| URL: | https://sadownload.mcafee.com/products/SA/v1/update/win/build/4.1.1.866/64/wataskmanager.cab |
| Full analysis: | https://app.any.run/tasks/1f2be783-5d60-4e0c-b4b8-d9f98e919295 |
| Verdict: | Malicious activity |
| Analysis date: | March 07, 2024, 17:24:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 291FBA7D875A3C3847921A81BDD3946A |
| SHA1: | 92D7C1B7B3CD827AFD62A24FD180FF56DA47F401 |
| SHA256: | E66A3CC7C4727B8CEC74CF7F85757BEC59C7B2F2C4F0969172161BA0D443D4B7 |
| SSDEEP: | 3:N8J8El3AyKIOXaQGRWWIU93w1LSc4KSE1LXH:2yK5KIRRWBUZ+SehXH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver | C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 1644 | "C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true" /installsource taggedmi /sessionid "{22DCF746-9C27-4795-A715-DBF05857300F}" | C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 2044 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3864 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2364 | "C:\Users\admin\AppData\Local\Temp\EU508C.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\EU508C.tmp\MicrosoftEdgeUpdateSetup.exe | MicrosoftEdgeUpdate.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Setup Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 2440 | "C:\Program Files\Microsoft\Temp\EU552F.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true" /installelevated | C:\Program Files\Microsoft\Temp\EU552F.tmp\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeUpdateSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 2832 | "C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNDEuNjMiIHNoZWxsX3ZlcnNpb249IjEuMy4xNDEuNjMiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MjJEQ0Y3NDYtOUMyNy00Nzk1LUE3MTUtREJGMDU4NTczMDBGfSIgdXNlcmlkPSJ7NEQ1RjZBQTEtOEYyNS00RDZBLUI1MzAtMjI1NjhFOEM0RkNCfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezNFNDRCRDMwLUU3MEQtNDQyMS1BMjExLTNFNkMzRUI4OTM0Rn0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IjEuMy4xNzUuMjkiIG5leHR2ZXJzaW9uPSIxLjMuMTQxLjYzIiBsYW5nPSIiIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9Ijc4MSIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | MicrosoftEdgeUpdate.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 3276 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.31117\microsoftedgewebview2setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.31117\microsoftedgewebview2setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 3324 | "C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc | C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 3684 | "C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc | C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Exit code: 0 Version: 1.3.141.63 Modules
| |||||||||||||||
| 3864 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://sadownload.mcafee.com/products/SA/v1/update/win/build/4.1.1.866/64/wataskmanager.cab" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31092916 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31092916 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_AE91539AB0CE5822066147077CD4AD95 | binary | |
MD5:13A80824D09D7E618ABFCA0C3AB59581 | SHA256:642EABC0F1A7963D03C5F2561B3381DA68D4ADCDDC9C326DA2ECD36FAD18756D | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:5EC90F7E83DCEDCDD37198187FFF1D2B | SHA256:5F8B6ECCC716BBF52DAAD58559E3FD4D8480D30AC61F0B95AE6240E73D076986 | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5C8CC0A7FE31816B4641D0465402560 | binary | |
MD5:908FA32319E8FF25C0FAC3D158DFBDD6 | SHA256:B5DDA4239592705740384FBB1E7101752B84C7032D48554440BD005971AD62A6 | |||
| 3956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.31117\wataskmanager.manifest | text | |
MD5:283156FBAEFC42426F4B3E439427AEBF | SHA256:1B54C187D9128631392073A53992967F532A9EBC60C3ECF2A352C889170D8131 | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C8CC0A7FE31816B4641D0465402560 | binary | |
MD5:E94FB54871208C00DF70F708AC47085B | SHA256:7B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF86 | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{A30C9DCD-DCA7-11EE-AE0A-12A9866C77DE}.dat | binary | |
MD5:4ED09559764B6E67D57D1CE1C8821956 | SHA256:0CAA0C23EB4F225D32808562F0E52DCBA5B90D00ACED9F6998A544C044BCC41C | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:753DF6889FD7410A2E9FE333DA83A429 | SHA256:B42DC237E44CBC9A43400E7D3F9CBD406DBDEFD62BFE87328F8663897D69DF78 | |||
| 3956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.31117\microsoftedgewebview2setup.exe | executable | |
MD5:080FF9263F39F62DBDAE513C66B7B9D2 | SHA256:326CBB6CD7D6062B850337A50200C805CDCBF59A6E05818990E6352AC68B4935 | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Tar2FE6.tmp | cat | |
MD5:DD73CEAD4B93366CF3465C8CD32E2796 | SHA256:A6752B7851B591550E4625B832A393AABCC428DE18D83E8593CD540F7D7CAE22 | |||
| 3956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.31117\wataskmanager.dll | executable | |
MD5:A6A7EE15FA13D8D8DB80C40EA6A9F80B | SHA256:2A774C4A38CD1317A4752A6073984E31FD45090943BFFA1279A731D033D37DF8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2044 | iexplore.exe | GET | 304 | 184.51.127.17:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6 | unknown | — | — | unknown |
2044 | iexplore.exe | GET | 304 | 184.51.127.17:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f78d505714a595e3 | unknown | — | — | unknown |
2044 | iexplore.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCu%2F8JZxQ3BalXFvP7Nih9m | unknown | binary | 2.18 Kb | unknown |
3864 | iexplore.exe | GET | 200 | 184.51.127.17:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?96c8eb5dfc595a04 | unknown | compressed | 67.5 Kb | unknown |
3864 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://secure.globalsign.com/cacert/codesigningrootr45.crt | unknown | binary | 1.37 Kb | unknown |
2832 | MicrosoftEdgeUpdate.exe | GET | 304 | 184.51.127.10:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?12afe32a0108ba7d | unknown | — | — | unknown |
856 | svchost.exe | HEAD | 200 | 152.199.19.161:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e13adb3a-1fec-487b-8317-614b7fac4afe?P1=1710437132&P2=404&P3=2&P4=bDwisHayAckjHqc8Bt9wt7UPR1mFsJIqL6sq5BuJtHI%2fh%2fWBV8IY0givsjJ20e5I2ssTuHmkzsxWWEHPqOxw%2bQ%3d%3d | unknown | — | — | unknown |
3864 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
856 | svchost.exe | GET | — | 152.199.19.161:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e13adb3a-1fec-487b-8317-614b7fac4afe?P1=1710437132&P2=404&P3=2&P4=bDwisHayAckjHqc8Bt9wt7UPR1mFsJIqL6sq5BuJtHI%2fh%2fWBV8IY0givsjJ20e5I2ssTuHmkzsxWWEHPqOxw%2bQ%3d%3d | unknown | — | — | unknown |
2832 | MicrosoftEdgeUpdate.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2044 | iexplore.exe | 184.51.127.42:443 | sadownload.mcafee.com | Akamai International B.V. | IT | unknown |
2044 | iexplore.exe | 184.51.127.17:80 | ctldl.windowsupdate.com | Akamai International B.V. | IT | unknown |
2044 | iexplore.exe | 104.18.38.233:80 | ocsp.usertrust.com | CLOUDFLARENET | — | shared |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3864 | iexplore.exe | 104.18.20.226:80 | secure.globalsign.com | CLOUDFLARENET | — | shared |
3864 | iexplore.exe | 184.51.127.17:80 | ctldl.windowsupdate.com | Akamai International B.V. | IT | unknown |
1556 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
sadownload.mcafee.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
secure.globalsign.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
msedge.api.cdp.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
msedge.f.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
856 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |