General Info

URL

https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/releases/download/v0.5.7B/COMPILED.zip

Full analysis
https://app.any.run/tasks/0f06f173-70ef-461a-beed-ddfc32b0381d
Verdict
Malicious activity
Analysis date
14/01/2022, 19:55:19
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 11.0.9600.19596 KB4534251
  • Adobe Acrobat Reader DC (20.013.20064)
  • Adobe Flash Player 32 ActiveX (32.0.0.453)
  • Adobe Flash Player 32 NPAPI (32.0.0.453)
  • Adobe Flash Player 32 PPAPI (32.0.0.453)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.74)
  • FileZilla Client 3.51.0 (3.51.0)
  • Google Chrome (86.0.4240.198)
  • Google Update Helper (1.3.36.31)
  • Java 8 Update 271 (8.0.2710.9)
  • Java Auto Updater (2.8.271.9)
  • Microsoft .NET Framework 4.5.2 (4.5.51209)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 83.0 (x86 en-US) (83.0)
  • Mozilla Maintenance Service (83.0.0.7621)
  • Notepad++ (32-bit x86) (7.9.1)
  • Opera 12.15 (12.15.1748)
  • QGA (2.14.33)
  • Skype version 8.29 (8.29)
  • VLC media player (3.0.11)
  • WinRAR 5.91 (32-bit) (5.91.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Hyphenation Parent Package English
  • IE Spelling Parent Package English
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • InternetExplorer Package TopLevel
  • KB2479943
  • KB2491683
  • KB2506212
  • KB2506928
  • KB2532531
  • KB2533552
  • KB2533623
  • KB2534111
  • KB2545698
  • KB2547666
  • KB2552343
  • KB2560656
  • KB2564958
  • KB2574819
  • KB2579686
  • KB2585542
  • KB2604115
  • KB2620704
  • KB2621440
  • KB2631813
  • KB2639308
  • KB2640148
  • KB2653956
  • KB2654428
  • KB2656356
  • KB2660075
  • KB2667402
  • KB2676562
  • KB2685811
  • KB2685813
  • KB2685939
  • KB2690533
  • KB2698365
  • KB2705219
  • KB2719857
  • KB2726535
  • KB2727528
  • KB2729094
  • KB2729452
  • KB2731771
  • KB2732059
  • KB2736422
  • KB2742599
  • KB2750841
  • KB2758857
  • KB2761217
  • KB2770660
  • KB2773072
  • KB2786081
  • KB2789645
  • KB2799926
  • KB2800095
  • KB2807986
  • KB2808679
  • KB2813347
  • KB2813430
  • KB2820331
  • KB2834140
  • KB2836942
  • KB2836943
  • KB2840631
  • KB2843630
  • KB2847927
  • KB2852386
  • KB2853952
  • KB2857650
  • KB2861698
  • KB2862152
  • KB2862330
  • KB2862335
  • KB2864202
  • KB2868038
  • KB2871997
  • KB2872035
  • KB2884256
  • KB2891804
  • KB2893294
  • KB2893519
  • KB2894844
  • KB2900986
  • KB2908783
  • KB2911501
  • KB2912390
  • KB2918077
  • KB2919469
  • KB2923545
  • KB2931356
  • KB2937610
  • KB2943357
  • KB2952664
  • KB2968294
  • KB2970228
  • KB2972100
  • KB2972211
  • KB2973112
  • KB2973201
  • KB2977292
  • KB2978120
  • KB2978742
  • KB2984972
  • KB2984976
  • KB2984976 SP1
  • KB2985461
  • KB2991963
  • KB2992611
  • KB2999226
  • KB3004375
  • KB3006121
  • KB3006137
  • KB3010788
  • KB3011780
  • KB3013531
  • KB3019978
  • KB3020370
  • KB3020388
  • KB3021674
  • KB3021917
  • KB3022777
  • KB3023215
  • KB3030377
  • KB3031432
  • KB3035126
  • KB3037574
  • KB3042058
  • KB3045685
  • KB3046017
  • KB3046269
  • KB3054476
  • KB3055642
  • KB3059317
  • KB3060716
  • KB3061518
  • KB3067903
  • KB3068708
  • KB3071756
  • KB3072305
  • KB3074543
  • KB3075226
  • KB3078667
  • KB3080149
  • KB3086255
  • KB3092601
  • KB3093513
  • KB3097989
  • KB3101722
  • KB3102429
  • KB3102810
  • KB3107998
  • KB3108371
  • KB3108664
  • KB3109103
  • KB3109560
  • KB3110329
  • KB3115858
  • KB3118401
  • KB3122648
  • KB3123479
  • KB3126587
  • KB3127220
  • KB3133977
  • KB3137061
  • KB3138378
  • KB3138612
  • KB3138910
  • KB3139398
  • KB3139914
  • KB3140245
  • KB3147071
  • KB3150220
  • KB3150513
  • KB3155178
  • KB3156016
  • KB3159398
  • KB3161102
  • KB3161949
  • KB3170735
  • KB3172605
  • KB3179573
  • KB3184143
  • KB3185319
  • KB4019990
  • KB4040980
  • KB4474419
  • KB4490628
  • KB4524752
  • KB4532945
  • KB4536952
  • KB4567409
  • KB958488
  • KB976902
  • KB982018
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • Package 21 for KB2984976
  • Package 38 for KB2984976
  • Package 45 for KB2984976
  • Package 59 for KB2984976
  • Package 7 for KB2984976
  • Package 76 for KB2984976
  • PlatformUpdate Win7 SRV08R2 Package TopLevel
  • ProfessionalEdition
  • RDP BlueIP Package TopLevel
  • RDP WinIP Package TopLevel
  • RollupFix
  • UltimateEdition
  • WUClient SelfUpdate ActiveX
  • WUClient SelfUpdate Aux TopLevel
  • WUClient SelfUpdate Core TopLevel
  • WinMan WinIP Package TopLevel

Behavior activities

MALICIOUS SUSPICIOUS INFO

No malicious indicators.

