File name:

Connectify Hotspot 2015.0.4.34734.rar

Full analysis: https://app.any.run/tasks/d29b0edc-f0e7-44a1-b6e2-53157690adc3
Verdict: Malicious activity
Analysis date: April 29, 2025, 04:31:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v2.0, os: Win32, flags: FirstVolume
MD5:

2079F5A8853799D89053DBAD70BCA117

SHA1:

68231CBB623DB494596E73F41B6D4FB999C9B774

SHA256:

03337D17D4344D7DE4D26E8CFF02AEC17F8C851B813A4C0C6293D76FFEB53878

SSDEEP:

98304:r/dUwrSJF8GUby7k7hS0w/yx/EyCooLn65r5wIGZ79fhSBK+CoNoFUsXhGKyW/iW:+FJPg33KNKQjMzaKH6EruLuo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2448)
    • Executing a file with an untrusted certificate

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2016)
      • Analytics.exe (PID: 2532)
      • GlobalAtomTable.exe (PID: 1980)
      • ConnectifySupportCenter.exe (PID: 2724)
      • Analytics.exe (PID: 3628)
      • ConnectifyShutdown.exe (PID: 872)
      • Analytics.exe (PID: 3752)
      • DriverSwitcher.exe (PID: 2496)
      • Analytics.exe (PID: 2460)
      • Analytics.exe (PID: 2840)
      • GlobalAtomTable.exe (PID: 1628)
      • Analytics.exe (PID: 2204)
      • Analytics.exe (PID: 1980)
      • Connectify.exe (PID: 3788)
      • GlobalAtomTable.exe (PID: 2120)
      • GlobalAtomTable.exe (PID: 1824)
      • GlobalAtomTable.exe (PID: 2716)
      • ConnectifyGopher.exe (PID: 2964)
      • GlobalAtomTable.exe (PID: 3380)
      • GlobalAtomTable.exe (PID: 3996)
      • ConnectifyGopher.exe (PID: 3508)
      • DispatchUI.exe (PID: 3892)
      • GlobalAtomTable.exe (PID: 3964)
    • Changes the autorun value in the registry

      • Connectify2015Installer.exe (PID: 1460)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Connectify2015Installer.exe (PID: 1460)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2448)
      • Connectify2015Installer.exe (PID: 1460)
      • snetcfg.exe (PID: 3368)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
    • The process creates files with name similar to system file names

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
    • Executable content was dropped or overwritten

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Application launched itself

      • Connectify2015Installer.exe (PID: 1404)
      • Analytics.exe (PID: 2016)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 2460)
      • Analytics.exe (PID: 2204)
      • WinRAR.exe (PID: 2448)
      • WinRAR.exe (PID: 3684)
    • Starts application with an unusual extension

      • Connectify2015Installer.exe (PID: 1460)
    • Reads the Internet Settings

      • Analytics.exe (PID: 2532)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3752)
    • There is functionality for taking screenshot (YARA)

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
    • Reads Microsoft Outlook installation path

      • Connectify2015Installer.exe (PID: 1460)
    • Suspicious use of NETSH.EXE

      • ConnectifyShutdown.exe (PID: 872)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 3228)
      • schtasks.exe (PID: 3364)
      • schtasks.exe (PID: 3108)
    • Drops a system driver (possible attempt to evade defenses)

      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Creates a software uninstall entry

      • Connectify2015Installer.exe (PID: 1460)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3084)
    • Reads settings of System Certificates

      • rundll32.exe (PID: 2924)
      • snetcfg.exe (PID: 3368)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3792)
    • Uses ICACLS.EXE to modify access control lists

      • Connectifyd.exe (PID: 1704)
      • Connectify.exe (PID: 2552)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 2152)
      • sipnotify.exe (PID: 2164)
    • The process deletes folder without confirmation

      • runonce.exe (PID: 2416)
    • Starts CMD.EXE for commands execution

      • runonce.exe (PID: 2416)
    • Connects to unusual port

      • Connectify.exe (PID: 2552)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2448)
      • WinRAR.exe (PID: 4084)
    • Checks supported languages

