.exe
c:\systemroot\system32\ntdll.dll
1432"C:\Program Files\XYRZ\xyrzsvc.exe"C:\Program Files\XYRZ\xyrzsvc.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\xyrz\xyrzsvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 394
Read events
1 188
Write events
199
Delete events
7

Modification events

(PID) Process:(2464) Plugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Plugin
Operation:writeName:EventMessageFile
Value:
C:\Windows\system32\PluginManager\Plugin.exe
(PID) Process:(2464) Plugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Plugin
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(3968) XSDPlugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\XSDPlugin
Operation:writeName:EventMessageFile
Value:
C:\Windows\system32\PluginManager\XSDPlugin.exe
(PID) Process:(3968) XSDPlugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\XSDPlugin
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(3768) MPlugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\MPlugin
Operation:writeName:EventMessageFile
Value:
C:\Windows\system32\PluginManager\MPlugin.exe
(PID) Process:(3768) MPlugin.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\MPlugin
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(2480) PluginSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Plugin.exe
Operation:writeName:(default)
Value:
C:\Windows\system32\PluginManager\Plugin.exe
(PID) Process:(2480) PluginSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\²å¼þ¹ÜÀíÈí¼þ
Operation:writeName:DisplayName
Value:
²å¼þ¹ÜÀíÈí¼þ EC.V.1.4.R
(PID) Process:(2480) PluginSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\²å¼þ¹ÜÀíÈí¼þ
Operation:writeName:UninstallString
Value:
C:\Windows\system32\PluginManager\uninst.exe
(PID) Process:(2480) PluginSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\²å¼þ¹ÜÀíÈí¼þ
Operation:writeName:DisplayIcon
Value:
C:\Windows\system32\PluginManager\Plugin.exe
Executable files
43
Suspicious files
6
Text files
43
Unknown types
15