Reads Microsoft Outlook installation path
  • iexplore.exe (PID: 3236)
Checks supported languages
  • WinRAR.exe (PID: 3552)
Reads the computer name
  • WinRAR.exe (PID: 3552)
Reads the computer name
  • iexplore.exe (PID: 2204)
  • iexplore.exe (PID: 3236)
Checks supported languages
  • iexplore.exe (PID: 3236)
  • iexplore.exe (PID: 2204)
Application launched itself
  • iexplore.exe (PID: 2204)
Reads settings of System Certificates
  • iexplore.exe (PID: 2204)
  • iexplore.exe (PID: 3236)
Reads the date of Windows installation
  • iexplore.exe (PID: 2204)
Modifies the phishing filter of IE
  • iexplore.exe (PID: 2204)
Changes internet zones settings
  • iexplore.exe (PID: 2204)
Reads internet explorer settings
  • iexplore.exe (PID: 3236)
Checks Windows Trust Settings
  • iexplore.exe (PID: 2204)
  • iexplore.exe (PID: 3236)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

+
start iexplore.exe iexplore.exe winrar.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2204
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" "https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/releases/download/v0.5.7B/COMPILED.zip"
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Image
c:\windows\system32\kernelbase.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\msctf.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\userenv.dll
c:\windows\system32\nsi.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\wininet.dll
c:\windows\system32\user32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\version.dll
c:\windows\system32\lpk.dll
c:\windows\system32\winhttp.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\secur32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ieui.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dui70.dll
c:\windows\system32\duser.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\propsys.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mlang.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\macromed\flash\flash32_32_0_0_453.ocx
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\windowspowershell\v1.0\pwrshsip.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ieapfltr.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\winshfhc.dll
c:\program files\windows defender\mpclient.dll
c:\program files\windows defender\mpoav.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\sfc_os.dll

PID
3236
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2204 CREDAT:267521 /prefetch:2
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Image
c:\windows\system32\dwrite.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\ieui.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\version.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wship6.dll
c:\windows\system32\webio.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\imm32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\user32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msctf.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\jscript9.dll
c:\windows\system32\propsys.dll
c:\windows\system32\mlang.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\fveui.dll
c:\windows\system32\wuaueng.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\cryptnet.dll
c:\windows\system32\netutils.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\wpc.dll

PID
3552
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\COMPILED.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.91.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\imageres.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\drprov.dll
c:\windows\system32\netutils.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\samlib.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\secur32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\slc.dll
c:\windows\system32\propsys.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\dui70.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll

Registry activity

Total events
13834
Read events
0
Write events
131
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
NTPDaysSinceLastAutoMigration
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateLowDateTime
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateHighDateTime
30935424
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
NTPLastLaunchHighDateTime
30935424
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
NTPLastLaunchLowDateTime
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
E0F5A2AA8009D801
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{E8295C1B-7573-11EC-A45D-12A9866C77DE}
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery
Active
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadNetworkName
Network 4
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Time
E607010005000E00130037001700E200
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E607010005000E00130037001700E200
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Blocked
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Blocked
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E607010005000E00130037001700E200
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E607010005000E00130037001700E200
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
8E42D0AA8009D801
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionReason
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Blocked
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecision
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
8E42D0AA8009D801
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Type
10
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Count
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Blocked
25
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionReason
1
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecision
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum
Implementing
1C00000001000000E607010005000E00130037001A00A70201000000644EA2EF78B0D01189E400C04FC9E26E
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum
Implementing
1C00000001000000E607010005000E00130037001B00C30000000000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy\DSP
BackupDefaultSearchScope
00000000A607000047985ECEEEB1527EFDC03B923182A06B3A7FC2DE18CD5B8BCFFFA82772140E0F6FD293F776A3D4A0610C5E84D43D85F39365ABF135B904FC025B6BD413A0551EF54D135C90D17F50E7A0FE1D07203368A4DDB92843F2769534D0B957C3E16B8991A9639AE55D3504311E890C3048758133864A141A98E67D76FEAEB7B1F7E0CBDE86DE9A2366ACDBAE248459CED4BDF6EFFFDA1300CB85FB00854BF00C03A88A4985C1A1D30BD77C35547BC7F6E6D864BBEAA2AB08AB127A260508DCF923E4DF3C4475641A6E8AC5684C21BF849D49802FE6B9E543589D62F01D86ACC87882F497641935B4ADA04C83AC56D13819B59BA792FCC370F2D6C4CA6F13EC64235EF0A9856C3E47EA69B25E18E3C27B7AB67A16907FC2239975D1A09AAE1972420534DC47DECBCE430CBFD02BDE2B85DFEC775A7F5C6C216D431ED03ECECAD6F6BCE8BF4AA2A65BDADB576488A8A5D56AF7F6A6FE9FFB108E53C4F8FB0064D15F0FD8932E6980A8CDE13904CDED8B173A002C0EAFEA0D071CD543FD71A3615D9E3B9D5394C168733E828DB09BD445026F6F307A312A632537E53E0940E62914D1AE1D691AB65EB94BB3492993E52A6929E261AB230FB547FF06003C089274FE190558186192E61616DA5DC05393EBA087091D16273197F194FFD75E693B4665978C80F109F7B683BD3DB7767D2396E4AB92C168DC3067EF16FD3C5603096F3769536CAEB2C96F00624C111CAFE11E3FB4FB01CFE12754B4A57ACC427673A8D1B0794DA6FC5069A523B292D18AC08006C2A58A00D8A86DCF614D0EC461F834E48CBEC117888A8B7E227A433DAFE76F98F4EFF9246045C6D56AFC0EAA66931C4E1EB12D51F44239287E3146DEBCD7909F6C5B1ED618FDA8D8E099C6AD24DEF00584AB691CE19E4BEB5610F06B53194D1049418F3EA2A0D6DFE3AC55D03B3E22CFDFCCBCECEFB61C5FCC94A4AC127D302FAB6890519D7CDFC993E207F94BBFE72250D12BF8BEFF9ED3FED786A09AA4D25CB230459BA8527DE410A32E1EF45BB619F51C13EEEE148B260ED8FA518CA25ED07D3F3827658F0DBA7A2DCD4AD6F445E3EFC3167020499ACC1AE1F5D786C996B62E6C2C94724C10FDF14E0B28917F28AE5E295A47F232CF4744E31D5A2A3F7D05E4B441D1710DB8B295A78150C5D5EF496343112A0571D0CDAAE3BCEA163B7C61BFEE6D66013193878658526F1297E5041C335910F9DB54606EBB7CBEEB1825BDDEF93ABAC19A37B9E4B60D3518365292AAFA68C46EC79B9BAED5FD684A7D82B8631AE09B530F09F2CF76709976A84E8C2DD507E004ABFA218C3930B6D1ADF1E26DFCA42D569B0BD46787E5BACE68326BC6F761925B6F73AC262D8B41221695391C04949069A5C367CDE7E6CFBF6F82E493711C7A