File name:

Connectify Hotspot 2015.0.4.34734.rar

Full analysis: https://app.any.run/tasks/d29b0edc-f0e7-44a1-b6e2-53157690adc3
Verdict: Malicious activity
Analysis date: April 29, 2025, 04:31:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v2.0, os: Win32, flags: FirstVolume
MD5:

2079F5A8853799D89053DBAD70BCA117

SHA1:

68231CBB623DB494596E73F41B6D4FB999C9B774

SHA256:

03337D17D4344D7DE4D26E8CFF02AEC17F8C851B813A4C0C6293D76FFEB53878

SSDEEP:

98304:r/dUwrSJF8GUby7k7hS0w/yx/EyCooLn65r5wIGZ79fhSBK+CoNoFUsXhGKyW/iW:+FJPg33KNKQjMzaKH6EruLuo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2448)
    • Executing a file with an untrusted certificate

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2016)
      • ConnectifySupportCenter.exe (PID: 2724)
      • GlobalAtomTable.exe (PID: 1980)
      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 3752)
      • ConnectifyShutdown.exe (PID: 872)
      • DriverSwitcher.exe (PID: 2496)
      • Analytics.exe (PID: 2204)
      • Analytics.exe (PID: 1980)
      • GlobalAtomTable.exe (PID: 2120)
      • Connectify.exe (PID: 3788)
      • Analytics.exe (PID: 2460)
      • Analytics.exe (PID: 2840)
      • GlobalAtomTable.exe (PID: 1628)
      • GlobalAtomTable.exe (PID: 1824)
      • ConnectifyGopher.exe (PID: 2964)
      • GlobalAtomTable.exe (PID: 2716)
      • GlobalAtomTable.exe (PID: 3380)
      • ConnectifyGopher.exe (PID: 3508)
      • DispatchUI.exe (PID: 3892)
      • GlobalAtomTable.exe (PID: 3996)
      • GlobalAtomTable.exe (PID: 3964)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Connectify2015Installer.exe (PID: 1460)
    • Changes the autorun value in the registry

      • Connectify2015Installer.exe (PID: 1460)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2448)
      • Connectify2015Installer.exe (PID: 1460)
      • snetcfg.exe (PID: 3368)
    • The process creates files with name similar to system file names

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
    • Executable content was dropped or overwritten

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
    • Application launched itself

      • Connectify2015Installer.exe (PID: 1404)
      • Analytics.exe (PID: 2016)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 2204)
      • WinRAR.exe (PID: 3684)
      • WinRAR.exe (PID: 2448)
      • Analytics.exe (PID: 2460)
    • Starts application with an unusual extension

      • Connectify2015Installer.exe (PID: 1460)
    • There is functionality for taking screenshot (YARA)

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
    • Reads the Internet Settings

      • Analytics.exe (PID: 2532)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3752)
    • Reads Microsoft Outlook installation path

      • Connectify2015Installer.exe (PID: 1460)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 3228)
      • schtasks.exe (PID: 3364)
      • schtasks.exe (PID: 3108)
    • Suspicious use of NETSH.EXE

      • ConnectifyShutdown.exe (PID: 872)
    • Creates a software uninstall entry

      • Connectify2015Installer.exe (PID: 1460)
    • Drops a system driver (possible attempt to evade defenses)

      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Reads settings of System Certificates

      • rundll32.exe (PID: 2924)
      • snetcfg.exe (PID: 3368)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3084)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3792)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 2164)
      • ctfmon.exe (PID: 2152)
    • The process deletes folder without confirmation

      • runonce.exe (PID: 2416)
    • Uses ICACLS.EXE to modify access control lists

      • Connectifyd.exe (PID: 1704)
      • Connectify.exe (PID: 2552)
    • Starts CMD.EXE for commands execution

      • runonce.exe (PID: 2416)
    • Connects to unusual port

      • Connectify.exe (PID: 2552)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2448)
      • WinRAR.exe (PID: 4084)
    • Checks supported languages

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • ns5C09.tmp (PID: 3044)
      • ns5438.tmp (PID: 1888)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2532)
      • ns6467.tmp (PID: 984)
      • GlobalAtomTable.exe (PID: 1980)
      • ns66C9.tmp (PID: 2764)
      • Analytics.exe (PID: 2016)
      • ns6B9D.tmp (PID: 3820)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 3752)
      • ns6C88.tmp (PID: 3676)
      • ConnectifyShutdown.exe (PID: 872)
      • ConnectifySupportCenter.exe (PID: 2724)
      • DriverSwitcher.exe (PID: 2496)
      • ns8003.tmp (PID: 848)
      • ns73EC.tmp (PID: 3232)
      • ns8081.tmp (PID: 3152)
      • snetcfg.exe (PID: 1124)
      • snetcfg.exe (PID: 3868)
      • snetcfg.exe (PID: 4080)
      • snetcfg.exe (PID: 2092)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Create files in a temporary directory

