File name:

Setup.exe

Full analysis: https://app.any.run/tasks/a60e6c4b-832f-4fcd-80da-622aa81634d0
Verdict: Malicious activity
Analysis date: December 19, 2023, 16:58:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

18B4B4C0910D9B1B7C411962403240BB

SHA1:

C8BCE50FB63681ACD77EE8C6C7CECCD2B95A72CD

SHA256:

02DCA5F8626C5874553A4B6F48146D196F580E20B8F94DCC5021A26F4897504D

SSDEEP:

98304:ogIrPHNqA7u880727qoAk4NONn5Vf2Dw+5KqRSmnUFXcdnI1LCBsNPx2XpP6djBS:0h3CqzAeYL1EiO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup.exe (PID: 1776)
      • Setup.tmp (PID: 784)
      • setup_server_ung.exe (PID: 1772)
      • Setup.exe (PID: 668)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1936)
      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup.tmp (PID: 784)
    • Drops a system driver (possible attempt to evade defenses)

      • Setup.tmp (PID: 784)
      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1936)
      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
    • Reads settings of System Certificates

      • setup_server_ung.exe (PID: 1772)
      • UsbConfig.exe (PID: 2832)
    • Checks Windows Trust Settings

      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
      • drvinst.exe (PID: 188)
      • drvinst.exe (PID: 2028)
      • UsbService.exe (PID: 2816)
      • UsbConfig.exe (PID: 2832)
    • Reads security settings of Internet Explorer

      • setup_server_ung.exe (PID: 1772)
      • UsbConfig.exe (PID: 2832)
    • Executes as Windows Service

      • UsbService.exe (PID: 2816)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • Setup.tmp (PID: 784)
    • Reads the history of recent RDP connections

      • UsbConfig.exe (PID: 2832)
    • Searches for installed software

      • UsbConfig.exe (PID: 2832)
    • Reads the BIOS version

      • UsbService.exe (PID: 2816)
    • Reads the Internet Settings

      • UsbConfig.exe (PID: 2832)
    • Adds/modifies Windows certificates

      • UsbService.exe (PID: 2816)
    • Reads Internet Explorer settings

      • UsbConfig.exe (PID: 2832)
    • Reads Microsoft Outlook installation path

      • UsbConfig.exe (PID: 2832)
  • INFO

    • Reads the computer name

      • Setup.tmp (PID: 1356)
      • Setup.tmp (PID: 784)
      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
      • drvinst.exe (PID: 2028)
      • drvinst.exe (PID: 188)
      • UsbService.exe (PID: 1572)
      • UsbService.exe (PID: 2908)
      • UsbService.exe (PID: 2816)
      • UsbConfig.exe (PID: 2832)
    • Create files in a temporary directory

      • Setup.exe (PID: 668)
      • Setup.exe (PID: 1776)
      • Setup.tmp (PID: 784)
      • setup_server_ung.exe (PID: 1772)
    • Checks supported languages

      • Setup.exe (PID: 1776)
      • Setup.tmp (PID: 784)
      • Setup.exe (PID: 668)
      • setup_server_ung.exe (PID: 1772)
      • Setup.tmp (PID: 1356)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 2028)
      • drvinst.exe (PID: 188)
      • UsbService.exe (PID: 2908)
      • UsbService.exe (PID: 1572)
      • UsbService.exe (PID: 240)
      • UsbService.exe (PID: 2816)
      • UsbConfig.exe (PID: 2832)
      • drvinst.exe (PID: 1736)
    • Creates files in the program directory

      • Setup.tmp (PID: 784)
      • UsbService.exe (PID: 1572)
      • UsbService.exe (PID: 2816)
      • UsbConfig.exe (PID: 2832)
    • Reads the machine GUID from the registry

      • setup_server_ung.exe (PID: 1772)
      • drvinst.exe (PID: 1936)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 1736)
      • drvinst.exe (PID: 2028)
      • drvinst.exe (PID: 188)
      • UsbService.exe (PID: 1572)
      • UsbConfig.exe (PID: 2832)
      • UsbService.exe (PID: 2816)
    • Reads CPU info

