File name:

7tsp GUI v0.6.exe

Full analysis: https://app.any.run/tasks/af0433c3-2b61-41dd-9b97-1d92839e451f
Verdict: Malicious activity
Analysis date: May 25, 2025, 10:58:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

0FC4B5592E3B58F1FC87D5EF81DE981A

SHA1:

F9408F54BE6540CCAF7CE0B9DBB80B81AFD83CA8

SHA256:

090C9E214599150F6ED241171BB2107E04D13BFA5E74927B094B139EAE280B65

SSDEEP:

98304:0kJXjsBN1FOVttlTfMO5bkjUBoUpQbo3r95HwTClvBAOMpWaQ0dy4ybVWT1rk/lv:0o31yYVBFX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • cmd.exe (PID: 5132)
      • net.exe (PID: 2552)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • 7tsp GUI v0.6.exe (PID: 6992)
    • There is functionality for taking screenshot (YARA)

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Drops 7-zip archiver for unpacking

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Executable content was dropped or overwritten

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Reads security settings of Internet Explorer

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7568)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 6944)
      • cmd.exe (PID: 2644)
    • Process drops legitimate windows executable

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 7948)
      • cmd.exe (PID: 7580)
    • Takes ownership (TAKEOWN.EXE)

      • cmd.exe (PID: 6264)
    • Starts CMD.EXE for commands execution

      • 7tsp GUI v0.6.exe (PID: 6992)
  • INFO

    • The sample compiled with english language support

      • 7tsp GUI v0.6.exe (PID: 6992)
      • msedge.exe (PID: 4668)
    • Checks supported languages

      • 7tsp GUI v0.6.exe (PID: 6992)
      • identity_helper.exe (PID: 7260)
      • identity_helper.exe (PID: 4120)
    • Creates files in the program directory

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Reads mouse settings

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Create files in a temporary directory

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 4844)
    • Reads the computer name

      • 7tsp GUI v0.6.exe (PID: 6992)
      • identity_helper.exe (PID: 7260)
      • identity_helper.exe (PID: 4120)
    • UPX packer has been detected

      • 7tsp GUI v0.6.exe (PID: 6992)
    • The process uses AutoIt

      • 7tsp GUI v0.6.exe (PID: 6992)
    • Manual execution by a user

      • msedge.exe (PID: 2504)
      • WinRAR.exe (PID: 7676)
    • Reads the software policy settings

      • slui.exe (PID: 6252)
      • slui.exe (PID: 2692)
    • Application launched itself

      • msedge.exe (PID: 2504)
    • Reads Environment values

      • identity_helper.exe (PID: 7260)
      • identity_helper.exe (PID: 4120)
    • Checks proxy server information

      • slui.exe (PID: 2692)
    • Manages system restore points

      • SrTasks.exe (PID: 7636)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:03:07 16:08:39+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 270336
InitializedDataSize: 151552
UninitializedDataSize: 602112
EntryPoint: 0xd5bc0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.6.2.0
ProductVersionNumber: 3.3.6.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 0.6.2.0
Comments: Se7en Theme Source Patcher v0.6.2019 Patches your Windows Se7en System Files with new Icons and Bitmaps
FileDescription: Se7en Theme Source Patcher
LegalCopyright: XPtsp Team -Program Written By Fixit-
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
331
Monitored processes
195
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7tsp gui v0.6.exe sppextcomobj.exe no specs slui.exe notepad.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs rundll32.exe no specs winrar.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs conhost.exe no specs 7za.exe no specs msedge.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs cmd.exe no specs conhost.exe no specs takeown.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs cmd.exe no specs conhost.exe no specs reshacker.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs 7tsp gui v0.6.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516C:\WINDOWS\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -delete "C:\ProgramData\local\temp\7tsp\resources\shell32.dll.res", "C:\ProgramData\local\temp\7tsp\resources\shell32.dll.res", IMAGE,632,1033"C:\Windows\SysWOW64\cmd.exe7tsp GUI v0.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
516C:\WINDOWS\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -delete "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", IMAGE,5031,"C:\Windows\SysWOW64\cmd.exe7tsp GUI v0.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
704C:\WINDOWS\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -delete "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", IMAGE,5035,"C:\Windows\SysWOW64\cmd.exe7tsp GUI v0.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5648 --field-trial-handle=2460,i,7609091914687540837,8273180273966805818,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
736C:\WINDOWS\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -delete "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", IMAGE,5043,"C:\Windows\SysWOW64\cmd.exe7tsp GUI v0.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=5784 --field-trial-handle=2460,i,7609091914687540837,8273180273966805818,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1196"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2728 --field-trial-handle=2460,i,7609091914687540837,8273180273966805818,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244C:\WINDOWS\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -delete "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", "C:\ProgramData\local\temp\7tsp\resources\imageres.dll.res", IMAGE,5036,"C:\Windows\SysWOW64\cmd.exe7tsp GUI v0.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
17 760
Read events
17 364
Write events
369
Delete events
27

