File name:

SmartAlertsSetup.exe

Full analysis: https://app.any.run/tasks/ced27296-b194-4814-a70f-b7651f0bd8f6
Verdict: Malicious activity
Analysis date: August 23, 2022, 16:12:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

C9532854CCBFAD59B910ADBC7F8F4380

SHA1:

0A8FCFC0BF4FB947FCC128741AF54EE9131F1777

SHA256:

F112C60061AFA2FE14E22E5C253809A7FDFE785D18A37CA02EC612A7A0BD118E

SSDEEP:

98304:Zenn3xWmIc1BjORWF5mwUDdXIvf0i50MRwTQXcqgLNrNeECKx/U5JTboDVBvfUQc:Zrs35BOdYX556Mcjccx/E8vfNeUb+3N

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • SmartAlertsSetup.exe (PID: 3488)
    • Loads dropped or rewritten executable

      • SmartAlertsSetup.exe (PID: 3488)
    • Changes settings of System certificates

      • Settings.exe (PID: 2084)
    • Application was dropped or rewritten from another process

      • Settings.exe (PID: 2084)
      • WinZip Smart Monitor Service.exe (PID: 488)
      • WinZipSmartMonitor.exe (PID: 2612)
      • WinZip Smart Monitor Service.exe (PID: 932)
  • SUSPICIOUS

    • Checks supported languages

      • SmartAlertsSetup.exe (PID: 3488)
      • Settings.exe (PID: 2084)
      • WinZip Smart Monitor Service.exe (PID: 488)
      • WinZipSmartMonitor.exe (PID: 2612)
      • WinZip Smart Monitor Service.exe (PID: 932)
    • Creates a directory in Program Files

      • SmartAlertsSetup.exe (PID: 3488)
    • Reads the computer name

      • Settings.exe (PID: 2084)
      • WinZip Smart Monitor Service.exe (PID: 488)
      • WinZipSmartMonitor.exe (PID: 2612)
      • WinZip Smart Monitor Service.exe (PID: 932)
      • SmartAlertsSetup.exe (PID: 3488)
    • Drops a file with a compile date too recent

      • SmartAlertsSetup.exe (PID: 3488)
    • Adds / modifies Windows certificates

      • Settings.exe (PID: 2084)
    • Creates files in the program directory

      • SmartAlertsSetup.exe (PID: 3488)
      • WinZipSmartMonitor.exe (PID: 2612)
    • Executed as Windows Service

      • WinZip Smart Monitor Service.exe (PID: 932)
    • Executable content was dropped or overwritten

      • SmartAlertsSetup.exe (PID: 3488)
  • INFO

    • Reads settings of System Certificates

      • Settings.exe (PID: 2084)
      • WinZip Smart Monitor Service.exe (PID: 488)
      • WinZipSmartMonitor.exe (PID: 2612)
      • WinZip Smart Monitor Service.exe (PID: 932)
    • Checks Windows Trust Settings

      • Settings.exe (PID: 2084)
      • WinZip Smart Monitor Service.exe (PID: 488)
      • WinZipSmartMonitor.exe (PID: 2612)
      • WinZip Smart Monitor Service.exe (PID: 932)
    • Checks supported languages

      • sc.exe (PID: 2344)
    • Reads the computer name

      • sc.exe (PID: 2344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2018-Jan-30 03:57:41
Detected languages:
  • English - United States
CompanyName: Corel Corporation
FileDescription: WinZip Smart Monitor installer
FileVersion: 2.12.3.2
InternalName: WinZipSmartMonitor.exe
LegalCopyright: Copyright © 1991-2022 Corel Corporation. All Rights Reserved.
OriginalFileName: WinZipSmartMonitorSetup.exe
ProductName: WinZip Smart Monitor
ProductVersion: 2.12.3.2

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 216

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 5
TimeDateStamp: 2018-Jan-30 03:57:41
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
25609
26112
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.41622
.rdata
32768
5006
5120
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.14383
.data
40960
131928
1536
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.0044
.ndata
176128
77824
0
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc
253952
175352
175616
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.33781