Dropped files

PID
Process
Filename
Type
308PluginManagerSetup.exeC:\Windows\system32\PluginManager\XYRZSetup.exeexecutable
MD5:
SHA256:
308PluginManagerSetup.exeC:\Windows\system32\PluginManager\PluginSetup.exeexecutable
MD5:
SHA256:
3420EcV01.04.R.exeC:\Windows\system32\PluginManager\PluginManagerSetup.exeexecutable
MD5:
SHA256:
3420EcV01.04.R.exeC:\Users\admin\AppData\Local\Temp\nsqAA0D.tmp\processwork.dllexecutable
MD5:0A4FA7A9BA969A805EB0603C7CFE3378
SHA256:27329EA7002D9CE81C8E28E97A5C761922097B33CEDEADA4DB30D2B9D505007C
3420EcV01.04.R.exeC:\Windows\system32\PluginManager\SignToolSetup.exeexecutable
MD5:
SHA256:
2480PluginSetup.exeC:\Windows\system32\PluginManager\Plugin.exeexecutable
MD5:
SHA256:
2480PluginSetup.exeC:\Windows\system32\PluginManager\MPlugin.exeexecutable
MD5:
SHA256:
2480PluginSetup.exeC:\Windows\system32\PluginManager\XSDMPlugin.exeexecutable
MD5:
SHA256:
2480PluginSetup.exeC:\Windows\system32\PluginManager\uninst.exeexecutable
MD5:
SHA256:
2480PluginSetup.exeC:\Windows\system32\PluginManager\XSDPlugin.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
13
DNS requests
10
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2780
AcroRd32.exe
GET
304
2.16.177.50:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277_15_23_20070.zip
unknown
whitelisted
2780
AcroRd32.exe
GET
304
2.16.177.50:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278_15_23_20070.zip
unknown
whitelisted
2228
XSDPlugin.exe
GET
200
60.10.7.133:80
http://upgrade.i-xinnuo.com/contract_sign/client-version/currentxsd?version=XSD.V.1.4.R&retry=0&os=Microsoft%20Windows%207
CN
text
48 b
malicious
584
SignTool.exe
POST
200
60.10.7.137:80
http://ec.i-xinnuo.com/e-contract/checkin/first
CN
text
42 b
malicious
1992
Plugin.exe
GET
200
60.10.7.133:80
http://upgrade.i-xinnuo.com/contract_sign/client-version/current?version=EC.V.1.4.R&retry=0
CN
text
48 b
malicious
1056
svchost.exe
GET
200
104.18.24.243:80
http://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIGkp0%2Fv9GUvNUu1EP06Tu7%2BChyAQUkZ47RGw9V5xCdyo010%2FRzEqXLNoCEyAAASWxwt68EQiA3cUAAAABJbE%3D
US
der
1.75 Kb
whitelisted
1056
svchost.exe
GET
200
216.58.208.35:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D
US
der
492 b
whitelisted
2780
AcroRd32.exe
GET
304
2.16.177.50:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281_15_23_20070.zip
unknown
whitelisted
1056
svchost.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2780
AcroRd32.exe
GET
304
2.16.177.50:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280_15_23_20070.zip
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
584
SignTool.exe
60.10.7.137:80
ec.i-xinnuo.com
CHINA UNICOM China169 Backbone
CN
malicious
1992
Plugin.exe
60.10.7.133:80
upgrade.i-xinnuo.com
CHINA UNICOM China169 Backbone
CN
malicious
2228
XSDPlugin.exe
60.10.7.133:80
upgrade.i-xinnuo.com
CHINA UNICOM China169 Backbone
CN
malicious
2780
AcroRd32.exe
2.16.177.50:80
acroipm2.adobe.com
Akamai International B.V.
unknown
2780
AcroRd32.exe
2.21.36.203:443
armmf.adobe.com
GTT Communications Inc.
FR
suspicious
2780
AcroRd32.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1056
svchost.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1056
svchost.exe
2.16.106.171:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
1056
svchost.exe
2.16.186.120:80
crl.microsoft.com
Akamai International B.V.
whitelisted
1056
svchost.exe
216.58.208.35:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
ec.i-xinnuo.com
  • 60.10.7.137
malicious
upgrade.i-xinnuo.com
  • 60.10.7.133
malicious
acroipm2.adobe.com
  • 2.16.177.50
  • 2.16.177.91
whitelisted
armmf.adobe.com
  • 2.21.36.203
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl.microsoft.com
  • 2.16.186.120
  • 2.16.186.74
whitelisted
ocsp.msocsp.com
  • 104.18.24.243
  • 104.18.25.243
whitelisted
ocsp.pki.goog
  • 216.58.208.35
whitelisted
www.microsoft.com
  • 2.21.38.54
whitelisted
www.download.windowsupdate.com
  • 2.16.106.171
  • 2.16.106.186
whitelisted

Threats

PID
Process
Class
Message
584
SignTool.exe
A Network Trojan was detected
MALWARE [PTsecurity] Tiggre
584
SignTool.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (Http-connect)
1992
Plugin.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (Http-connect)
1992
Plugin.exe
Misc activity
SUSPICIOUS [PTsecurity] HTTP GET method with http_client_body (RFC7231)
1992
Plugin.exe
Misc activity
ADWARE [PTsecurity] PluginManager.C.component
2228
XSDPlugin.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (Http-connect)
2228
XSDPlugin.exe
Misc activity
SUSPICIOUS [PTsecurity] HTTP GET method with http_client_body (RFC7231)
2228
XSDPlugin.exe
Misc activity
ADWARE [PTsecurity] PluginManager.C.component
Process
Message
xyrzsvc.exe
´´½¨³É¹¦
xyrzsvc.exe
»ñȡʧ°Ü
xyrzsvc.exe
»ñȡʧ°Ü
xyrzsvc.exe
´ò¿ª³É¹¦
xyrzsvc.exe
дע²á±í³É¹¦
xyrzsvc.exe
´ò¿ª³É¹¦
xyrzsvc.exe
´ò¿ª³É¹¦
xyrzsvc.exe
¹Ø±Õ³É¹¦
SignTool.exe
¹Ø±Õ³É¹¦
SignTool.exe
»ñÈ¡³É¹¦