| URL: | https://breakingsecurity.net/wp-content/uploads/dlm_uploads/2018/03/Remcos-v4.9.3-Pro.zip |
| Full analysis: | https://app.any.run/tasks/b5a343a5-b3d2-4f1b-a3f1-26ab1996fc4f |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 19:31:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | E9844E6B517D75F0C993F6303AD81D96 |
| SHA1: | 740D828BEE23A9ADAACFD0AB20300EAF81ACE50C |
| SHA256: | F1FA33FFC6962426E7098ED0A2E8D8E7CD1B7065C65EA5920C936D2693625A28 |
| SSDEEP: | 3:N8eM2WrRFRbOlAQy/HAhXSKwIUITRWWxrUn:232cRFRbOlAZfyihIUu/NUn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.2.24295201\1260471687" -childID 1 -isForBrowser -prefsHandle 2064 -prefMapHandle 2060 -prefsLen 28712 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0183bed3-7670-4f7c-ab5b-67407e97958a} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 2076 12d3e560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 324 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.5.862651404\71274905" -childID 4 -isForBrowser -prefsHandle 3944 -prefMapHandle 3844 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7e171a16-83c6-4a6e-89fe-eacfac1fc2aa} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 3948 1935e280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 492 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.0.1274099969\1058963226" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6dff4ed1-5edb-4e62-a328-a73a48e7903b} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 1188 d6a71a0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
| 668 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.4.1544453248\1158686838" -childID 3 -isForBrowser -prefsHandle 3496 -prefMapHandle 3500 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e9dda0e4-701c-42e3-b6c9-42975ce79604} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 3376 1832eb20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2064 | "C:\Users\admin\Desktop\Remcos v4.9.3 Pro.exe" | C:\Users\admin\Desktop\Remcos v4.9.3 Pro.exe | explorer.exe | ||||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: MEDIUM Description: REMCOS Remote Control & Surveillance Exit code: 0 Version: 4.9.3.0 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.1.1096668296\1936187182" -parentBuildID 20230710165010 -prefsHandle 1420 -prefMapHandle 1416 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {45c6288f-3451-492c-bb43-70fd166b110c} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 1432 d614390 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2616 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.3.1029315035\278041649" -childID 2 -isForBrowser -prefsHandle 2888 -prefMapHandle 2884 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ae7dfd00-07d2-4add-b7e9-2fce6e04c598} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 2900 169a1280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2636 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31087703 | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31087703 | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3656) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3720 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Remcos-v4.9.3-Pro.zip.uednp5o.partial | — | |
MD5:— | SHA256:— | |||
| 3656 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Remcos-v4.9.3-Pro.zip | — | |
MD5:— | SHA256:— | |||
| 3960 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3960.2539\Remcos v4.9.3 Pro.exe | — | |
MD5:— | SHA256:— | |||
| 3720 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9430F1AFA8A7B223876A48A9BD0AF49E_51C62C590BD0DE4E3BDCA66FB8E819EA | binary | |
MD5:F25C8713E13A4B9AD8C06A533EB9B5BA | SHA256:15FD801E5F4AA17F8171423F98F6E571815E5038FE062D1C84D6D74145369C89 | |||
| 3720 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562 | binary | |
MD5:7CEE9B9A5C755762AEFCF010B23EA104 | SHA256:43134E740D828B663DC4AEB7D2D446648F6633E08BA50CEA76E2670BA71B81EB | |||
| 3720 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562 | der | |
MD5:5A6508503C3D0D836B9D7D3F63B6EAA8 | SHA256:185DC72407B6908E6BC9CD9BE64A92C113A112F0ACC92FE28825C737B6CD9E3A | |||
| 3720 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Remcos-v4.9.3-Pro[1].zip | compressed | |
MD5:4097D31FE332F688E20724CEB448334D | SHA256:35A3A6E953060BF5464C1DBD510B871DDE9B9015889CC5753D72AEE4D08DDEBF | |||
| 3720 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:69962D0BA72D47AD35D0CDA71268A596 | SHA256:3183C88FE7E67FCBE78C722AFE4D59E7EEC3011589F2EFD93D5EF477164FAB53 | |||
| 3656 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\urlblockindex[1].bin | binary | |
MD5:FA518E3DFAE8CA3A0E495460FD60C791 | SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7 | |||
| 3656 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | der | |
MD5:AE042CBB1AC8C1449D76ACCECF94DD81 | SHA256:B186D44EF30080B9D84D7DD60AEE0B63265D192602AE4C5AE33D5048F787D653 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3720 | iexplore.exe | GET | 304 | 46.228.146.128:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?927e0d673a39dd41 | unknown | — | — | unknown |
2724 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2724 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2724 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2724 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2724 | firefox.exe | POST | — | 142.250.186.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | — | — | unknown |
2724 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
— | — | POST | 200 | 142.250.186.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
— | — | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3720 | iexplore.exe | GET | 304 | 46.228.146.128:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d362edf7b65e9a48 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3720 | iexplore.exe | 192.124.249.19:443 | — | SUCURI-SEC | US | unknown |
3720 | iexplore.exe | 46.228.146.128:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
3720 | iexplore.exe | 192.124.249.22:80 | ocsp.starfieldtech.com | SUCURI-SEC | US | unknown |
3656 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | EDGECAST | US | whitelisted |
3656 | iexplore.exe | 46.228.146.128:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
3656 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1080 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
breakingsecurity.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.starfieldtech.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ieonline.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
www.msn.com |
| whitelisted |
p4-preview.runhosting.com |
| malicious |