File name:

SStap-2018.7.10.exe

Full analysis: https://app.any.run/tasks/0ecce5f6-e242-4ec9-a2a7-1d8bf5f3f721
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 31, 2019, 03:42:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DB8E5A5A8D5612D4978F623B6FE6E7FE

SHA1:

2F1B5D1A54D9AB0A010D9BA4580A7F62E9FD9191

SHA256:

FBEB573B11788346DC8AF5E77F48A272BEA97DE6F4435A5F03703020B8CB59DE

SSDEEP:

196608:/ITU1z6ydJOXod1Cs8tZfXAtWoDWjOFw3pntbyUdC/AxV1KzPX5bOL:wTKjGXOg/fQtnGWwqUYUozPJ6L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SStap-2018.7.10.exe (PID: 1924)
      • SStap-2018.7.10.exe (PID: 2868)
      • SStap-2018.7.10.exe (PID: 2876)
      • tapinstall.exe (PID: 3112)
      • tapinstall.exe (PID: 2764)
      • SSTap.exe (PID: 2524)
    • Loads dropped or rewritten executable

      • SSTap.exe (PID: 2524)
    • Changes settings of System certificates

      • tapinstall.exe (PID: 2764)
      • SSTap.exe (PID: 2524)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SStap-2018.7.10.exe (PID: 856)
      • SStap-2018.7.10.exe (PID: 2876)
      • tapinstall.exe (PID: 2764)
      • DrvInst.exe (PID: 2096)
      • DrvInst.exe (PID: 1472)
    • Creates files in the user directory

      • SStap-2018.7.10.exe (PID: 2876)
      • SSTap.exe (PID: 2524)
    • Creates files in the program directory

      • SStap-2018.7.10.exe (PID: 2876)
      • SSTap.exe (PID: 2524)
    • Starts CMD.EXE for commands execution

      • SStap-2018.7.10.exe (PID: 856)
    • Uses NETSH.EXE for network configuration

      • SSTap.exe (PID: 2524)
    • Creates a software uninstall entry

      • SStap-2018.7.10.exe (PID: 2876)
    • Creates files in the Windows directory

      • tapinstall.exe (PID: 3112)
      • tapinstall.exe (PID: 2764)
      • DrvInst.exe (PID: 2096)
      • DrvInst.exe (PID: 1472)
    • Adds / modifies Windows certificates

      • tapinstall.exe (PID: 2764)
      • SSTap.exe (PID: 2524)
    • Reads internet explorer settings

      • SSTap.exe (PID: 2524)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 2096)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2096)
      • DrvInst.exe (PID: 1472)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2096)
      • DrvInst.exe (PID: 1472)
    • Searches for installed software

      • DrvInst.exe (PID: 2096)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3380)
    • Reads settings of System Certificates

      • SSTap.exe (PID: 2524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:02:01 21:18:00+01:00
PEType: PE32
LinkerVersion: 2.5
CodeSize: 67584
InitializedDataSize: 9227776
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.4
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug, Pre-release, Private build
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 1.0.0.4
ProductVersion: 2018.7.10
ProductName: SSTap
OriginalFileName: SSTap
FileDescription: 网游加速器
LegalCopyright: https://github.com/FQrabbit/SSTab-Rule
PrivateBuild: FQrabbit

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-Feb-2018 20:18:00
Detected languages:
  • English - United States
FileVersion: 1.0.0.4
ProductVersion: 2018.7.10
ProductName: SSTap
OriginalFilename: SSTap
FileDescription: 网游加速器
LegalCopyright: https://github.com/FQrabbit/SSTab-Rule
PrivateBuild: FQrabbit

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 01-Feb-2018 20:18:00
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.code
0x00001000
0x000037F0
0x00003800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.61236
.text
0x00005000
0x0000CFA2
0x0000D000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.58582
.rdata
0x00012000
0x000033A0
0x00003400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.11024
.data
0x00016000
0x00001724
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.93727
.rsrc
0x00018000
0x008C878C
0x008C8800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.98923

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.92322
611
Latin 1 / Western European
UNKNOWN
RT_MANIFEST
2
3.72457
744
Latin 1 / Western European
UNKNOWN
RT_ICON
3
3.62544
488
Latin 1 / Western European
UNKNOWN
RT_ICON
4
3.39324
296
Latin 1 / Western European
UNKNOWN
RT_ICON
5
7.9813
36340
Latin 1 / Western European
UNKNOWN
RT_ICON
6
5.18366
3752
Latin 1 / Western European
UNKNOWN
RT_ICON
7
5.51348
2216
Latin 1 / Western European
UNKNOWN
RT_ICON
8
4.8787
1736
Latin 1 / Western European
UNKNOWN
RT_ICON
9
3.59768
1384
Latin 1 / Western European
UNKNOWN
RT_ICON
10
7.9764
139672
Latin 1 / Western European
UNKNOWN
RT_ICON

