| File name: | EndpointBasecamp (2).exe |
| Full analysis: | https://app.any.run/tasks/093fd055-2d0c-47c6-bf20-ae25679298f4 |
| Verdict: | Malicious activity |
| Analysis date: | October 15, 2021, 14:49:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 42F72C674AF9363CB6276A62EBF6BE59 |
| SHA1: | 696447F082687DB8C7569EA3098A70DB1CC15BE7 |
| SHA256: | FD1DEC9F3C39445346060159ACFA67F6F1E178CFD8B60EA2F8422F74D700191B |
| SSDEEP: | 49152:YjgCr8Kjf2v8cGVOu/gnLSIzK5OINNTZ4bP6TPedSDeA+9:9zKL2v8cAgnLSI+nib |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:09:10 04:31:04+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.26 |
| CodeSize: | 1992704 |
| InitializedDataSize: | 676864 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x167406 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
| FileVersionNumber: | 1.1.0.1995 |
| ProductVersionNumber: | 1.1.0.1995 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build, Special build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | Trend Micro Endpoint Basecamp |
| FileVersion: | 1.1.0.1995 |
| ProductVersion: | 1.1 |
| ProductName: | Trend Micro Endpoint Basecamp |
| CompanyName: | Trend Micro Inc. |
| LegalCopyright: | Copyright (C) 2021 Trend Micro Incorporated. All rights reserved. |
| LegalTrademarks: | Copyright (C) Trend Micro Inc. |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_CUI |
| Compilation Date: | 10-Sep-2021 02:31:04 |
| Detected languages: |
|
| Debug artifacts: |
|
| FileDescription: | Trend Micro Endpoint Basecamp |
| FileVersion: | 1.1.0.1995 |
| ProductVersion: | 1.1 |
| ProductName: | Trend Micro Endpoint Basecamp |
| CompanyName: | Trend Micro Inc. |
| LegalCopyright: | Copyright (C) 2021 Trend Micro Incorporated. All rights reserved. |
| LegalTrademarks: | Copyright (C) Trend Micro Inc. |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000148 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 10-Sep-2021 02:31:04 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x001E676C | 0x001E6800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63748 |
.rdata | 0x001E8000 | 0x00064D64 | 0x00064E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.83662 |
.data | 0x0024D000 | 0x00027A80 | 0x0001BC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.3585 |
.rsrc | 0x00275000 | 0x00002B80 | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.5266 |
.reloc | 0x00278000 | 0x00021CF0 | 0x00021E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.71429 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.21628 | 2281 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.58987 | 4264 | Latin 1 / Western European | Chinese - Taiwan | RT_ICON |
101 | 2.18545 | 34 | Latin 1 / Western European | Chinese - Taiwan | RT_GROUP_ICON |
ADVAPI32.dll |
CRYPT32.dll |
IPHLPAPI.DLL |
KERNEL32.dll |
OLEAUT32.dll |
SHELL32.dll |
SHLWAPI.dll |
VERSION.dll |
WINHTTP.dll |
WINTRUST.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 408 | "C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (2).exe" | C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (2).exe | — | Explorer.EXE | |||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: MEDIUM Description: Trend Micro Endpoint Basecamp Exit code: 3221226540 Version: 1.1.0.1995 Modules
| |||||||||||||||
| 2340 | "C:\Windows\temp\zpibKmvFES9\tvSNwXLoxU2\TelemetryAgentServiceWebInstaller.exe" --install --env prod --region us1 --install-path "C:\Program Files\Trend Micro\Endpoint Basecamp\modules\ceta" --log-path "C:\Program Files\Trend Micro\Endpoint Basecamp\log" | C:\Windows\temp\zpibKmvFES9\tvSNwXLoxU2\TelemetryAgentServiceWebInstaller.exe | — | EndpointBasecamp.exe | |||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Cloud Endpoint Telemetry Service Web Installer Exit code: 0 Version: 1.1.0.447 Modules
| |||||||||||||||
| 2960 | "C:\\Program Files\\Trend Micro\\Endpoint Basecamp\\EndpointBasecamp.exe" /service | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | services.exe | ||||||||||||