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
    • Reads the computer name

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2016)
      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3628)
      • ConnectifyShutdown.exe (PID: 872)
      • Analytics.exe (PID: 3752)
      • ConnectifySupportCenter.exe (PID: 2724)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Process checks whether UAC notifications are on

      • Connectify2015Installer.exe (PID: 1404)
    • Creates files in the program directory

      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2532)
      • Connectify2015Installer.exe (PID: 1460)
    • Reads the machine GUID from the registry

      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2532)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 2016)
      • ConnectifySupportCenter.exe (PID: 2724)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 3752)
      • ConnectifyShutdown.exe (PID: 872)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • The sample compiled with english language support

      • Connectify2015Installer.exe (PID: 1460)
    • Disables trace logs

      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3752)
    • Reads Environment values

      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3752)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 3084)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2924)
    • Reads the software policy settings

      • rundll32.exe (PID: 2924)
      • drvinst.exe (PID: 3084)
      • snetcfg.exe (PID: 3368)
    • Manual execution by a user

      • Connectify.exe (PID: 3788)
      • runonce.exe (PID: 2416)
      • Connectify.exe (PID: 2552)
      • IMEKLMG.EXE (PID: 2544)
      • IMEKLMG.EXE (PID: 2536)
      • conhost.exe (PID: 2736)
      • Connectify.exe (PID: 3120)
      • conhost.exe (PID: 3400)
      • conhost.exe (PID: 3620)
      • conhost.exe (PID: 3980)
      • conhost.exe (PID: 4016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 10318821
UncompressedSize: 10318768
OperatingSystem: Win32
ModifyDate: 2015:04:28 09:06:12
PackingMethod: Stored
ArchivedFileName: Connectify2015Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
79
Malicious processes
15
Suspicious processes
21

Behavior graph

Click at the process to see the details
start start winrar.exe connectify2015installer.exe connectify2015installer.exe ns5438.tmp no specs analytics.exe no specs ns5c09.tmp no specs analytics.exe no specs analytics.exe ns6467.tmp no specs globalatomtable.exe no specs ns66c9.tmp no specs connectifysupportcenter.exe no specs ns6b9d.tmp no specs analytics.exe no specs analytics.exe ns6c88.tmp no specs connectifyshutdown.exe no specs netsh.exe no specs ns73ec.tmp no specs schtasks.exe no specs regsvr32.exe no specs ns8003.tmp no specs schtasks.exe no specs ns8081.tmp no specs driverswitcher.exe pnputil.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs nsda4a.tmp no specs analytics.exe no specs analytics.exe nsdb35.tmp no specs globalatomtable.exe no specs nsdd0b.tmp no specs globalatomtable.exe no specs nsddc8.tmp no specs schtasks.exe no specs nsbce.tmp no specs analytics.exe no specs analytics.exe winrar.exe no specs winrar.exe connectify.exe no specs globalatomtable.exe no specs connectifyservice.exe no specs connectifyd.exe icacls.exe no specs icacls.exe no specs ctfmon.exe no specs sipnotify.exe icacls.exe no specs icacls.exe no specs runonce.exe cmd.exe no specs conhost.exe no specs imeklmg.exe no specs imeklmg.exe no specs connectify.exe globalatomtable.exe no specs conhost.exe no specs connectifygopher.exe connectify.exe no specs globalatomtable.exe no specs conhost.exe no specs connectifygopher.exe no specs icacls.exe no specs conhost.exe no specs connectify.exe no specs dispatchui.exe no specs globalatomtable.exe no specs conhost.exe no specs globalatomtable.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700"icacls" C:\ProgramData\Connectify /T /Q /C /grant Everyone:(F)C:\Windows\System32\icacls.exeConnectifyd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
848"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmp" C:\Windows\system32\schtasks.exe /delete /TN "ConnectifyInstallerTask" /FC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\ns8003.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
872"C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown"C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown.exens6C88.tmp
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Description:
Connectify Shutdown App
Exit code:
0
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\connectify\5\connectifyshutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
984"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Check ConnectifyC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\ns6467.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1032"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set ConnectifyC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\nsdd0b.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1124"Exes\i386\snetcfg.exe" -v -u nt_cnnctfy2C:\Users\admin\AppData\Local\Temp\Connectify\DriverSwitcher\976\Exes\i386\snetcfg.exeDriverSwitcher.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
network config sample
Exit code:
1
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\users\admin\appdata\local\temp\connectify\driverswitcher\976\exes\i386\snetcfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1404"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe
WinRAR.exe
User:
admin
Company:
Connectify
Integrity Level:
MEDIUM
Description:
Connectify 2015
Exit code:
1223
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.44073\connectify2015installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1460"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" /UAC:40182 /NCRC C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe
Connectify2015Installer.exe
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Description:
Connectify 2015
Exit code:
1223
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.44073\connectify2015installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1628"C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set ConnectifyC:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exensDB35.tmp
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Exit code:
0
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\connectify\5\globalatomtable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1632"C:\Program Files\Connectify\ConnectifyService.exe"C:\Program Files\Connectify\ConnectifyService.exeservices.exe
User:
SYSTEM
Company:
Connectify
Integrity Level:
SYSTEM
Version:
2015.0.5.34877
Modules
Images
c:\program files\connectify\connectifyservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\connectify\nativelibrary.dll
c:\program files\connectify\log4cplus.dll
Total events
46 911
Read events
46 231
Write events
628
Delete events
52

