Edit tour
Windows
Analysis Report
AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Overview
General Information
Detection
Score: | 26 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 20% |
Compliance
Score: | 49 |
Range: | 0 - 100 |
Signatures
.NET source code contains method to dynamically call methods (often used by packers)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Yara detected Generic Downloader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Connects to many different domains
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Drops PE files
Drops certificate files (DER)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
HTML page contains hidden javascript code
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w10x64
- AirDroid_Cast_Desktop_Client_1.2.1.0.exe (PID: 6316 cmdline:
"C:\Users\ user\Deskt op\AirDroi d_Cast_Des ktop_Clien t_1.2.1.0. exe" MD5: 637A0FD3E65D39AD0C6C3D5CC042C4DE) - Helper.exe (PID: 7156 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /cef MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Launcher.exe (PID: 3604 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\La uncher.exe " MD5: CD3C5A78EE09451D22E17F297CE072C3) - Helper.exe (PID: 5460 cmdline:
"/C:\Progr am Files ( x86)\AirDr oid Cast\h elper.exe" "/shortcu t" "C:\Pro gram Files (x86)\Air Droid Cast \AirDroidC ast.exe" MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - AirDroidCast.exe (PID: 2692 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\Ai rDroidCast .exe" MD5: 49C94164E66D29A783E2BC858D1568FD) - adb_helper.exe (PID: 5004 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\In cludeAdb\a db_helper. exe" devic es MD5: 41C69E96E17FEBE6DCB309A323E3A71C) - conhost.exe (PID: 5244 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - adb_helper.exe (PID: 2300 cmdline:
adb -L tcp :5037 fork -server se rver --rep ly-fd 612 MD5: 41C69E96E17FEBE6DCB309A323E3A71C) - usbmuxd.exe (PID: 4592 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\us bmuxd\usbm uxd.exe" - r airdroid _cast_lock down MD5: F2600C9676A718D7B49BE9F32E222D6B) - conhost.exe (PID: 5596 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - Helper.exe (PID: 5172 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172829504 4&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 8080 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172863229 8&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 7180 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172892429 0&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 6580 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172922759 2&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 2844 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172943620 1&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 7564 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =172988110 9&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 2264 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173174099 9&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 6696 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173193000 1&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 3676 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173238555 2&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 5456 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173257242 1&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 8000 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173280882 3&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 500 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173303761 9&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 1800 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173343002 1&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 2288 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173361477 6&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 7788 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173381836 9&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 4140 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173407266 2&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 4484 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173429948 4&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 7124 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173453693 1&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 6020 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173479591 6&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 5584 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173507345 6&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 2948 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173532179 6&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 5576 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173556193 7&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 7432 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173586711 8&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 3960 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173617491 0&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - Helper.exe (PID: 8936 cmdline:
"C:\Progra m Files (x 86)\AirDro id Cast\He lper.exe" /update /s ilent "C:\ Program Fi les (x86)\ AirDroid C ast\AirDro idCast.exe " "AirDroi d Cast" "h ttps://srv 3.airdroid .com/p20/c ast/pcupgr ade?v=1.2. 1.0&inner_ version=12 10&type=63 &lang=en&a pp_channel =0&os_vers ion=10.0.1 9045&incre mental_upd ate=1&beta =0" "" 0 0 0 0 1 "C: \Users\use r\AppData\ Roaming\Ai rDroidCast \Cache\Cac heInfo.txt " "https:/ /www.airdr oid.com/{0 }/cast/?_t =173707966 3&app_ver= 1.2.1.0&de vice_type= 63&app_cha nnel=0&lan guage=en&v ersion=121 0&os_verio n=10.0&jto ken=&mode_ type=2&acc ount_id=0" "" -999 MD5: B8863BE3E3AE0FF06DED82DE94DD75A2) - chrome.exe (PID: 1712 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// www.airdro id.com/tha nkyou/inst all-airdro id-cast.ht ml MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6868 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2464 --fi eld-trial- handle=208 8,i,423686 1329904630 897,402692 2523893907 418,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 2932 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// m-embed.ai rdroid.com /cast_link .html?aird roidCast-c ode=028461 947 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7184 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2052 --fi eld-trial- handle=199 2,i,170232 9221283246 3388,15458 2558841098 08151,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security |
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-07T11:57:20.411035+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49827 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:20.412776+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49826 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:21.268774+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49859 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:21.313831+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49860 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:22.500106+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49890 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:22.794617+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49891 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:25.072159+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49936 | 170.106.112.204 | 443 | TCP |
2024-10-07T11:57:25.909249+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49916 | 49.51.181.65 | 443 | TCP |
2024-10-07T11:57:26.190621+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49957 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:28.606822+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50005 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:28.973346+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50007 | 170.106.112.204 | 443 | TCP |
2024-10-07T11:57:29.449418+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50009 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:30.286934+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50022 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:31.438283+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50047 | 170.106.112.204 | 443 | TCP |
2024-10-07T11:57:32.827523+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50066 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:36.066500+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50101 | 49.51.42.41 | 443 | TCP |
2024-10-07T11:57:36.066978+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 50100 | 49.51.42.41 | 443 | TCP |
Click to jump to signature section
Show All Signature Results
Source: | HTTP Parser: |
Compliance |
---|
Source: | Static PE information: |
Source: | Window detected: |