14F9610B9E4909ECDB9D5163908A83F02E8C2A431F6E1C88E9527DB1B57EC835CDEC35861291F9969D065CFEE8CD667444B6B05F7E775CC4ECBC2E524DE19B3C27843C50A41AA20209C559F5469AF0D24A1B501A0A267075682D186479F47FE3C2CF7D8E7252AEE6BD5D0C1FC9E58EFCE20BAE40E3EBAD33FD3F65825A1C6BD03EAFA1A99EB46F545B1C92429119A65BABE84E5B298F5E3E4B0EB291101D12953B6CF06647C3EFFC81183595BD6D2FA6440ED741FCFAFB4EF2236575BCE1DF225ABF57F38C1BCE73D1B3C7A86F7993EC4F1B5F1C7CE2315A92B490C97C42427E39028B508F7CF53DE95894AEC630E6486B85D517C9B0BCCCCAB06ECC71934B5F796328A66E8414A56AC3DA20E2E868FC3794702B0332108C3C306276BCCE98E9BA07F8004B46F856F555E137E3385D08558E313E4A8CCDAC8780912C7BBD91909CDF31C344A3A2D3284F90DDE84A2C506469783BBE710FD64BD10CF0CF50F5A5BFF5DA4D7BAB422FA574A2C913B9D8A00393A1167F9A7EE62840808DD82CB498C3B52FA70E96F0140AEF615683E4C512D4BBC01DADCB3FE1BEF87F5CB7971F5C49051F2B1FFF40B4F870F84058C2C87276195A066836A610AD395A0E8A706438EF6CD4B3CCFCA12610384C74B27790B888E73C1FD02DC12795C281B3728F561256F14E3937D28EDDF0BB70EEB0CA570EAC255EF60509B052166D814490D991F61E3F118E7E69902C3A4EA2F97443EB29812AD3EF27FFCF51D019823B02E3E08FE77CDA07C3D90A118C69D6251DAFFCFDA611CEC056C8AD30630266D9E9F4FCBB51846CA52417E1918725D91DCB58C826BD60B3AAB2A8D4E36E6B6968653C9A54FD176E22C34EE43ACC5FFE9A9DE7085765733AC65B8A63B493C35B7097BAC34F89AF4D42BFD812C5F9A95BECB57D3CDC3D87A0CB719A7689711D66039D0A882A963841ED3728AB76B0F09B1732CB382FE7B2EEFB14B15ED9A87B63CE98F1F5EAC4794E364DA50BF98F31582C346C107102DB46C86422AAC6D8FFC176A9EA66DEB32264FB1F3062B5379D0C1FDBE344792DC148AA8171FF09A1A3FE76EE281FF003588949CF232D3C491C91B346414F3C0ABF85A58B1FC011A317ABF78860386A55D411C87BA88BD563052CF697E270D437A9019EA25A8A237E2A01959791DC1247A4ED0645D85F19275C2E56ED94D8CF565AC5B4E6077740D2820B433C95D66A7AC0FFD24B193CE73371225D684E1A2C06DE819F77A43B6E3F7E5D0D95856A1A8E638B3DAF12279228038A9C27D6EE9FE61D429C75880A6965135492C3DC84C82391ACBA8FE42938A78C30CC4C9B4BE098DF2F9D00255399E329F59DE61734BBD93BE5560D010000000E000000385835324E41646D516B412533640200000000000000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE0733252019000000000200000000001066000000010000200000003739C7DBE0CD722D9708076EEFAA24E3F253B37B7679C27C8BDF0DD5935D54D2000000000E8000000002000020000000B36D1D8819CA010C3A5198255BD25882ECD996A82C10E0C2C52955D7D960DEDF50000000F4921E2F9B6743A45D6EACD403E833A4D9CE16E8D63E1E23BA332BB0D36B06F5915A3E11A39AB1F60CC54793F83B0D57E49642A3010C96F36C2D64F4628965A2563FC9A08D640B17D2CD3C63C15755AB4000000096C52363ACFCA4CE86FD4D765CF809E42C1B617842E3B2549F7B18FC0701B04D735CCE06F597B0FFA559051A2C11A9B345A24EA44BDA91DA06A25928BE6491AC
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy\DSP
ChangeNotice
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE07332520190000000002000000000010660000000100002000000021D902CC3A94790F63D2070873ED2744470B55573C008854011E5018CEC9BBA2000000000E8000000002000020000000421913966F9DAD54E4E3C1EC844F732638E124E2FFC916B763B823A2A2308FB610000000DE39734BD7E71B49D17714475E3FDBD74000000048B4DF5D66E4AB041B7EBEE8CF9A369EBA19405800AFE0097EC3FF56A771418A5632C58254FAAC5C4159A8501046141C50123D25CAD3A4BB65284E98AEBF8C0D
2204
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
LanguageList
en-US
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE0733252019000000000200000000001066000000010000200000004E6F81B89B9F901EE9219403AF1528C37C67DEB55D8174BB343C8D1028BBF2E9000000000E8000000002000020000000E7F26DF7B0C2B8D62FE076A7B223305235FFE16ECAA48F20E440A61A996D952B50000000348B4C9C8B47C30341CFE2110449C37A8133A8DAE532995630491B28FB44E39949E15113D0FD01A949434B7997F745797FABA501E19A855C6443A75111F21F143C8ECDA27D287119EC77983AE78D697B4000000053E71DAA0C7012A5DCA7F1DEA394C1A05D719788097D1626E3D5C169752F322173C49FD0CC025FA18AAB8FDD63A43D1E12FE7D8E3F6CD5045E511CA080B555AF
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy\DSP
BackupDefaultSearchScope