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.33763
67624
UNKNOWN
English - United States
RT_ICON
2
4.42169
38056
UNKNOWN
English - United States
RT_ICON
3
7.89889
31340
UNKNOWN
English - United States
RT_ICON
4
4.6237
16936
UNKNOWN
English - United States
RT_ICON
5
4.77233
9640
UNKNOWN
English - United States
RT_ICON
6
5.10041
4264
UNKNOWN
English - United States
RT_ICON
7
5.39165
2440
UNKNOWN
English - United States
RT_ICON
8
5.63701
1128
UNKNOWN
English - United States
RT_ICON
103
2.97321
118
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.73893
514
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start smartalertssetup.exe settings.exe no specs winzip smart monitor service.exe no specs winzipsmartmonitor.exe no specs sc.exe no specs winzip smart monitor service.exe smartalertssetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe" /ServiceC:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exeSmartAlertsSetup.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor Service
Exit code:
0
Version:
2,12,3,2
Modules
Images
c:\program files\winzip smart monitor\winzip smart monitor service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
932"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe
services.exe
User:
SYSTEM
Company:
Corel Corporation
Integrity Level:
SYSTEM
Description:
WinZip Smart Monitor Service
Exit code:
0
Version:
2,12,3,2
Modules
Images
c:\program files\winzip smart monitor\winzip smart monitor service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2084"C:\Program Files\WinZip Smart Monitor\Settings.exe" /RegServerC:\Program Files\WinZip Smart Monitor\Settings.exeSmartAlertsSetup.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
Settings
Exit code:
0
Version:
2,12,3,2
Modules
Images
c:\program files\winzip smart monitor\settings.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2344sc start "WinZip Smart Monitor Service"C:\Windows\system32\sc.exeSmartAlertsSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1053
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\sc.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2612"C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe" -installC:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exeSmartAlertsSetup.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor
Exit code:
0
Version:
2,12,3,2
Modules
Images
c:\program files\winzip smart monitor\winzipsmartmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3204"C:\Users\admin\AppData\Local\Temp\SmartAlertsSetup.exe" C:\Users\admin\AppData\Local\Temp\SmartAlertsSetup.exeExplorer.EXE
User:
admin
Company:
Corel Corporation
Integrity Level:
MEDIUM
Description:
WinZip Smart Monitor installer
Exit code:
3221226540
Version:
2.12.3.2
Modules
Images
c:\users\admin\appdata\local\temp\smartalertssetup.exe
c:\windows\system32\ntdll.dll
3488"C:\Users\admin\AppData\Local\Temp\SmartAlertsSetup.exe" C:\Users\admin\AppData\Local\Temp\SmartAlertsSetup.exe
Explorer.EXE
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor installer
Exit code:
0
Version:
2.12.3.2
Modules
Images
c:\users\admin\appdata\local\temp\smartalertssetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
14 204
Read events
14 111
Write events
93
Delete events
0