      • UsbService.exe (PID: 2816)
      • UsbService.exe (PID: 1572)
    • Checks proxy server information

      • UsbConfig.exe (PID: 2832)
    • Creates files or folders in the user directory

      • UsbConfig.exe (PID: 2832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 16:39:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 9.0.2236.0
ProductVersionNumber: 9.0.2236.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Electronic Team
FileDescription: USB Network Gate
FileVersion: Usb Network Gate 9.0
LegalCopyright: Copyright © 2000-2020 Electronic Team, Inc. All rights reserved.
ProductName: USB Network Gate
ProductVersion: Usb Network Gate 9.0.2236
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
17
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe no specs setup.tmp no specs setup.exe setup.tmp no specs setup_server_ung.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs usbservice.exe usbservice.exe no specs usbservice.exe no specs usbservice.exe netsh.exe no specs netsh.exe no specs usbconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
188DrvInst.exe "1" "200" "UsbEStub\Devices\0000" "" "" "655b45ca3" "00000000" "000005F0" "000005E4"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
240"C:\Program Files\Electronic Team\USB Network Gate\UsbService.exe" migrateC:\Program Files\Electronic Team\USB Network Gate\UsbService.exeSetup.tmp
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
4294967295
Version:
9.0.2236
Modules
Images
c:\program files\electronic team\usb network gate\usbservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
668"C:\Users\admin\AppData\Local\Temp\Setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\Setup.exe
Setup.tmp
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
0
Version:
Usb Network Gate 9.0
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
784"C:\Users\admin\AppData\Local\Temp\is-K9MBJ.tmp\Setup.tmp" /SL5="$501AC,5153551,121344,C:\Users\admin\AppData\Local\Temp\Setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-K9MBJ.tmp\Setup.tmpSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k9mbj.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1356"C:\Users\admin\AppData\Local\Temp\is-EK5EB.tmp\Setup.tmp" /SL5="$301AA,5153551,121344,C:\Users\admin\AppData\Local\Temp\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-EK5EB.tmp\Setup.tmpSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ek5eb.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1572"C:\Program Files\Electronic Team\USB Network Gate\UsbService.exe" install E232F16E-D109-45DB-A1D3-DD21BEB3B75FC:\Program Files\Electronic Team\USB Network Gate\UsbService.exe
Setup.tmp
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
4294967295
Version:
9.0.2236
Modules
Images
c:\program files\electronic team\usb network gate\usbservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
1736DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "vuh.inf:Electronic.NTx86:VUHUB_Device:9.0.2205.0:vuhub" "625e1bb63" "000003F8" "000003BC" "000005E4"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1772"C:\Program Files\Electronic Team\USB Network Gate\drv\NT6\setup_server_ung.exe"C:\Program Files\Electronic Team\USB Network Gate\drv\NT6\setup_server_ung.exeSetup.tmp
User:
admin
Company:
Electronic Team, Inc.
Integrity Level:
HIGH
Description:
Setup USB drivers
Exit code:
0
Version:
2.6.2
Modules
Images
c:\program files\electronic team\usb network gate\drv\nt6\setup_server_ung.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1776"C:\Users\admin\AppData\Local\Temp\Setup.exe" C:\Users\admin\AppData\Local\Temp\Setup.exeexplorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
Usb Network Gate 9.0
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1816DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2e9ba3d0-228e-1ba5-7066-26212f33d328}\vuh.inf" "0" "625e1bb63" "000003F8" "WinSta0\Default" "000005C0" "208" "c:\program files\electronic team\usb network gate\drv\nt6"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
29 656
Read events
29 324
Write events
326
Delete events
6