User: SYSTEM Company: Trend Micro Inc. Integrity Level: SYSTEM Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.1995 Modules
| |||||||||||||||
| 3172 | "C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (2).exe" | C:\Users\admin\AppData\Local\Temp\EndpointBasecamp (2).exe | Explorer.EXE | ||||||||||||
User: admin Company: Trend Micro Inc. Integrity Level: HIGH Description: Trend Micro Endpoint Basecamp Exit code: 0 Version: 1.1.0.1995 Modules
| |||||||||||||||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\OfficeScan\DE |
| Operation: | write | Name: | InstallDateTime |
Value: 2021101500154936 | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000008292BA5BEFCD8A6FA63D55F984F6D6B77F0000000100000036000000303406082B06010505070303060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703071900000001000000100000002DC9CB9BB2FA9BA688D1D2AA642A33CC0B000000010000002E000000410066006600690072006D0054007200750073007400200043006F006D006D00650072006300690061006C00000053000000010000002400000030223020060A2B06010401828F09020130123010060A2B0601040182373C0101030200C06200000001000000200000000376AB1D54C5F9803CE4B2E201A0EE7EEF7B57B636E8A93C9B8D4860C96F5FA71400000001000000140000009D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F1D0000000100000010000000CF9381E42222DF55D1E3C07829CDFD1A030000000100000014000000F9B5B632455F9CBEEC575F80DCE96E2CC7B278B70F00000001000000200000001E2A4EF9C6208AEA146FE6074589F80FB1C7A73D2D20511B6F47D0E61874EB6A090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087E000000010000000800000000C001B39667D6012000000001000000500300003082034C30820234A00302010202087777062726A9B17C300D06092A864886F70D01010B05003044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C301E170D3130303132393134303630365A170D3330313233313134303630365A3044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C30820122300D06092A864886F70D01010105000382010F003082010A0282010100F61B4F67072BA115F50622CB1F01B2E373450644492CBB492514D6CEC3B7AB2C4FC641329457FA12A75B0EE28F1F1E8619A7AAB52DB95F0D8AC2AF853579322DBB1C6237F2B15B4A3DCACD715FE942BE94E8C8DEF9224864C6E5ABC62B6DAD05F0FAD50BCF9AE5F050A48B3B47A5235B7A7AF8333FB8EF9997E320C1D62889CF94FBB945EDE3401711D474F00B31E22B266A9B4C57AEAC203EBA457A05F3BD9B6915AE7D4E2063C435763A0702C937FDC747EEE8F1761D7315F297A4B5C87A79D942AA2B7F5CFECE264FA3668135AF44BA541E1C3032659DE63C935E504E7AE33AD46ECC1AFBF9D237AE242AAB570322280D49757FB728DA75BF8EE3DC0E79310203010001A3423040301D0603551D0E041604149D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106300D06092A864886F70D01010B0500038201010058ACF4040ECDC00DFF0AFDD4BA165F29BD7B68995849D2B41D374D7F277D46065D43C6862E3E73B2267D4F93A9B6C42A9AAB219714B1DE8CD3AB8915D86B24D4F116AED8A45CD47F518EED1801B19363BDBCF861809A9EB1CE4270E2A97D06257D27A1FE6FECB31E24DAE34B551A003B35B43BD9D75D30FD811389F2C2062BED67C48EC943B25C6B158902BC62FC4EF2B533AAB26FD30AA250E3F63BE82E44C2DB6638A9335648F16D1B338D0D8C3F60379DD3CA6D7E347E0D9F72768B1B9F72FD5235414502962F1CB29A734921B149474547B4EF6A3411C94D9ACC59B7D6029E5A4E65B594AE1BDF29B016F1BF009E073A1764B504B52321990A953B977CEF | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7 |
| Operation: | write | Name: | Blob |
Value: 5C0000000100000004000000000800007E000000010000000800000000C001B39667D601090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F00000001000000200000001E2A4EF9C6208AEA146FE6074589F80FB1C7A73D2D20511B6F47D0E61874EB6A030000000100000014000000F9B5B632455F9CBEEC575F80DCE96E2CC7B278B71D0000000100000010000000CF9381E42222DF55D1E3C07829CDFD1A1400000001000000140000009D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F6200000001000000200000000376AB1D54C5F9803CE4B2E201A0EE7EEF7B57B636E8A93C9B8D4860C96F5FA753000000010000002400000030223020060A2B06010401828F09020130123010060A2B0601040182373C0101030200C00B000000010000002E000000410066006600690072006D0054007200750073007400200043006F006D006D00650072006