Imports

COMCTL32.DLL
GDI32.DLL
KERNEL32.dll
MSVCRT.dll
OLE32.DLL
SHELL32.DLL
SHLWAPI.DLL
USER32.DLL
WINMM.DLL
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
17
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start sstap-2018.7.10.exe cmd.exe no specs sstap-2018.7.10.exe no specs sstap-2018.7.10.exe no specs sstap-2018.7.10.exe sstap.exe netsh.exe no specs netsh.exe no specs netsh.exe no specs tapinstall.exe no specs tapinstall.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs drvinst.exe no specs drvinst.exe netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
856"C:\Users\admin\Desktop\SStap-2018.7.10.exe" C:\Users\admin\Desktop\SStap-2018.7.10.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\sstap-2018.7.10.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
1424DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000005E0" "000005DC"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1472DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem4.inf" "oemwin2k.inf:tap0901:tap0901.ndi:9.0.0.9:tap0901" "6d14a44ff" "00000304" "000005D0" "000005E8"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1924SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.execmd.exe
User:
admin
Company:
技术支持(http://www.hofosetup.com)
Integrity Level:
MEDIUM
Description:
真正的"网游加速器"
Exit code:
3221226540
Version:
2018.7.10
Modules
Images
c:\users\admin\appdata\local\temp\738c.tmp\sstap-2018.7.10.exe
c:\systemroot\system32\ntdll.dll
2096DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{60e53b82-5dae-6bb6-ae22-662847da8430}\oemwin2k.inf" "0" "6d14a44ff" "00000304" "WinSta0\Default" "00000534" "208" "c:\program files\sstap\tap-driver\x86"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2524"C:\Program Files\SSTap\SSTap.exe" C:\Program Files\SSTap\SSTap.exe
SStap-2018.7.10.exe
User:
admin
Company:
Taro Labs
Integrity Level:
HIGH
Description:
Enjoy Gaming
Exit code:
0
Version:
1.0.9.1
Modules
Images
c:\program files\sstap\sstap.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\sstap\libintl3.dll
c:\program files\sstap\libiconv2.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2744rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{311a80dd-1238-64f5-520d-f0427e56464f} Global\{26f5f208-fb0c-1955-bc02-c512c7e7b42e} C:\Windows\System32\DriverStore\Temp\{6f1fb17e-ce89-2e25-266e-5e348d33b479}\oemwin2k.inf C:\Windows\System32\DriverStore\Temp\{6f1fb17e-ce89-2e25-266e-5e348d33b479}\tap0901.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2764"C:\Program Files\SSTap\tap-driver\x86\tapinstall.exe" install "C:\Program Files\SSTap\tap-driver\x86\OemWin2k.inf" tap0901C:\Program Files\SSTap\tap-driver\x86\tapinstall.exe
SSTap.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.10011.16384
Modules
Images
c:\program files\sstap\tap-driver\x86\tapinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2868"C:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.exe" C:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.execmd.exe
User:
admin
Company:
技术支持(http://www.hofosetup.com)
Integrity Level:
MEDIUM
Description:
真正的"网游加速器"
Exit code:
3221226540
Version:
2018.7.10
Modules
Images
c:\users\admin\appdata\local\temp\738c.tmp\sstap-2018.7.10.exe
c:\systemroot\system32\ntdll.dll
2876"C:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.exe" C:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.exe
cmd.exe
User:
admin
Company:
技术支持(http://www.hofosetup.com)
Integrity Level:
HIGH
Description:
真正的"网游加速器"
Exit code:
0
Version:
2018.7.10
Modules
Images
c:\users\admin\appdata\local\temp\738c.tmp\sstap-2018.7.10.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
Total events
1 818
Read events
996
Write events
772
Delete events
50

Modification events

(PID) Process:(856) SStap-2018.7.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(856) SStap-2018.7.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3244) cmd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3244) cmd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_CURRENT_USER\Software\Newsoft
Operation:writeName:UID
Value:
NS010797652327019920
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SStap-2018_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SStap-2018_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SStap-2018_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SStap-2018_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2876) SStap-2018.7.10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SStap-2018_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
20
Suspicious files
24
Text files
766
Unknown types
20

