| File name: | GWSetup.exe |
| Full analysis: | https://app.any.run/tasks/531aac56-305c-40cd-b6d8-f0b5dbc706ec |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2024, 03:34:31 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive |
| MD5: | D8E1DEF4D2B55210DCFAE3AD784CA7B9 |
| SHA1: | 398902BC050EBAAB539C37429C887714A60AE76F |
| SHA256: | EAB58C18FA7A36D77CB0D62C73B0D5AD674F1A37A1073D5BA50D7E12EE7EFCEE |
| SSDEEP: | 98304:lgrrdQE3heOgiLJC44Cjn+rCPpzj0HyWvwGgrjEplb/eJh3J43+DxHJWAnayBSlc:+NQlBbgmvaJYcTE72yUAMZ |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:10:10 03:22:54+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 31232 |
| InitializedDataSize: | 34304 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x8810 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.1.3 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | GWSetup |
| FileVersion: | 0, 0, 1, 3 |
| InternalName: | GWSetup |
| LegalCopyright: | Copyright 2020 |
| LegalTrademarks: | - |
| OriginalFileName: | SetupStub.exe |
| PrivateBuild: | - |
| ProductName: | - |
| ProductVersion: | 1, 0, 0, 0 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1028 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | devcon.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3848 | "C:\WINDOWS\system32\drivers\devcon.exe" enable gwvnic | C:\Windows\System32\drivers\devcon.exe | — | GWSetup.exe | |||||||||||
User: admin Company: Windows (R) Codename Longhorn DDK provider Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.0.6001.18000 built by: WinDDK Modules
| |||||||||||||||
| 3940 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4388 | "C:\WINDOWS\system32\regsvr32.exe" "C:\Program Files\Gateway\SSLVPN\gwieplugin_1d3222a3c1.dll" /s | C:\Windows\System32\regsvr32.exe | — | GWSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4808 | "C:\Users\admin\AppData\Local\Temp\GWSetup.exe" | C:\Users\admin\AppData\Local\Temp\GWSetup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: GWSetup Exit code: 3221226540 Version: 0, 0, 1, 3 Modules
| |||||||||||||||
| 5284 | "C:\Users\admin\AppData\Local\Temp\GWSetup.exe" | C:\Users\admin\AppData\Local\Temp\GWSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: GWSetup Exit code: 0 Version: 0, 0, 1, 3 Modules
| |||||||||||||||
| 5448 | "C:\WINDOWS\SysWOW64\gwupdater.exe" | C:\Windows\SysWOW64\gwupdater.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: gwservice Version: 0, 0, 1, 54 Modules
| |||||||||||||||
| 5528 | "C:\WINDOWS\SysWOW64\gwservice.exe" | C:\Windows\SysWOW64\gwservice.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: gwservice Version: 0, 0, 1, 54 Modules
| |||||||||||||||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install |
| Operation: | write | Name: | UpdaterFlag |
Value: 0 | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install |
| Operation: | write | Name: | UIOption |
Value: 0 | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install |
| Operation: | write | Name: | InstallPath |
Value: C:\Program Files (x86)\Gateway\SSLVPN | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install |
| Operation: | write | Name: | InstallPath64 |
Value: C:\Program Files\Gateway\SSLVPN | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install |
| Operation: | write | Name: | InstallPath64 |
Value: | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{100C2765-1362-4CCF-AB02-56D916BB8732}\InprocServer32 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{100C2765-1362-4CCF-AB02-56D916BB8732} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4A2B7DF6-7E36-4A71-8169-D790C00DFCD3}\InprocServer32 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4A2B7DF6-7E36-4A71-8169-D790C00DFCD3} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5284) GWSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install\Shortcut |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwuninstall.exe.cab | compressed | |