000000009C0800006ABCB7818591497E303E80C4CE49C77D4FDE1EAFD3BBC0C07A0F3C237551BD5B72D777DD6D60B5B37C71BB4C753A8A6B83EB7E5324B3517D73C9471EA2435362179FA0523B28C87485B96F7607812F383FB6D869C873F7C68427B7910847E62CEE34863F528937945037DD03F6295AE9945D09F0629DF979F64B3A6C4FFCB469E4B62E2D402343B43A093D5AB3D2B46F2B02C2B109CF8B5A375484F0DE01C198CE45E7C76896485CEA50103D8C1C9D7285C3E6E592AA803641620E5D00F84918C5019FA6C58183A0D72C59DA52A8C52B47C2BCA264CFDE8FDF9477DE3D80874B960A7CE7EF86985801BED5250F14364C401ED91CF4DC64DB840CE6D2853852CD92805C92F744B3E5472496861A0182FEE7F6D5B8767329537DE987621BC2FAAEDA8393D5D95BF188867F2CD6A00F49EB616C4CE9AF320E51294BA16064BD5BCFD9336C0FF86B274862F03EA7C1DEBA55FD9E97E187BA16406152BE81C4C8703ACAB022A03314F868379516E8E90E0C4715AEBC1614ACD417E31D3BDF1785089CFD1AFD9A48F67473A38F37CB6140D8C7EFBA6D8DFFA6EB6DB5CED4CBCA922DC4E391E3370FB1EFC89EFEAC046A12A32A77E4AAFB214AD411608498F8A3919B36DA35E31F35E530CC2403085857254066BE4A2BBB8936653E285F24EA4B2110D1E22671846932A1961CBC77735019A181270ECF86980BA856927EFABB9DE19477C4844B066A38D43F9B4A9A1BD48E350CA24ED80C386AEF32C803E433A47306E1876F23719F969CB1C1CD28ABBC24B3AA372CAA4FA2F10E01D40D09293176955F89070D42F3EE8F1225661FDB9C7BB1AFAAC646D552424CB529BCBD388C89F3C8636D9100D8DF40B9AA337FE37E343DC7113EE5A8F5FB32027830EAC6E84EFC646FBFC466C80966B3AC55C7E22EEDD9B09AB2A02884BD3BEEAA8841564C6414F4771E6B5AEA0C3BDC68ED14A0144791091344BEAB132944EDD7E68D2B866A9EC17DAA25B30188C7854219E694F2E232298A124FECA6DDD79120695843E202C1C24A83F6D8601DA1AAC5FA1E47855E3F08E33ECA4C457B31CA5F3107937BCBEECA43C972242D6BA6B889B0DAFBA15B423E5CE751E6A4A110B0BD5D82A28864A0CE009CF61D5D12ABE4015C7CAD4A7AEF09A62C24690EF153E6600F326CEB6F8B364E1C20832FB24C12AB1CFF5A4059DA6D302F14CE0009CC86EF66D592488B67422F69AA208EEA344AAD11E1A43C99E358990E2FD7EC8A99A12382B4E7B2574D7629A35D78B15CA6C0665C55B9F4DA53E108EB495E4B151B4D2583453D3E75362506EA163CBDA7BE6B391B2990DABC1C90C2E4D976E7484642B288758B1E8431FD1F5E6B97E76BB62A966F6878A7DFADBB031BE15F4CC5310A98B39565DB2316AEC21FC742F548397A98782FF2C5E3C5EFE9AE8540062A7AC05E23FABE1AF479980D4D0872E6DEEEBE595764DF54696F6B2FBF18BEBA18C95D07F816FC2696FE910108A3890CCD1A161F2AACFB1B0FF2A7A46C325732300E992652125DB1A8A9B74770AAA710B5E7C3971295AC1676ECF63DD74F97EB109155B050B2AC2DCC7952D0A542FD00363D214930BA1CCD3E622AD41E8915615A63A0AD14104656A14CC4BAC7AFF436F0B529F4A23DA7AF07FC501A63844743ACD33C77BD1C6CCCC64191BCF61E2D64838A8CFB8941958C71567D9BC4A52092A7DCC9416B46EB00DD356CA5527542C88EA3579705102B761D76A51D6371801DECA4689A3D120D7885AF5D84FB5561AFB30D2A113771047AA98487555FBE75D0199600D35508E1F15DB7F3D211BCB6839148FE263D5ABE5AB6C6AACBD751504DD0E10B2AD2B9CC2B07F4858FB433A3E8C8367C8C3864F79BE43F63B6EDC97CE9AF70F434D449713922B58595041DC6E2F820E42A49879ADED389F1F9BFFE398A571B04657BF1E1D84D34E4A321A7D41EC18C83738E257CE223A2AB556FDA15306992E5B3E61926072AF582B82BC04216C363BBB228934475756A36931B7C40FC83C6ADCB37E9109A577CB4B14223BB0F9E1594A4378CAF6967DDCF64E529AA1C47357D258DB75FF776B3D18886FA6945F293EA19DC1D16129A00AC8EEB95F79C533DAF7A093A3723266FDD96179211275F51204335274D0FAEA15E684FC13D9848739697C72FE09006623187159EF77485D064D963CCD08943BC53BD2F0C9521C7F1CBC9ECCDDFFEB876468BA0CF989603968A99862840BDF97B5C3EADF77BA46E3A0FED96885B3EDB8B8397D84235A77B207121BFD32CCA70B246B2E7D10047DF23B33DE578CF8C0EFD237FDE3326D08C82F6F42C62337649048C12FFA6C9ACB8B99C79F9F20CA9F3DB236BD01508F2D65482B0EE2B6A2F228E08C8134FE1969AF3D1B0F1C895522985487ACF50B4B0F9951775262F1F559CC9C61945B9562926F496C9EFA03D8B4F213167FB210506956A0107F27DE1FE57F8D890B321B0ACFADB1E0F126E1FFF070D7759745173384A8601DF73ACDDDCF3F344EF7FE52A5FB8B0C8557AD5DE54F09DE25E5AD67B63B8D31FBBC9748FAA100EFE47C8FAC8D7FE60EFAB46A041FDA97EAE51CD94D8787F05F80D1584B60F4F74F196ADA036016E3D44FA98BA11D6D436D55FED228A663FB9A7E57513AA5A4EEA1C7050547628A6DFC3F88FC2504A103F7B23DA4DAFB197DF3FAF0A0AF133AE6BBBC9CF6A648D47AA2D394B94BCA1FC5E5B39B45E2C832927CC48F5B52FE90FF1804B4C3E0557F262196CEC30A83E3A8A4A229B2526A294F3EC3954FD64F311A6E1D3E574A8D745518E8391BA185069BBCD5AAFD149B578A6F7A4489073A35401714EBCEED426E24D38CF5C4C41E5283CB70B1009E3EF7507B39FF16E0699785348E8EFB30E1E67DB225F6CB6410419BFDC03DEA6C8EE2B319C0B70A6B14E1EBF8025A063649D7518070CE1BE3F28DBCCD84739FA104B3A36B91DE38D7A28E42EC2B7EDC3CE24ADDB2C7BDB56C7A20DCCDD1D41449C34420205A16BE99C516B26DA3DF87764C5AD91D6F5791F821851C996E316656E58E3E7636929E0A7FA5303679BDFCD567217E142FEDDBB3B6146201CF9D84CD418BDE526373B98EDA93C8B931CC4C3C60A89C1352526F533010000000E000000385835324E41646D516B412533640200000000000000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
FaviconPath
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy\DSP
BackupDefaultSearchScope