Modification events

(PID) Process:(1772) setup_server_ung.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1936) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1816) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1736) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1736) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
130000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F00000010000000110000001200000013000000
(PID) Process:(1736) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
140000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000
(PID) Process:(2028) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2028) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
140000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000
(PID) Process:(2028) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
150000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000
(PID) Process:(188) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
50
Suspicious files
85
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\sessapart32.dllexecutable
MD5:6399E1E8AF96FAE43DDF7141B2ED12DD
SHA256:10D43A69192E57A6D71D26CDEEF1F6B65020FFFBD4EA48450D785F03827446F9
668Setup.exeC:\Users\admin\AppData\Local\Temp\is-K9MBJ.tmp\Setup.tmpexecutable
MD5:1E3F8EF861175CE4C64566A6B58756AE
SHA256:58C74F8BA18CEF9DFD57CF2C33915DDCF3A2F3510EAEBBDA178713E1E769A35E
784Setup.tmpC:\Users\admin\AppData\Local\Temp\is-41D3U.tmp\reset.dllexecutable
MD5:1FB1431779318F095681607EACCC1C04
SHA256:EF4465A8765B207BAB591CB1BD2BB0402CE60A1F99C5391B1BEB65936BC6869C
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\is-JFJEU.tmpexecutable
MD5:42BE85CD7A4B410EE46F24D819FDFD70
SHA256:FBF0269654F9539216AB6B50C01C93944B2590EB55DAF0274B3AA8F440973603
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\is-5O742.tmpexecutable
MD5:1E3F8EF861175CE4C64566A6B58756AE
SHA256:58C74F8BA18CEF9DFD57CF2C33915DDCF3A2F3510EAEBBDA178713E1E769A35E
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\is-SLT98.tmpexecutable
MD5:B8D5929235B1E3FEB6867ECF616576DE
SHA256:1DAF8DB5C3FD96A885FF9F7C9303D56B6704A284B9E78902DF477506F3EA9786
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\usb4citrix.dllexecutable
MD5:42BE85CD7A4B410EE46F24D819FDFD70
SHA256:FBF0269654F9539216AB6B50C01C93944B2590EB55DAF0274B3AA8F440973603
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\u2ec.dllexecutable
MD5:14BEB39A731DEA957B5EE11E18BDCCA9
SHA256:3628C90FC84E9BFEBA3E7CCA8A138240BCD7B95D5B63FAC7A70AF4AC6BBA6E71
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\AutoUpdate.dllexecutable
MD5:B8D5929235B1E3FEB6867ECF616576DE
SHA256:1DAF8DB5C3FD96A885FF9F7C9303D56B6704A284B9E78902DF477506F3EA9786
784Setup.tmpC:\Program Files\Electronic Team\USB Network Gate\unins000.exeexecutable
MD5:1E3F8EF861175CE4C64566A6B58756AE
SHA256:58C74F8BA18CEF9DFD57CF2C33915DDCF3A2F3510EAEBBDA178713E1E769A35E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
27
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2816
UsbService.exe
GET
200
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?75a637ffbd26fa7b
unknown
compressed
65.2 Kb
unknown
2832
UsbConfig.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c893a4f26d8123fd
unknown
compressed
4.66 Kb
unknown
2832
UsbConfig.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
binary
2.18 Kb
unknown
2832
UsbConfig.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1572
UsbService.exe
78.46.96.38:443
appstatico.electronic.us
Hetzner Online GmbH
DE
unknown
2816
UsbService.exe
173.222.108.195:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
2816
UsbService.exe
188.40.191.126:443
activate.electronic.us
Hetzner Online GmbH
DE
unknown
2832
UsbConfig.exe
192.168.100.255:5474
whitelisted
2816
UsbService.exe
78.46.96.38:443
appstatico.electronic.us
Hetzner Online GmbH
DE
unknown
2832
UsbConfig.exe
212.102.56.182:443
cdn.electronic.us
Datacamp Limited
DE
unknown
2832
UsbConfig.exe
184.24.77.199:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
appstatico.electronic.us
  • 78.46.96.38
unknown
ctldl.windowsupdate.com
  • 173.222.108.195
  • 173.222.108.210
  • 173.222.108.249
  • 173.222.108.201
  • 184.24.77.199
  • 184.24.77.174
  • 184.24.77.208
  • 184.24.77.206
  • 184.24.77.176
  • 184.24.77.207
  • 184.24.77.205
  • 184.24.77.209
whitelisted
activate.electronic.us
  • 188.40.191.126
unknown
cdn.electronic.us
  • 212.102.56.182
  • 212.102.56.179
  • 156.146.33.137
  • 195.181.175.15
  • 195.181.170.19
  • 195.181.175.40
  • 156.146.33.141
unknown
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info