MD5:F99914BE0A2031359173FF3064B22384 | SHA256:01DD490A987B7C2C0058E0B795515BD39004A78A88588D8ABDCF8D40917881F9 | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\signcrack.exe | executable | |
MD5:BB03938C9127612DD30A96B4A421FFC2 | SHA256:E079F07A37BCEE95738FFB162AF75D487D95E7D67359459A1A0B2193F48DCF36 | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwuninstall.exe | executable | |
MD5:CB0107B47A77FE4FC7C158F4F7AE4591 | SHA256:8F62AD14C3946D53A790672915513595454547BE9729FCC425037A3B663FCFC7 | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwupdater.dll.cab | compressed | |
MD5:7D1808986C2EA6271063EC7CFE360D7B | SHA256:FEA0A2358F04183BBACB5CAB5A9F3C666C3776D3D91A21285371914A51631D8C | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwclient.exe | executable | |
MD5:90C1778D45FD9ACA9E21D708BEA36D9D | SHA256:2C7DA6690BE26BD6B5CEEA90B233FDD26589D7A72B2A62468903ABA887E7AD6A | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwclient.exe.cab | compressed | |
MD5:996CB58EA64015C4C63BEC7234B2C8A6 | SHA256:928DB5AADAD4D3D3FDE92C63D760FEE2A91D7D6EFE6675A98153A7C27C8651A0 | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\GWVPNDoctor.exe.cab | compressed | |
MD5:61E12AF3F5FD2EEC4F5EA72BA819AFC8 | SHA256:0A45778BF05CF539FE43DB2A40AD20B2EB31DDF173E75254B1BB130C47168793 | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwtrayclient.exe.cab | compressed | |
MD5:817713E095C18E60DC53A295DFD38A0D | SHA256:ADFD1EAE028A2A889BBE86AD66F514D16E84D0E385A5A0B3849BC79C4D132BBE | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\gwsdk.dll.cab | compressed | |
MD5:2B53FEC738E8A4BC56616FDC956063AE | SHA256:3F2414EF59CB4F0BE1C7A2CF15A7319B888DD9715F452679188F86C4696D472A | |||
| 5284 | GWSetup.exe | C:\Users\admin\AppData\Local\Temp\gwtemp\GWVPNDoctor.exe | executable | |
MD5:19F0EB0B269FA8BD647B52954706A45B | SHA256:85BDD14F616073CB28D29C1704112E3595FB5515B2E41DA00E7FA8C5019E825C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4424 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3676 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
4132 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5532 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 131.253.33.254:443 | a-ring-fallback.msedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 104.126.37.145:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2348 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6012 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4792 | slui.exe | 20.83.72.98:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1620 | slui.exe | 20.83.72.98:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4092 | slui.exe | 20.83.72.98:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
t-ring-fdv2.msedge.net |
| unknown |
a-ring-fallback.msedge.net |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
fp-afd-nocache-ccp.azureedge.net |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
Process | Message |
|---|---|
GWSetup.exe | [07-29 03:34:42][INF][GWUPDLL]DLL_PROCESS_ATTACH
|
GWSetup.exe | [07-29 03:34:42][INF][GWUPDLL]Load SSPI library(C:\WINDOWS\syswow64\Secur32.dll).
|
GWSetup.exe | [07-29 03:34:42][WAR][GWUPDLL]Name:GWVNIC, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
|
GWSetup.exe | [07-29 03:34:42][WAR][GWUPDLL]Name:VNICCAT, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
|
GWSetup.exe | [07-29 03:34:42][WAR][GWUPDLL]Name:VNICINF, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
|
GWSetup.exe | [07-29 03:34:42][DBG][GWUPDLL]check ver conf path:C:\Program Files (x86)\Gateway\SSLVPN\package.conf.bak
|
GWSetup.exe | [07-29 03:34:42][WAR][GWUPDLL]file[C:\Program Files (x86)\Gateway\SSLVPN\package.conf.bak] md5:
|
GWSetup.exe | [07-29 03:34:42][DBG][GWUPDLL]conf.bak check failed
|
GWSetup.exe | get sign config is not xp |
GWSetup.exe | get sign config is not xp |