000000009C080000FD24D915CC6365DB5BA3DC874F0D12EED0E4CB0F5A74FDA791816AB82425764CE5D6BC1914EE5150872423D3140D137D6CAF30AF7DB5E3FA08DF8FE333AC1C3AA061116332ED42F5EE469A1FC6467FAFC0222B8581FA421D6F2E62D43960C88ED9659C72CB81AF338BA9B56B57BDBDC67BDFE70DDB658ACFAD0D1BB03E61AD97F382090689CA44CB91ED498DB290F411348417F3001535521C1E6FF30FCF4C3ED958936251E985F851B3A5AA2DE1AE78AAB2D9614B2AC7777A006D2B11CA49BB3287A6274CFCFBF67C9972C893CE42E0780AB1DF2DC4580BF452D7CE4C72E72161AFAAB8F624B9C65A40D85F6E799957EF2AF2C08D02E8845FB6811EB4E78BB705708F303E820050AC48440C9B00101D78B43823FF061B0E16CB4317CA49851D4D6AC9EB2034FFCBFD5174444185556A0E460D7D76EFB8D5D2305F74F5B89B466E3DAD9AF15B117F89FBF5258026491682816EBD4EDD6AB50A8717C2F554E842FD88B4EBAA1749CC6CE77F4D4805ED067A0639F5ADEF0124386FC082E63DC9D5EAED46BF0189AD8A08B37FC46041BA70F073889EF6478D7D9E879A5C9B9398E0F40B6EF036CFB5B52500C6F8CBF9A9E6586A34637804CF945B717660B276FD98AD82C2A8BC0A7C688F6ECDC9164FC13B8189017F4046D79803CC2359BA06999395F2D449705B6A2BC79D3EA0B1610D338871F7AD612DA347C937E430AC632E9853FB6CE123E0578EF02D9F99555145003DC383A8B1D8827723542060F5AD0D52103D5D30E6BA82173ABF05C5DD3D1897D81D6937FB698DE7AFC12F75A004D3C13E58D742FA09EE804EF1BD6A5D4731CF55218BCA1BFF5F64C220EEA1BD884F8654EC399441EE1B3E7164F266DF8D8C4FFE6D40AF4CBA293C2310C55E99591AF8789968C80187506307B899942F315D5485A20BC88DB93007813079229D97D51160FF6CEFD3F588C7D38DDE4AB551783A3C612DE1CA1EA8B6EC226A1C9762AB248ABD955C88581A89E983F4E2330F63E3B5485289EF0865FE0B85A20D93DA9965BD75361179D151D59E3A6D54E489EFE44CF9EA843C975B0484F8FB294A202144D4C687ABE47EF1056253F1E020E15E89C3124FC92DEB8869D61DD2065952079197504FF4A480260E7A6C5FCEAB35AE9FC934660DD723F19C9B9360A27A91A579F9B300F026F803394026AC2E01A7601D4F00DFE7C961427E84F9417479FDB04E188F208A17041732F62155BF9D550A8CF614A07B55C4E854F8F1AB8F43B6F11D3E840AC6F8C55B65CDFD82CDF561874E1712C2B9426C18120E1A48D66FDC9C171132658C845B63A8825AA8377BEA02ADED98092CBE78A4E9891323390F8FFACC6839FFF96EE7EB393DD99471E60F80B73C483657850A1131B37EE10F2AEFA531B5396E4CEC87300D431894A224F2A2F646C051A7FF417E9705FA68752B1C94799AD15156AF5C0A6632B82FD0D5B15FEAB0A1EAED333DA3A7EC268FBC77368EBF96A3F5857587DEC6E45956157A6EAD5C4B8CF6716B1E43A15DA4C1F6205D537DF04E1C7919265129FC9B93F0D747D881C21F3E8DA20301975B13A27E1CB157D3E7724B2A995AE390921E749E6C5E57E63BFC94DCD80E78E9F612E7A027525EA3ADAFE09EFF4301E15F82F17EAED16E3305C190FB4A5E16045C43974B1D60BE78ABA5C6345D02D10E406835972DC29CBAB40FFDD54B13147A7A45E4D311FB673F52F4677441B56E9A3C6EEB16B74FC7DC2287D582544DFB65B1B7D2C209437DCC733CF378B67DC85B4A3591F31B9A1B33FAC7F8B6A92B231C083B44BEC058C437451D0BE64A7B55A1CD5DE796DBC1AB955471FFBFC4CF1E3641702977FA5A95041837BB7011CD4199F7865A927AE638E9D923FB14305878E1CFF5F0ADA869351A222AEFF2EB94C711C15000709F2722BF867EEF7443E657840E6CD342E9A541899495F11187F02781285CAE8A43A638C83A236A93899841B66874895CF62E1328AF1A60775F02C466194860F77482B9128CB07B58F590BD80E0AC9696CB2436FBA6587D9636E8A6F31FB5C57FC8DA901C4BC773AF45EDDEF41EB69445E6A7436AFFEFA601CCC3370AB2430FB053D087B3B1068AE455CFC50F5130A2C9D2D7394BE17FC8523EB4B088989245EEEE82BFA4C70E4D94615624F0CCBC17F0A1D4F8BB10A807A03DD997E5B24278A408122B3E2280FC28A8A1B65922F98167AFBE08C61C0AFF83EF53A11E62F4FF7CDC9E539FD1FA90E8FDD2E98896867842AFB5E9DE204518B1AE4261F24A462AAC0B4846D84D1E5E970E08AA58D6057885BDD9262748F9E01D49C7C36C2FD9F84CD72E53DCFD8A4DA0156366B82215F8CFD84AB58A7CC65FB43B00CFC61B4DE1C52E720440D7DF94D79F02B66B9B551E0A832805A56D4CE89D890EE98FCE421149F43201CD36BEC2C9F007C524F2671C2B9A937E7C902A0F178F11BC2AAC58225E3F9048DFAFC54096E591BFE324EAA0078EABF305AE023ED8212A5B9C842F6C79BDAAD9954096756126C07CAF8E7D1A3665919783C973CF09AA7742A550682CA72BA28DD5D8CF2C515EB4EA95C0C2BD022C63B2AAC61D71CB8119542F76A17B4BEE96F918F911B51ED88C6F040158CE6F4742E399E8A04A4B6F31950A0E7B4EE41BA8D40E0FFD522EE16A1A6993DE5D487B4EC2A3149C4C6C28DD8DFAF49619EA92F6CD0CA6314145346D552BE2F6474450A7BAE82EB11FFBCA3E7C11E392FEB9E8A2434E544F4FC45EB56FEA473F97396F6D1BBD357F15789B74255A820F7F8B52CBBE06FCF504768E61A016B858DD5F41C074E32DA6586A3CA030DB0FAEAA7FE290334171C543F0EF933FD6E4E31CA014C0AF917CC6F846F6E040DF440DA9BB7813888F475DC37EE76A3D35047F7FFC358D4E4F947E64E8A755968E60CD6490CF72388EBA5EC0A3140610AFE7CB0CFB79473598D070FA94322001E2E68ECEB549CFC0305869F0267D87C3FF00693931330EF258AA3B63953D5F4ADCCAF07B9790487EE5C21C10B28C0C344A1EF845CF2902DF34D47FCC59C1333C14B293AFAB5BFF0F837419A703CBB70B8BA517CD451043CFA0EEDC5332D1BC64969C17D5E2A812210E03FE14A603A7D95F0E68E7F7010000000E000000385835324E41646D516B412533640200000000000000