Dropped files

PID
Process
Filename
Type
2876SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\report[1].htm
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\data2[1].zip
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Program Files\SSTap\config\localhost.initext
MD5:
SHA256:
856SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Temp\738C.tmp\738D.tmp\739D.battext
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\data[1].zipbinary
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Program Files\SSTap\config\config.initext
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Program Files\SSTap\config\proxylist.jsontext
MD5:
SHA256:
2876SStap-2018.7.10.exeC:\Program Files\SSTap\libcurl.dllexecutable
MD5:2B275E2CFBE9D7D972718C0EB14238BD
SHA256:EE5D44FF49294D6432E33CA08DBDE7567F4D5AFDAD3A19663E5923771E999DD4
2876SStap-2018.7.10.exeC:\Program Files\SSTap\bin\plink.exeexecutable
MD5:720E00F913830C4FE2E7C481A9748D70
SHA256:EE105FED0641382408274DE9498A62509125074C91C86C56158A8B1A34CB3F25
856SStap-2018.7.10.exeC:\Users\admin\AppData\Local\Temp\738C.tmp\SStap-2018.7.10.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
63
TCP/UDP connections
12
DNS requests
9
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2524
SSTap.exe
GET
104.27.169.90:80
http://www.wynmd.club/wp-content/themes/gameplay/css/index.css?ver=5.0.3
US
malicious
2876
SStap-2018.7.10.exe
GET
200
50.62.160.125:80
http://hofosetup.com/update/install/data.zip
US
binary
544 b
malicious
2876
SStap-2018.7.10.exe
GET
200
50.62.160.125:80
http://hofosetup.com/update/install/data2.zip
US
binary
638 b
malicious
2876
SStap-2018.7.10.exe
POST
302
50.62.160.125:80
http://api.hofosetup.com/report.asp
US
html
243 b
malicious
2876
SStap-2018.7.10.exe
POST
302
50.62.160.125:80
http://api.hofosetup.com/report.asp
US
html
239 b
malicious
2876
SStap-2018.7.10.exe
GET
200
50.62.160.125:80
http://hofosetup.com/update/install/data2.zip
US
binary
638 b
malicious
2524
SSTap.exe
GET
200
104.27.169.90:80
http://www.wynmd.club/category/jump-run/
US
html
7.50 Kb
malicious
2876
SStap-2018.7.10.exe
GET
200
139.199.14.96:80
http://www.hofosoft.cn/api/report.asp?type=open&value=Install_time&uuid=NS010797652327019920&ip=185.253.99.100
CN
text
2 b
malicious
2876
SStap-2018.7.10.exe
GET
200
139.199.14.96:80
http://www.hofosoft.cn/api/report.asp?type=install&value=SSTap&uuid=NS010797652327019920&ip=185.253.99.100
CN
text
2 b
malicious
2524
SSTap.exe
GET
200
104.27.169.90:80
http://www.wynmd.club/wp-content/themes/gameplay/css/OpenSans-Light-webfont.eot?
US
eot
13.3 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2876
SStap-2018.7.10.exe
50.62.160.125:80
api.hofosetup.com
GoDaddy.com, LLC
US
malicious
2876
SStap-2018.7.10.exe
139.199.14.96:80
www.hofosoft.cn
Shenzhen Tencent Computer Systems Company Limited
CN
malicious
2524
SSTap.exe
119.29.29.29:53
Shenzhen Tencent Computer Systems Company Limited
CN
malicious
2524
SSTap.exe
104.27.169.90:443
h.magichost.club
Cloudflare Inc
US
shared
2524
SSTap.exe
104.27.169.90:80
h.magichost.club
Cloudflare Inc
US
shared
2524
SSTap.exe
216.58.206.2:80
pagead2.googlesyndication.com
Google Inc.
US
whitelisted
2524
SSTap.exe
172.217.18.162:443
adservice.google.com
Google Inc.
US
whitelisted
2524
SSTap.exe
216.58.207.34:443
adservice.google.es
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
api.hofosetup.com
  • 50.62.160.125
malicious
hofosetup.com
  • 50.62.160.125
malicious
www.hofosoft.cn
  • 139.199.14.96
malicious
ht.magichost.club
  • 19.29.18.11
suspicious
h.magichost.club
  • 104.27.168.90
  • 104.27.169.90
malicious
www.wynmd.club
  • 104.27.169.90
  • 104.27.168.90
malicious
pagead2.googlesyndication.com
  • 216.58.206.2
whitelisted
adservice.google.es
  • 216.58.207.34
whitelisted
adservice.google.com
  • 172.217.18.162
whitelisted

Threats

PID
Process
Class
Message
2876
SStap-2018.7.10.exe
Misc activity
ADWARE [PTsecurity] Win32/Amonetize
2876
SStap-2018.7.10.exe
A Network Trojan was detected
MALWARE [PTsecurity] BehavesLike.Win32.Dropper.wc
2876
SStap-2018.7.10.exe
Misc activity
ADWARE [PTsecurity] Win32/Amonetize
2876
SStap-2018.7.10.exe
A Network Trojan was detected
MALWARE [PTsecurity] BehavesLike.Win32.Dropper.wc
Process
Message
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.
SSTap.exe
Invalid parameter passed to C runtime function.