Modification events

(PID) Process:(2084) Settings.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
Operation:writeName:Blob
Value:
04000000010000001000000078F2FCAA601F2FB4EBC937BA532E7549530000000100000040000000303E301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00F00000001000000300000004EA1B34B10B982A96A38915843507820AD632C6AAD8343E337B34D660CD8366FA154544AE80668AE1FDF3931D57E1996030000000100000014000000DDFB16CD4931C973A2037D3FC83A4D7D775D05E41D0000000100000010000000A86DC6A233EB339610F3ED414927C559140000000100000014000000ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F620000000100000020000000552F7BDCF1A7AF9E6CE672017F4F12ABF77240C78E761AC203D1D9D20AC899880B00000001000000320000004400690067006900430065007200740020005400720075007300740065006400200052006F006F0074002000470034000000190000000100000010000000FFAC207997BB2CFE865570179EE037B9090000000100000034000000303206082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030106082B060105050703082000000001000000940500003082059030820378A0030201020210059B1B579E8E2132E23907BDA777755C300D06092A864886F70D01010C05003062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F74204734301E170D3133303830313132303030305A170D3338303131353132303030305A3062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F7420473430820222300D06092A864886F70D01010105000382020F003082020A0282020100BFE6907368DEBBE45D4A3C3022306933ECC2A7252EC9213DF28AD859C2E129A73D58AB769ACDAE7B1B840DC4301FF31BA43816EB56C6976D1DABB279F2CA11D2E45FD6053C520F521FC69E15A57EBE9FA95716595572AF689370C2B2BA75996A733294D11044102EDF82F30784E6743B6D71E22D0C1BEE20D5C9201D63292DCEEC5E4EC893F821619B34EB05C65EEC5B1ABCEBC9CFCDAC34405FB17A66EE77C848A86657579F54588E0C2BB74FA730D956EECA7B5DE3ADC94F5EE535E731CBDA935EDC8E8F80DAB69198409079C378C7B6B1C4B56A183803108DD8D437A42E057D88F5823E109170AB55824132D7DB04732A6E91017C214CD4BCAE1B03755D7866D93A31449A3340BF08D75A49A4C2E6A9A067DDA427BCA14F39B5115817F7245C468F64F7C169887698763D595D4276878997697A48F0E0A2121B669A74CADE4B1EE70E63AEE6D4EF92923A9E3DDC00E4452589B69A44192B7EC094B4D2616DEB33D9C5DF4B0400CC7D1C95C38FF721B2B211B7BB7FF2D58C702C4160AAB1631844951A76627EF680B0FBE864A633D18907E1BDB7E643A418B8A67701E10F940C211DB2542925896CE50E52514774BE26ACB64175DE7AAC5F8D3FC9BCD34111125BE51050EB31C5CA72162209DF7C4C753F63EC215FC420516B6FB1AB868B4FC2D6455F9D20FCA11EC5C08FA2B17E0A2699F5E4692F981D2DF5D9A9B21DE51B0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E04160414ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F300D06092A864886F70D01010C05000382020100BB61D97DA96CBE17C4911BC3A1A2008DE364680F56CF77AE70F9FD9A4A99B9C9785C0C0C5FE4E61429560B36495D4463E0AD9C9618661B230D3D79E96D6BD654F8D23CC14340AE1D50F552FC903BBB9899696BC7C1A7A868A427DC9DF927AE3085B9F6674D3A3E8F5939225344EBC85D03CAED507A7D62210A80C87366D1A005605FE8A5B4A7AFA8F76D359C7C5A8AD6A23899F3788BF44DD2200BDE04EE8C9B4781720DC01432EF30592EAEE071F256E46A976F92506D968D687A9AB236147A06F224B9091150D708B1B8897A8423614229E5A3CDA22041D7D19C64D9EA26A18B14D74C19B25041713D3F4D7023860C4ADC81D2CC3294840D0809971C4FC0EE6B207430D2E03934108521150108E85532DE7149D92817504DE6BE4DD175ACD0CAFB41B843A5AAD3C305444F2C369BE2FAE245B823536C066F67557F46B54C3F6E285A7926D2A4A86297D21EE2ED4A8BBC1BFD474A0DDF67667EB25B41D03BE4F43BF40463E9EFC2540051A08A2AC9CE78CCD5EA870418B3CEAF4988AFF39299B6B3E6610FD28500E7501AE41B959D19A1B99CB19BB1001EEFD00F4F426CC90ABCEE43FA3A71A5C84D26A535FD895DBC85621D32D2A02B54ED9A57C1DBFA10CF19B78B4A1B8F01B6279553E8B6896D5BBC68D423E88B51A256F9F0A680A0D61EB3BC0F0F537529AAEA1377E4DE8C8121AD07104711AD873D07D175BCCFF3667E
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
Operation:writeName:Blob
Value:
5C000000010000000400000000100000090000000100000034000000303206082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030106082B06010505070308190000000100000010000000FFAC207997BB2CFE865570179EE037B90B00000001000000320000004400690067006900430065007200740020005400720075007300740065006400200052006F006F0074002000470034000000620000000100000020000000552F7BDCF1A7AF9E6CE672017F4F12ABF77240C78E761AC203D1D9D20AC89988140000000100000014000000ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F1D0000000100000010000000A86DC6A233EB339610F3ED414927C559030000000100000014000000DDFB16CD4931C973A2037D3FC83A4D7D775D05E40F00000001000000300000004EA1B34B10B982A96A38915843507820AD632C6AAD8343E337B34D660CD8366FA154544AE80668AE1FDF3931D57E1996530000000100000040000000303E301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C004000000010000001000000078F2FCAA601F2FB4EBC937BA532E75492000000001000000940500003082059030820378A0030201020210059B1B579E8E2132E23907BDA777755C300D06092A864886F70D01010C05003062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F74204734301E170D3133303830313132303030305A170D3338303131353132303030305A3062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F7420473430820222300D06092A864886F70D01010105000382020F003082020A0282020100BFE6907368DEBBE45D4A3C3022306933ECC2A7252EC9213DF28AD859C2E129A73D58AB769ACDAE7B1B840DC4301FF31BA43816EB56C6976D1DABB279F2CA11D2E45FD6053C520F521FC69E15A57EBE9FA95716595572AF689370C2B2BA75996A733294D11044102EDF82F30784E6743B6D71E22D0C1BEE20D5C9201D63292DCEEC5E4EC893F821619B34EB05C65EEC5B1ABCEBC9CFCDAC34405FB17A66EE77C848A86657579F54588E0C2BB74FA730D956EECA7B5DE3ADC94F5EE535E731CBDA935EDC8E8F80DAB69198409079C378C7B6B1C4B56A183803108DD8D437A42E057D88F5823E109170AB55824132D7DB04732A6E91017C214CD4BCAE1B03755D7866D93A31449A3340BF08D75A49A4C2E6A9A067DDA427BCA14F39B5115817F7245C468F64F7C169887698763D595D4276878997697A48F0E0A2121B669A74CADE4B1EE70E63AEE6D4EF92923A9E3DDC00E4452589B69A44192B7EC094B4D2616DEB33D9C5DF4B0400CC7D1C95C38FF721B2B211B7BB7FF2D58C702C4160AAB1631844951A76627EF680B0FBE864A633D18907E1BDB7E643A418B8A67701E10F940C211DB2542925896CE50E52514774BE26ACB64175DE7AAC5F8D3FC9BCD34111125BE51050EB31C5CA72162209DF7C4C753F63EC215FC420516B6FB1AB868B4FC2D6455F9D20FCA11EC5C08FA2B17E0A2699F5E4692F981D2DF5D9A9B21DE51B0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E04160414ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F300D06092A864886F70D01010C05000382020100BB61D97DA96CBE17C4911BC3A1A2008DE364680F56CF77AE70F9FD9A4A99B9C9785C0C0C5FE4E61429560B36495D4463E0AD9C9618661B230D3D79E96D6BD654F8D23CC14340AE1D50F552FC903BBB9899696BC7C1A7A868A427DC9DF927AE3085B9F6674D3A3E8F5939225344EBC85D03CAED507A7D62210A80C87366D1A005605FE8A5B4A7AFA8F76D359C7C5A8AD6A23899F3788BF44DD2200BDE04EE8C9B4781720DC01432EF30592EAEE071F256E46A976F92506D968D687A9AB236147A06F224B9091150D708B1B8897A8423614229E5A3CDA22041D7D19C64D9EA26A18B14D74C19B25041713D3F4D7023860C4ADC81D2CC3294840D0809971C4FC0EE6B207430D2E03934108521150108E85532DE7149D92817504DE6BE4DD175ACD0CAFB41B843A5AAD3C305444F2C369BE2FAE245B823536C066F67557F46B54C3F6E285A7926D2A4A86297D21EE2ED4A8BBC1BFD474A0DDF67667EB25B41D03BE4F43BF40463E9EFC2540051A08A2AC9CE78CCD5EA870418B3CEAF4988AFF39299B6B3E6610FD28500E7501AE41B959D19A1B99CB19BB1001EEFD00F4F426CC90ABCEE43FA3A71A5C84D26A535FD895DBC85621D32D2A02B54ED9A57C1DBFA10CF19B78B4A1B8F01B6279553E8B6896D5BBC68D423E88B51A256F9F0A680A0D61EB3BC0F0F537529AAEA1377E4DE8C8121AD07104711AD873D07D175BCCFF3667E
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B71C4444-6A93-4BD8-BCCA-07C6A01F2340}
Operation:writeName:(default)
Value:
ISMSettings
