IOC Report
https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Unconfirmed 293673.crdownload
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\Downloads\hp-hpia-5.2.1.exe (copy)
PE32+ executable (GUI) x86-64, for MS Windows
dropped
Chrome Cache Entry: 43
PE32+ executable (GUI) x86-64, for MS Windows
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1884 --field-trial-handle=2520,i,9680638350717332926,39774128382146307,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5416 --field-trial-handle=2520,i,9680638350717332926,39774128382146307,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Users\user\Downloads\hp-hpia-5.2.1.exe
"C:\Users\user\Downloads\hp-hpia-5.2.1.exe"

URLs

Name
IP
Malicious
https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe
https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe
18.160.60.98

Domains

Name
IP
Malicious
hpia.hpcloud.hp.com
18.160.60.98
www.google.com
64.233.177.99

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
18.160.60.98
hpia.hpcloud.hp.com
United States
192.168.2.4
unknown
unknown
64.233.177.99
www.google.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF649E5A000
unkown
page readonly
A88F8EE000
stack
page read and write
22EC72F0000
trusted library section
page read and write
22EC5AA1000
heap
page read and write
7FF649E55000
unkown
page read and write
7FF649DD1000
unkown
page execute read
22EC5ABA000
heap
page read and write
7FF649DD1000
unkown
page execute read
7FF649DD0000
unkown
page readonly
22EC5A5C000
heap
page read and write
22EC5AA2000
heap
page read and write
22EC7E09000
heap
page read and write
22EC74D0000
heap
page read and write
22EC5A9E000
heap
page read and write
7FF649E31000
unkown
page readonly
22EC5A50000
heap
page read and write
22EC7310000
trusted library section
page read and write
22EC74C0000
heap
page read and write
22EC58D0000
heap
page read and write
22EC7673000
heap
page read and write
22EC7672000
heap
page read and write
7FF649E53000
unkown
page read and write
22EC7393000
heap
page read and write
22EC5AB9000
heap
page read and write
7FF649E53000
unkown
page write copy
22EC7350000
heap
page read and write
7FF649E54000
unkown
page write copy
22EC7E00000
heap
page read and write
22EC7340000
heap
page read and write
A88F8F7000
stack
page read and write
22EC5A8E000
heap
page read and write
22EC74D4000
heap
page read and write
22EC7670000
heap
page read and write
22EC7390000
heap
page read and write
22EC5A59000
heap
page read and write
7FF649DD0000
unkown
page readonly
22EC5A8E000
heap
page read and write
7FF649E31000
unkown
page readonly
22EC59B0000
heap
page read and write
A88FAFE000
stack
page read and write
A88F9FE000
stack
page read and write
22EC74C5000
heap
page read and write
22EC5A92000
heap
page read and write
22EC5AD7000
heap
page read and write
22EC5A8E000
heap
page read and write
22EC7671000
heap
page read and write
7FF649E5A000
unkown
page readonly
22EC9160000
trusted library allocation
page read and write
22EC59E0000
heap
page read and write
A88FBFE000
stack
page read and write
22EC5A82000
heap
page read and write
22EC7300000
trusted library section
page read and write
There are 42 hidden memdumps, click here to show them.