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • ns5438.tmp (PID: 1888)
      • Analytics.exe (PID: 2016)
      • ns5C09.tmp (PID: 3044)
      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3168)
      • GlobalAtomTable.exe (PID: 1980)
      • ns66C9.tmp (PID: 2764)
      • Analytics.exe (PID: 3628)
      • ns6B9D.tmp (PID: 3820)
      • ConnectifySupportCenter.exe (PID: 2724)
      • ns6467.tmp (PID: 984)
      • Analytics.exe (PID: 3752)
      • ConnectifyShutdown.exe (PID: 872)
      • ns6C88.tmp (PID: 3676)
      • ns73EC.tmp (PID: 3232)
      • ns8003.tmp (PID: 848)
      • ns8081.tmp (PID: 3152)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 4080)
      • snetcfg.exe (PID: 1124)
      • snetcfg.exe (PID: 3868)
      • snetcfg.exe (PID: 2092)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Create files in a temporary directory

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
    • Reads the computer name

      • Connectify2015Installer.exe (PID: 1404)
      • Connectify2015Installer.exe (PID: 1460)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2016)
      • Analytics.exe (PID: 2532)
      • ConnectifySupportCenter.exe (PID: 2724)
      • Analytics.exe (PID: 3752)
      • ConnectifyShutdown.exe (PID: 872)
      • Analytics.exe (PID: 3628)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Process checks whether UAC notifications are on

      • Connectify2015Installer.exe (PID: 1404)
    • The sample compiled with english language support

      • Connectify2015Installer.exe (PID: 1460)
    • Reads the machine GUID from the registry

      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2016)
      • Connectify2015Installer.exe (PID: 1460)
      • ConnectifySupportCenter.exe (PID: 2724)
      • Analytics.exe (PID: 3628)
      • Analytics.exe (PID: 3752)
      • ConnectifyShutdown.exe (PID: 872)
      • DriverSwitcher.exe (PID: 2496)
      • snetcfg.exe (PID: 3368)
      • drvinst.exe (PID: 3084)
    • Creates files in the program directory

      • Analytics.exe (PID: 3168)
      • Analytics.exe (PID: 2532)
      • Connectify2015Installer.exe (PID: 1460)
    • Reads Environment values

      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3752)
    • Disables trace logs

      • Analytics.exe (PID: 2532)
      • Analytics.exe (PID: 3752)
    • Reads the software policy settings

      • drvinst.exe (PID: 3084)
      • rundll32.exe (PID: 2924)
      • snetcfg.exe (PID: 3368)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2924)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 3084)
    • Manual execution by a user

      • Connectify.exe (PID: 3788)
      • runonce.exe (PID: 2416)
      • Connectify.exe (PID: 3120)
      • conhost.exe (PID: 3400)
      • conhost.exe (PID: 3620)
      • conhost.exe (PID: 3980)
      • conhost.exe (PID: 4016)
      • IMEKLMG.EXE (PID: 2536)
      • IMEKLMG.EXE (PID: 2544)
      • Connectify.exe (PID: 2552)
      • conhost.exe (PID: 2736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 10318821
UncompressedSize: 10318768
OperatingSystem: Win32
ModifyDate: 2015:04:28 09:06:12
PackingMethod: Stored
ArchivedFileName: Connectify2015Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
79
Malicious processes
15
Suspicious processes
21

Behavior graph

Click at the process to see the details
start start winrar.exe connectify2015installer.exe connectify2015installer.exe ns5438.tmp no specs analytics.exe no specs ns5c09.tmp no specs analytics.exe no specs analytics.exe ns6467.tmp no specs globalatomtable.exe no specs ns66c9.tmp no specs connectifysupportcenter.exe no specs ns6b9d.tmp no specs analytics.exe no specs analytics.exe ns6c88.tmp no specs connectifyshutdown.exe no specs netsh.exe no specs ns73ec.tmp no specs schtasks.exe no specs regsvr32.exe no specs ns8003.tmp no specs schtasks.exe no specs ns8081.tmp no specs driverswitcher.exe pnputil.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe no specs snetcfg.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs nsda4a.tmp no specs analytics.exe no specs analytics.exe nsdb35.tmp no specs globalatomtable.exe no specs nsdd0b.tmp no specs globalatomtable.exe no specs nsddc8.tmp no specs schtasks.exe no specs nsbce.tmp no specs analytics.exe no specs analytics.exe winrar.exe no specs winrar.exe connectify.exe no specs globalatomtable.exe no specs connectifyservice.exe no specs connectifyd.exe icacls.exe no specs icacls.exe no specs ctfmon.exe no specs sipnotify.exe icacls.exe no specs icacls.exe no specs runonce.exe cmd.exe no specs conhost.exe no specs imeklmg.exe no specs imeklmg.exe no specs connectify.exe globalatomtable.exe no specs conhost.exe no specs connectifygopher.exe connectify.exe no specs globalatomtable.exe no specs conhost.exe no specs connectifygopher.exe no specs icacls.exe no specs conhost.exe no specs connectify.exe no specs dispatchui.exe no specs globalatomtable.exe no specs conhost.exe no specs globalatomtable.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700"icacls" C:\ProgramData\Connectify /T /Q /C /grant Everyone:(F)C:\Windows\System32\icacls.exeConnectifyd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
848"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmp" C:\Windows\system32\schtasks.exe /delete /TN "ConnectifyInstallerTask" /FC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\ns8003.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
872"C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown"C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown.exens6C88.tmp
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Description:
Connectify Shutdown App
Exit code:
0
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\connectify\5\connectifyshutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
984"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Check ConnectifyC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\ns6467.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1032"C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set ConnectifyC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmpConnectify2015Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\users\admin\appdata\local\temp\nsc466c.tmp\nsdd0b.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1124"Exes\i386\snetcfg.exe" -v -u nt_cnnctfy2C:\Users\admin\AppData\Local\Temp\Connectify\DriverSwitcher\976\Exes\i386\snetcfg.exeDriverSwitcher.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
network config sample
Exit code:
1
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\users\admin\appdata\local\temp\connectify\driverswitcher\976\exes\i386\snetcfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1404"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe
WinRAR.exe
User:
admin
Company:
Connectify
Integrity Level:
MEDIUM
Description:
Connectify 2015
Exit code:
1223
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.44073\connectify2015installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1460"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" /UAC:40182 /NCRC C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe
Connectify2015Installer.exe
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Description:
Connectify 2015
Exit code:
1223
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.44073\connectify2015installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1628"C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set ConnectifyC:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exensDB35.tmp
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Exit code:
0
Version:
2015.0.5.34877
Modules
Images
c:\users\admin\appdata\local\temp\connectify\5\globalatomtable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1632"C:\Program Files\Connectify\ConnectifyService.exe"C:\Program Files\Connectify\ConnectifyService.exeservices.exe
User:
SYSTEM
Company:
Connectify
Integrity Level:
SYSTEM
Version:
2015.0.5.34877
Modules
Images
c:\program files\connectify\connectifyservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\connectify\nativelibrary.dll
c:\program files\connectify\log4cplus.dll
Total events
46 911
Read events
46 231
Write events
628
Delete events
52

Modification events

(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Connectify Hotspot 2015.0.4.34734.rar
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
91
Suspicious files
170
Text files
258
Unknown types
3