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B71C4444-6A93-4BD8-BCCA-07C6A01F2340}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{00020424-0000-0000-C000-000000000046}
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B71C4444-6A93-4BD8-BCCA-07C6A01F2340}\TypeLib
Operation:writeName:(default)
Value:
{CEC67385-D765-4B64-BCBD-888BA1DDFC09}
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{37EF56AC-DD78-4013-B1D4-C31AC04BF93C}
Operation:writeName:(default)
Value:
ISMSettings2
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{37EF56AC-DD78-4013-B1D4-C31AC04BF93C}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{00020424-0000-0000-C000-000000000046}
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{37EF56AC-DD78-4013-B1D4-C31AC04BF93C}\TypeLib
Operation:writeName:(default)
Value:
{CEC67385-D765-4B64-BCBD-888BA1DDFC09}
(PID) Process:(2084) Settings.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CEC67385-D765-4B64-BCBD-888BA1DDFC09}
Operation:writeName:(default)
Value:
SMSettings
Executable files
17
Suspicious files
5
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\appsbinary
MD5:A480A3439C61BD1A541B53580B4F8BF2
SHA256:32475477F9708C9FA4A77DA5A619DEC15977897C15359C187C0364C45718DC59
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\Settings.mabbinary
MD5:8E1787896BA29AB18525DDBDD528D681
SHA256:D9871B47FF257A77A2990B200AC85AA35010BB3EE2C81C9FDAC6AE3922BDB851
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\Settings.exeexecutable
MD5:6078840235E271B2C2DA68F69FD124EB
SHA256:31AA4A59D00ACBD0BA5AF4A2E861E466948830B5B7768E299B307E6AC447E348
3488SmartAlertsSetup.exeC:\Users\admin\AppData\Local\Temp\nsu63C0.tmp\System.dllexecutable
MD5:75ED96254FBF894E42058062B4B4F0D1
SHA256:A632D74332B3F08F834C732A103DAFEB09A540823A2217CA7F49159755E8F1D7
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.mabbinary
MD5:9B37D7358770D2FD2FE17D14F06018BD
SHA256:232ADB20A8553521F336A9BFC086588BE4DC7254387E5D264C7BD52E19D21989
3488SmartAlertsSetup.exeC:\Users\admin\AppData\Local\Temp\nsu63BF.tmp
MD5:
SHA256:
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exeexecutable
MD5:3B6DF10A81CE0DA8D9FE6F7D1E5C57C4
SHA256:DCEED30A6E52003996FB434F4C04405CF26A22DC641F53754BD6F60F12B9491E
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.mabbinary
MD5:9C0DBF3E3296564EF592A9179C16B9D2
SHA256:65A62481080978FA36B2DB11A169EF762C7B43821BEA647F984E90133B2406D4
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\Plugins\2DEEE340-EAFF-4BF4-8B39-74F7B0E57CBB.2.9.0.10\2DEEE340-EAFF-4BF4-8B39-74F7B0E57CBB.2.9.0.10.dllexecutable
MD5:11477E3C766ECE15F845F0C29B24E4FA
SHA256:1C67C09ADF529E22D0B98D5859BC20930A83F92C0526E0A647A7085A00C388BC
3488SmartAlertsSetup.exeC:\Program Files\WinZip Smart Monitor\Plugins\FD4123B1-314F-4854-BCEA-A213C91C66E5.2.9.0.10\FD4123B1-314F-4854-BCEA-A213C91C66E5.2.9.0.10.dllexecutable
MD5:B4893FF1AC0BCFA60D03C297568D3F46
SHA256:8DA8D2BAA95753AE415F542DE294111A021E3E1F7C344E20B5950E8CB5B03156
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
4
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
932
WinZip Smart Monitor Service.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a427db1ebf455dab
US
whitelisted
932
WinZip Smart Monitor Service.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
US
der
471 b
whitelisted
932
WinZip Smart Monitor Service.exe
GET
93.184.220.29:80
http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.2:53
whitelisted
932
WinZip Smart Monitor Service.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
932
WinZip Smart Monitor Service.exe
93.184.221.240:80
ctldl.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl4.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info