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE0733252019000000000200000000001066000000010000200000007BF031919AE56DD637064C2156D38DF48C046D4247A953327A66473C72B94682000000000E8000000002000020000000723F4DA3061496E02C97B29973135C3338806BDF7CBF2898987B012ACBD0BE3A100000003C6ED79F262EED7E175F3379103A2BF440000000CD87D55C0E174ECFFF04892B141B87E6030DEC15A7D3C3C961FDE43EED3BB1D0D5ED5C4643C3A98E745483BB17EFD4520CA18CCAD06EC6556FF8A6D64DFF98FB
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
DefaultScope
{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE07332520190000000002000000000010660000000100002000000020809FDA237F132B2A90B3C09AA39C7098D40A36A38939D805BB6906536D0581000000000E80000000020000200000006F779E634E91A58EAE0CBFBAF06D3AF090167A8230311F7AB6FB6BC6FFC39D4710000000008DB0A04BAD9929387647409383F4F640000000AC52521A701C7D9419D304A3B2730FE71A3B4BADC56E753CC4559A7638A429C374C4AF37557941DDB15C8AAA224B81ADC7A5717C4EBAF13DE463B3CBA29FE137
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FCD599EC5BF85B48B7B1FE073325201900000000020000000000106600000001000020000000E1AA23D754F63D242FC2A3B0CF955C4FE1FEAE7EE2054839183E681D104F94E1000000000E8000000002000020000000A1314DE7287F2975F5F7F18F57915A2D646B8413E8E8D332414557EAF37B3A6950000000FC7F333423BBF073A05F4D951D09BCBDBE5516EBA9AA5BCF5E3EF7870073E140323A2F844C2F7254C87016104052FB4F32C01AECB10D6EE3C44D72A071F93192B3D2F1B42E4C75D203A0A4D3409E56AA40000000DD1B306B702A8AFE920245BA58982068537B152C841425D969B4E830FCEB06DCBE8213FFF50801B61E9AB14DEBA36544B95969858FE04323331BCACEBE25DAD8
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Blocked
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E607010005000E00130037002600C602
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Count
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Blocked
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E607010005000E00130037002600C602
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E607010005000E00130037002600C602
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Blocked
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Blocked
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
26
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28BCCB9A-E66B-463C-82A4-09F320DE94D7}\iexplore
Time
E607010005000E00130037002600C602
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter
ClientSupported_MigrationTime
360643B88009D801
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MINIE
TabBandWidth
500
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
HashFileVersionHighPart
0
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
HashFileVersionLowPart
2
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastTTLHighDateTime
50
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastUpdateLowDateTime
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastCheckForUpdateLowDateTime
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastCheckForUpdateHighDateTime
30935424
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateLowDateTime
127443150
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateHighDateTime
30935475
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastUpdateHighDateTime
30935424
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\VersionManager
LastTTLLowDateTime
2204
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E607010005000E00130038000A005902010000001E768127E028094199FEB9D127C57AFE
3236
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\History
CachePrefix
Visited:
3236
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies
CachePrefix
Cookie:
3236
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content
CachePrefix
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\Downloads\COMPILED.zip
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
1
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
2
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3552
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3552
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
LanguageList
en-US

