IOC Report
https://bpupdate.amadeus-leisure-it.com/9.10.102/BistroPortal_9.10.102_setup_de.msi

loading gif

Files

File Path
Type
Category
Malicious
C:\Config.Msi\52f118.rbs
data
dropped
C:\Program Files (x86)\BistroPortal\BPortal.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\BPortalWebUi.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\chrome_100_percent.pak
data
dropped
C:\Program Files (x86)\BistroPortal\chrome_200_percent.pak
data
dropped
C:\Program Files (x86)\BistroPortal\chrome_elf.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\d3dcompiler_47.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\icudtl.dat
data
dropped
C:\Program Files (x86)\BistroPortal\libEGL.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\libGLESv2.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\libcef.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\locales\af.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\am.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ar.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\bg.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\bn.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ca.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\cs.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\da.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\de.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\el.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\en-GB.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\en-US.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\es-419.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\es.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\et.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\fa.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\fi.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\fil.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\fr.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\gu.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\he.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\hi.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\hr.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\hu.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\id.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\it.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ja.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\kn.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ko.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\lt.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\lv.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ml.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\mr.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ms.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\nb.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\nl.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\pl.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\pt-BR.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\pt-PT.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ro.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ru.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\sk.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\sl.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\sr.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\sv.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\sw.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ta.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\te.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\th.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\tr.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\uk.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\ur.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\vi.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\zh-CN.pak
data
dropped
C:\Program Files (x86)\BistroPortal\locales\zh-TW.pak
data
dropped
C:\Program Files (x86)\BistroPortal\resources.pak
data
dropped
C:\Program Files (x86)\BistroPortal\snapshot_blob.bin
data
dropped
C:\Program Files (x86)\BistroPortal\v8_context_snapshot.bin
data
dropped
C:\Program Files (x86)\BistroPortal\vk_swiftshader.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\BistroPortal\vulkan-1.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BistroPortal\Amadeus Bistro Portal.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Wed Apr 17 11:01:44 2024, mtime=Thu Apr 25 06:11:48 2024, atime=Wed Apr 17 11:01:44 2024, length=7439408, window=hidenormal
dropped
C:\Users\Public\Desktop\Amadeus Bistro Portal.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Wed Apr 17 11:01:44 2024, mtime=Thu Apr 25 06:11:40 2024, atime=Wed Apr 17 11:01:44 2024, length=7439408, window=hidenormal
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 06:09:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 06:09:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 06:09:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 06:09:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 06:09:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\BistroPortal_9.10.102_setup_de.msi (copy)
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Amadeus Bistro Portal, Author: Amadeus Leisure IT GmbH, Keywords: Installer, Comments: This installer database contains the logic and data required to install Amadeus Bistro Portal., Template: Intel;1031, Revision Number: {7DE516CC-454E-46AF-B433-9115142FC1B5}, Create Time/Date: Thu Apr 18 09:32:18 2024, Last Saved Time/Date: Thu Apr 18 09:32:18 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
dropped
C:\Users\user\Downloads\Unconfirmed 365049.crdownload
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Amadeus Bistro Portal, Author: Amadeus Leisure IT GmbH, Keywords: Installer, Comments: This installer database contains the logic and data required to install Amadeus Bistro Portal., Template: Intel;1031, Revision Number: {7DE516CC-454E-46AF-B433-9115142FC1B5}, Create Time/Date: Thu Apr 18 09:32:18 2024, Last Saved Time/Date: Thu Apr 18 09:32:18 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
dropped
C:\Users\user\Downloads\e7b29052-a764-44ea-82c4-1af9067154bd.tmp
Composite Document File V2 Document, Can't read SAT
dropped
C:\Windows\Installer\MSI27EA.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
modified
C:\Windows\Installer\MSIFDAA.tmp
data
dropped
C:\Windows\Installer\SourceHash{E3BC9EF4-5C6C-4920-A151-24CBAABA025A}
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\{E3BC9EF4-5C6C-4920-A151-24CBAABA025A}\BistroIcon
MS Windows icon resource - 5 icons, 16x16, 8 bits/pixel, 32x32, 8 bits/pixel
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\Temp\~DF2F8BE6BDDAAD0D12.TMP
data
dropped
C:\Windows\Temp\~DF425179CC499F46DB.TMP
data
dropped
C:\Windows\Temp\~DF589E67984BA26261.TMP
data
dropped
C:\Windows\Temp\~DF7FFB6D8BB0475148.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF937DDAE1C8A256A4.TMP
Composite Document File V2 Document, Cannot read section info
dropped
There are 83 hidden files, click here to show them.

Domains

Name
IP
Malicious
www.google.com
108.177.122.147
bpupdate.amadeus-leisure-it.com
185.64.96.162

IPs

IP
Domain
Country
Malicious
172.253.124.101
unknown
United States
1.1.1.1
unknown
Australia
239.255.255.250
unknown
Reserved
185.64.96.162
bpupdate.amadeus-leisure-it.com
Germany
192.168.2.16
unknown
unknown
142.251.15.84
unknown
United States
108.177.122.138
unknown
United States
74.125.138.94
unknown
United States
108.177.122.147
www.google.com
United States