Modification events

(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Connectify Hotspot 2015.0.4.34734.rar
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
91
Suspicious files
170
Text files
258
Unknown types
3

Dropped files

PID
Process
Filename
Type
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\cracked.zipcompressed
MD5:53D046EE9453A05AFEDBA857D899F027
SHA256:88245461FB3186F2E5CDC3E2CCFDC92DA1901C2F1D6BB4CF09FA5496D33846B2
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\modern-wizard.bmpimage
MD5:AE43624C14859150EDFB54B4024AFF46
SHA256:D5B56046F10941E6659277D46FFD4A0D327DB24BE3174D6A8E7AE0660DA874E9
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\modern-header.bmpimage
MD5:F50B6CEE1BE90D50AF582E57528C7000
SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\UAC.dllexecutable
MD5:7F56C0D6A8733DEC142814ED5A58B0EE
SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exeexecutable
MD5:83B12271BEBCBE7A358CFE4501C0BD67
SHA256:C298D198591A8563FFC5453770FDCDA1A91E6657C026EE234E5794F13354EA1B
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\UAC.dllexecutable
MD5:7F56C0D6A8733DEC142814ED5A58B0EE
SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\modern-header.bmpimage
MD5:F50B6CEE1BE90D50AF582E57528C7000
SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\Connectify\5\Analytics.exeexecutable
MD5:E940D9CBB97A254946B7DEBCD64EA258
SHA256:F1E94BE7CB362B7D5F2BD5DEDB732187F19B4EA1278B41911ED6439F27B285E6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
42
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2532
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1927071427&utmhn=connectify.connectify.me&utmp=Installer%2fInit%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fInit%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
3752
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=402600594&utmhn=connectify.connectify.me&utmp=Installer%2fStart%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fStart%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
2840
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=431537628&utmhn=connectify.connectify.me&utmp=Installer%2fDriver%2fReboot%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fDriver%2fReboot%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
1980
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=609938169&utmhn=connectify.connectify.me&utmp=Installer%2fSuccess%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fSuccess%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
1704
Connectifyd.exe
GET
301
104.22.77.194:80
http://updates.connectify.me/settings.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0
unknown
whitelisted
2164
sipnotify.exe
HEAD
503
104.102.43.250:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133903785778750000
unknown
whitelisted
1704
Connectifyd.exe
GET
301
104.22.77.194:80
http://updates.connectify.me/dialerkeys.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0
unknown
whitelisted
2552
Connectify.exe
GET
200
52.216.42.165:80
http://data.connectify.me/driver.dat
unknown
whitelisted
1704
Connectifyd.exe
GET
200
142.250.186.174:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON
unknown
whitelisted
1704
Connectifyd.exe
GET
200
142.250.186.174:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2532
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
3752
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
2840
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
1980
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
1152
svchost.exe
224.0.0.252:5355
whitelisted
1484
svchost.exe
239.255.255.250:3702
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
www.google-analytics.com
  • 142.250.184.238
  • 142.250.186.174
whitelisted
updates.connectify.me
  • 104.22.77.194
  • 104.22.76.194
  • 172.67.36.143
whitelisted
query.prod.cms.rt.microsoft.com
  • 104.102.43.250
whitelisted
data.connectify.me
  • 52.216.42.165
  • 3.5.3.55
  • 54.231.235.29
  • 3.5.13.129
  • 54.231.227.149
  • 3.5.13.117
  • 3.5.2.119
  • 52.217.92.211
whitelisted
d1.connectify.me
  • 104.22.77.194
  • 104.22.76.194
  • 172.67.36.143
whitelisted
ctldl.windowsupdate.com
  • 217.20.57.35
  • 217.20.57.19
  • 217.20.57.36
  • 84.201.210.23
  • 217.20.57.34
  • 217.20.57.18
  • 217.20.57.20
whitelisted
news.connectify.me
  • 52.216.78.19
  • 54.231.139.221
  • 52.217.122.37
  • 3.5.13.140
  • 54.231.226.117
  • 52.217.198.133
  • 52.217.202.85
  • 52.217.126.69
whitelisted
c.pki.goog
  • 142.250.185.227
whitelisted

Threats

No threats detected
No debug info