300690061006C0000001900000001000000100000002DC9CB9BB2FA9BA688D1D2AA642A33CC7F0000000100000036000000303406082B06010505070303060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703070400000001000000100000008292BA5BEFCD8A6FA63D55F984F6D6B72000000001000000500300003082034C30820234A00302010202087777062726A9B17C300D06092A864886F70D01010B05003044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C301E170D3130303132393134303630365A170D3330313233313134303630365A3044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C30820122300D06092A864886F70D01010105000382010F003082010A0282010100F61B4F67072BA115F50622CB1F01B2E373450644492CBB492514D6CEC3B7AB2C4FC641329457FA12A75B0EE28F1F1E8619A7AAB52DB95F0D8AC2AF853579322DBB1C6237F2B15B4A3DCACD715FE942BE94E8C8DEF9224864C6E5ABC62B6DAD05F0FAD50BCF9AE5F050A48B3B47A5235B7A7AF8333FB8EF9997E320C1D62889CF94FBB945EDE3401711D474F00B31E22B266A9B4C57AEAC203EBA457A05F3BD9B6915AE7D4E2063C435763A0702C937FDC747EEE8F1761D7315F297A4B5C87A79D942AA2B7F5CFECE264FA3668135AF44BA541E1C3032659DE63C935E504E7AE33AD46ECC1AFBF9D237AE242AAB570322280D49757FB728DA75BF8EE3DC0E79310203010001A3423040301D0603551D0E041604149D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106300D06092A864886F70D01010B0500038201010058ACF4040ECDC00DFF0AFDD4BA165F29BD7B68995849D2B41D374D7F277D46065D43C6862E3E73B2267D4F93A9B6C42A9AAB219714B1DE8CD3AB8915D86B24D4F116AED8A45CD47F518EED1801B19363BDBCF861809A9EB1CE4270E2A97D06257D27A1FE6FECB31E24DAE34B551A003B35B43BD9D75D30FD811389F2C2062BED67C48EC943B25C6B158902BC62FC4EF2B533AAB26FD30AA250E3F63BE82E44C2DB6638A9335648F16D1B338D0D8C3F60379DD3CA6D7E347E0D9F72768B1B9F72FD5235414502962F1CB29A734921B149474547B4EF6A3411C94D9ACC59B7D6029E5A4E65B594AE1BDF29B016F1BF009E073A1764B504B52321990A953B977CEF | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | proxy_server |
Value: | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | proxy_bypass |
Value: | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | upgrade_actions_freq_min |
Value: 3000 | |||
| (PID) Process: | (3172) EndpointBasecamp (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | upgrade_actions_freq_max |
Value: 4200 | |||
| (PID) Process: | (2960) EndpointBasecamp.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2960) EndpointBasecamp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\TMSecurityService |
| Operation: | write | Name: | proxy_server |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2960 | EndpointBasecamp.exe | C:\Windows\temp\zpibKmvFES9\hpxRp3ABclD.zip | compressed | |
MD5:— | SHA256:— | |||
| 3172 | EndpointBasecamp (2).exe | C:\Program Files\Trend Micro\Endpoint Basecamp\log\EndpointBasecamp.log | text | |
MD5:— | SHA256:— | |||
| 3172 | EndpointBasecamp (2).exe | C:\Program Files\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe | executable | |
MD5:— | SHA256:— | |||
| 2960 | EndpointBasecamp.exe | C:\Windows\Temp\zpibKmvFES9\tvSNwXLoxU2\TelemetryAgentServiceWebInstaller.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3172 | EndpointBasecamp (2).exe | 3.237.58.224:443 | api-us1.xbc.trendmicro.com | — | US | unknown |
2960 | EndpointBasecamp.exe | 3.237.58.224:443 | api-us1.xbc.trendmicro.com | — | US | unknown |
— | — | 51.124.78.146:443 | — | Microsoft Corporation | GB | whitelisted |
2960 | EndpointBasecamp.exe | 143.204.98.25:443 | release-us1.mgcp.trendmicro.com | — | US | suspicious |
2960 | EndpointBasecamp.exe | 3.229.229.85:443 | api-us1.xbc.trendmicro.com | — | US | unknown |
2960 | EndpointBasecamp.exe | 3.223.187.121:443 | api-us1.xbc.trendmicro.com | — | US | unknown |
3172 | EndpointBasecamp (2).exe | 3.223.187.121:443 | api-us1.xbc.trendmicro.com | — | US | unknown |
1936 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | — | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api-us1.xbc.trendmicro.com |
| unknown |
release-us1.mgcp.trendmicro.com |
| malicious |
settings-win.data.microsoft.com |
| whitelisted |