Dropped files

PID
Process
Filename
Type
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\Connectify\5\Analytics.exeexecutable
MD5:E940D9CBB97A254946B7DEBCD64EA258
SHA256:F1E94BE7CB362B7D5F2BD5DEDB732187F19B4EA1278B41911ED6439F27B285E6
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\modern-header.bmpimage
MD5:F50B6CEE1BE90D50AF582E57528C7000
SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\modern-wizard.bmpimage
MD5:AE43624C14859150EDFB54B4024AFF46
SHA256:D5B56046F10941E6659277D46FFD4A0D327DB24BE3174D6A8E7AE0660DA874E9
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
1404Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\UAC.dllexecutable
MD5:7F56C0D6A8733DEC142814ED5A58B0EE
SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\modern-header.bmpimage
MD5:F50B6CEE1BE90D50AF582E57528C7000
SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\md5dll.dllexecutable
MD5:7059F133EA2316B9E7E39094A52A8C34
SHA256:32C3D36F38E7E8A8BAFD4A53663203EF24A10431BDA16AF9E353C7D5D108610F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\nsc466C.tmp\UAC.dllexecutable
MD5:7F56C0D6A8733DEC142814ED5A58B0EE
SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F
1460Connectify2015Installer.exeC:\Users\admin\AppData\Local\Temp\Connectify\5\Connectify.exeexecutable
MD5:CAA085B96AD81F2370A9ED4E1E4B8380
SHA256:A74A5AF7EFEA32714787279D1090679E2FF174F7C3903E07722534BAB3F570CE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
42
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2532
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1927071427&utmhn=connectify.connectify.me&utmp=Installer%2fInit%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fInit%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
3752
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=402600594&utmhn=connectify.connectify.me&utmp=Installer%2fStart%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fStart%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
1980
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=609938169&utmhn=connectify.connectify.me&utmp=Installer%2fSuccess%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fSuccess%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
2840
Analytics.exe
GET
200
142.250.184.238:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=431537628&utmhn=connectify.connectify.me&utmp=Installer%2fDriver%2fReboot%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fDriver%2fReboot%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON
unknown
whitelisted
2164
sipnotify.exe
HEAD
503
104.102.43.250:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133903785778750000
unknown
whitelisted
1704
Connectifyd.exe
GET
301
104.22.77.194:80
http://updates.connectify.me/settings.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0
unknown
whitelisted
1704
Connectifyd.exe
GET
301
104.22.77.194:80
http://updates.connectify.me/dialerkeys.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0
unknown
whitelisted
2552
Connectify.exe
GET
200
52.216.42.165:80
http://data.connectify.me/driver.dat
unknown
whitelisted
1704
Connectifyd.exe
GET
200
142.250.186.174:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON
unknown
whitelisted
1704
Connectifyd.exe
GET
200
142.250.186.174:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2532
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
3752
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
2840
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
1980
Analytics.exe
142.250.184.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
1152
svchost.exe
224.0.0.252:5355
whitelisted
1484
svchost.exe
239.255.255.250:3702
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
www.google-analytics.com
  • 142.250.184.238
  • 142.250.186.174
whitelisted
updates.connectify.me
  • 104.22.77.194
  • 104.22.76.194
  • 172.67.36.143
whitelisted
query.prod.cms.rt.microsoft.com
  • 104.102.43.250
whitelisted
data.connectify.me
  • 52.216.42.165
  • 3.5.3.55
  • 54.231.235.29
  • 3.5.13.129
  • 54.231.227.149
  • 3.5.13.117
  • 3.5.2.119
  • 52.217.92.211
whitelisted
d1.connectify.me
  • 104.22.77.194
  • 104.22.76.194
  • 172.67.36.143
whitelisted
ctldl.windowsupdate.com
  • 217.20.57.35
  • 217.20.57.19
  • 217.20.57.36
  • 84.201.210.23
  • 217.20.57.34
  • 217.20.57.18
  • 217.20.57.20
whitelisted
news.connectify.me
  • 52.216.78.19
  • 54.231.139.221
  • 52.217.122.37
  • 3.5.13.140
  • 54.231.226.117
  • 52.217.198.133
  • 52.217.202.85
  • 52.217.126.69
whitelisted
c.pki.goog
  • 142.250.185.227
whitelisted

Threats

No threats detected
No debug info