Files activity

Executable files
0
Suspicious files
13
Text files
6
Unknown types
7

Dropped files

PID
Process
Filename
Type
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\verABAE.tmp
xml
MD5: cbd0581678fa40f0edcbc7c59e0cad10
SHA256: 159bd4343f344a08f6af3b716b6fa679859c1bd1d7030d26ff5ef0255b86e1d9
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].bin
binary
MD5: fa518e3dfae8ca3a0e495460fd60c791
SHA256: 775853600060162c4b4e5f883f9fd5a278e61c471b3ee1826396b6d129499aa7
2204
iexplore.exe
C:\Users\admin\Downloads\COMPILED.zip
compressed
MD5: dce9498e1f4c442af9ba6eddea932c9e
SHA256: aea1e7906f7c4c8736efd398ccb819a6739058ee2e0ee87cac29ac72d764ec29
2204
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFF96D274FFFEF72E6.TMP
gmc
MD5: f69fbadf75eb330bd72c22561a98632f
SHA256: 2d2d945f57065988c0e95ef2f1fbf905b4e1e3ca0892200d0b211d33160740de
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\versionlist.xml
xml
MD5: cbd0581678fa40f0edcbc7c59e0cad10
SHA256: 159bd4343f344a08f6af3b716b6fa679859c1bd1d7030d26ff5ef0255b86e1d9
2204
iexplore.exe
C:\Users\admin\Downloads\COMPILED.zip.tpv6i1e.partial:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3236
iexplore.exe
C:\Users\admin\Downloads\COMPILED.zip.tpv6i1e.partial
compressed
MD5: dce9498e1f4c442af9ba6eddea932c9e
SHA256: aea1e7906f7c4c8736efd398ccb819a6739058ee2e0ee87cac29ac72d764ec29
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E8295C1D-7573-11EC-A45D-12A9866C77DE}.dat
binary
MD5: 768a917b1d146a3b394f2880e2feb3f9
SHA256: 58b4fa3ed41fc8abb140f2161daf856cbba382c3548327283fad5ea86d1acdd7
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
binary
MD5: 0eaf9f5aaf64c37be19b52fb9d07c841
SHA256: 0f6bc9d3e257383a61c2dd86bb6cbcdec1d3ad3cd1e97f87e77a7ec19f6b1ed3
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
der
MD5: ace427d9e2e5197da2f600c887dcfcb1
SHA256: 9d985ec5e3675b2c7ded4535f7de2cbe39934d67046e25c3d0466220fafe9651
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2A7611428D62805A3E4E5BC4103D82E4_D0FA13DADFB59BDF00C474952E166CC1
binary
MD5: 03db4afe519dff02147cc777e875756e
SHA256: 0df6799534ce0e0cb0dc0fa50aad41a1f4bcee55caac60925252ea9a3f0a4e87
2204
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFEE6C8447F05B5389.TMP
gmc
MD5: 7362bd84d810ee0601e526ad84aea0b5
SHA256: d516e4dbbafd5c7be0dc2fcc8d769eb6e4fbd03bc6d0d465cf4bb73631aef4e4
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB
der
MD5: 47396d1f83885b122f30d2d498c9ed2a
SHA256: ad4f35faf489dd92588539892a4ee173c84290d3b2118b21c6283d269db68f5d
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2A7611428D62805A3E4E5BC4103D82E4_D0FA13DADFB59BDF00C474952E166CC1
der
MD5: 74ba1d40ce03de4a7241db2a4705a38b
SHA256: 0ba2a020a9932a123d946e614a115681deb6297ecb585fcf8d2639e8cf496bd8
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB
binary
MD5: 37e152dad4558119a58b04009b50919e
SHA256: 71e4692d26ce7fcccc33167ab113993a675fb904777d107366fc805c72b9e944
3236
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\COMPILED[1].zip
compressed
MD5: 3e65dd515dae2b7dbce0159bc1a3c383
SHA256: e46b425e93705917350a3cbe7985f80205416cc4011873640eaa5e8142111699
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\12B578593FDE07EC53D020B1D5DEBF3B_5D74C2DB556F94499BCD6D74A36958A3
der
MD5: 08be4738a45b45b44770334cc225eb1f
SHA256: 10d6234a21679564bf2ccacde3c00f23076c2719e8f5fb7201308c60bcf24465
3236
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\12B578593FDE07EC53D020B1D5DEBF3B_5D74C2DB556F94499BCD6D74A36958A3
binary
MD5: d7c51b77265da8d095c504d4278db527
SHA256: 9681d44023a5069c6ba7942a08afa0d901e85d136b1880d82f906e0ba5ed2ec3
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].ico
image
MD5: da597791be3b6e732f0bc8b20e38ee62
SHA256: 5b2c34b3c4e8dd898b664dba6c3786e2ff9869eff55d673aa48361f11325ed07
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{F19D4EF0-7573-11EC-A45D-12A9866C77DE}.dat
binary
MD5: f3cb57a0b3c11b2c3eb97c4fb2dca26b
SHA256: d1489d1bbf1abbd077d97a043ad8a2ed63705afe8112ea3042c4ca5ce4073318
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
binary
MD5: a333a5ec092081851d6b084b1f02cb2e
SHA256: 00b989b66fd5627c795adc1be818aa31e060b6d3ee597e2ab936e4fe5503cdfd
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63
der
MD5: ac68acf50745357d4ea92b214d9e7132
SHA256: ae3f7fde380d2d90571a61378e52b1bc284b4c4c6a1e099f6f022395ebed6154
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
image
MD5: da597791be3b6e732f0bc8b20e38ee62
SHA256: 5b2c34b3c4e8dd898b664dba6c3786e2ff9869eff55d673aa48361f11325ed07
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63
binary
MD5: 7d9b9a05c577a66218849858ee431227
SHA256: fcf2319b61049d7679ccbd27c449831cadfd69a60e16d349f7109272fda3611e
2204
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
compressed
MD5: f7dcb24540769805e5bb30d193944dce
SHA256: 6b88c6ac55bbd6fea0ebe5a760d1ad2cfce251c59d0151a1400701cb927e36ea
2204
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].ico
image
MD5: da597791be3b6e732f0bc8b20e38ee62
SHA256: 5b2c34b3c4e8dd898b664dba6c3786e2ff9869eff55d673aa48361f11325ed07

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
7
TCP/UDP connections
18
DNS requests
14
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2204 iexplore.exe GET 200 93.184.221.240:80 http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cbe00e374b373317 US
compressed
whitelisted
2204 iexplore.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D US
der
shared
2204 iexplore.exe GET 200 93.184.221.240:80 http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a53a6cc97fb8ab6b US
compressed
whitelisted
3236 iexplore.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAZnA1u7FP1jr8DWqFNO%2FhY%3D US
der
shared
3236 iexplore.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTGMlruL6P9M9B3if1rTM7wyj%2FQKQQUUGGmoNI1xBEqII0fD6xC8M0pz0sCEA6L83cNktGW8Lth%2BTxBZr4%3D US
der
shared
3236 iexplore.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D US
der
shared
2204 iexplore.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D US
der
shared

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2204 iexplore.exe 204.79.197.200:443 Microsoft Corporation US whitelisted
2204 iexplore.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
2204 iexplore.exe 93.184.221.240:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3236 iexplore.exe 140.82.121.4:443 US malicious
3236 iexplore.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3236 iexplore.exe 185.199.108.133:443 GitHub, Inc. NL malicious
2204 iexplore.exe 152.199.19.161:443 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted

DNS requests

Domain IP Reputation
github.com 140.82.121.4
shared
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
api.bing.com 13.107.5.80
whitelisted
ctldl.windowsupdate.com 93.184.221.240
whitelisted
ocsp.digicert.com 93.184.220.29
shared
objects.githubusercontent.com 185.199.108.133
185.199.109.133
185.199.110.133
185.199.111.133
malicious
iecvlist.microsoft.com 152.199.19.161
whitelisted
r20swj13mr.microsoft.com 152.199.19.161
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.