Modification events

(PID) Process:(6992) 7tsp GUI v0.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Fixit Tools\7tsp
Operation:writeName:Agreement
Value:
(2019)Yes
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2504) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
0FF299018A942F00
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2504) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
F5E091018A942F00
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\131680
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1D1C88CA-2C1B-4230-A563-E6D1456E6CD8}
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\131680
Operation:writeName:WindowTabManagerFileMappingId
Value:
{E30D551A-959A-4073-92D2-AFCB52F4D0E0}
(PID) Process:(2504) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\131680
Operation:writeName:WindowTabManagerFileMappingId
Value:
{CF26CF36-04BA-4A45-ADC5-FFC7407B3050}
Executable files
60
Suspicious files
1 026
Text files
305
Unknown types
1

Dropped files

PID
Process
Filename
Type
69927tsp GUI v0.6.exeC:\Users\admin\AppData\Local\Temp\autB1DE.tmpbinary
MD5:0C4F0907658D48D9356D01C14282B1A0
SHA256:15B3DE395AD0E35EED04C239703C5CF1187FD016FD2B021A47A43AC85FD49D50
69927tsp GUI v0.6.exeC:\ProgramData\local\temp\ReadMe.txttext
MD5:907DB78291FB358F7D8B4CE73D33F8F1
SHA256:4C01C8609EFEFF5B359AA5355266C933EDB3F50DCA1CBF532C4D9096253581C9
69927tsp GUI v0.6.exeC:\Users\admin\AppData\Local\Temp\autAE82.tmpbinary
MD5:50A46D26B330BCD5D0BAC4E14554953B
SHA256:0D7193BDB42674D17C242D8504DB31A2C5B6864BD1D372016E8CDC9EAA62D9E4
69927tsp GUI v0.6.exeC:\ProgramData\local\temp\7tsp\programs\logo.bmpimage
MD5:E0EF4516C9ECA05CCF55E3F6413B18FD
SHA256:FDE61D0757522A87E9D11A64A6FD08569BD7977E94ED9E9502F52843217B6D50
69927tsp GUI v0.6.exeC:\Users\admin\AppData\Local\Temp\autD555.tmpbinary
MD5:24A69F380E798553D3057BB10E48D5D7
SHA256:12A574B867BF5B93BFD50F0BE082BC34E8A081CF1D4632CC68F4EEE839B197C9
69927tsp GUI v0.6.exeC:\ProgramData\local\temp\7tsp\programs\logos.bmpimage
MD5:D04E046BA533CE644FE6B97CD492FDB5
SHA256:6D9C1A14BDBF29D835F297CBAF39CF94FC4725CCDFE8878E3548D194E2E46648
69927tsp GUI v0.6.exeC:\Users\admin\AppData\Local\Temp\autD567.tmpbinary
MD5:023586F4B3AE9E4113AA8E9B6F0F5E0D
SHA256:EE9FFFA33CDB8E0690A8FFBD875CEFC01973259D61E7BE1197102FD66AC1864E
69927tsp GUI v0.6.exeC:\ProgramData\local\temp\7tsp\programs\lang.initext
MD5:DD3D7C4A542DBD24F254093762300901
SHA256:38B48270CC628E4B60DDB354EE115E6C465740D0B93AA6FCAECC60D5C67D9B72
69927tsp GUI v0.6.exeC:\Users\admin\AppData\Local\Temp\autD556.tmpbinary
MD5:27DA1566828714105C1ADBB661C76F7A
SHA256:2555C1E91E885ADBFE1F55617B1649DC926DF9AE3BC09B99D727C428B0D2AB17
69927tsp GUI v0.6.exeC:\ProgramData\local\temp\7tsp\programs\logon.bmpimage
MD5:46924FE2203EEDB58D745612F23758F6
SHA256:35820E9395F57D10B75ADB672552C0F487A60D90F6856A91CD0A472983D613EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
208
DNS requests
182
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5096
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5096
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5580
svchost.exe
HEAD
200
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748299437&P2=404&P3=2&P4=APHyJ1IGyW6yNupHZ6g%2bcEduEKVBr%2fe7hJlJTOKvoIdJCKdkuasFg4WMI2%2byQwORZK6M%2fF7q3uE4DqBXfllM0A%3d%3d
unknown
whitelisted
5580
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748299437&P2=404&P3=2&P4=APHyJ1IGyW6yNupHZ6g%2bcEduEKVBr%2fe7hJlJTOKvoIdJCKdkuasFg4WMI2%2byQwORZK6M%2fF7q3uE4DqBXfllM0A%3d%3d
unknown
whitelisted
5580
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748299437&P2=404&P3=2&P4=APHyJ1IGyW6yNupHZ6g%2bcEduEKVBr%2fe7hJlJTOKvoIdJCKdkuasFg4WMI2%2byQwORZK6M%2fF7q3uE4DqBXfllM0A%3d%3d
unknown
whitelisted
5580
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748299437&P2=404&P3=2&P4=APHyJ1IGyW6yNupHZ6g%2bcEduEKVBr%2fe7hJlJTOKvoIdJCKdkuasFg4WMI2%2byQwORZK6M%2fF7q3uE4DqBXfllM0A%3d%3d
unknown
whitelisted
5580
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748299437&P2=404&P3=2&P4=APHyJ1IGyW6yNupHZ6g%2bcEduEKVBr%2fe7hJlJTOKvoIdJCKdkuasFg4WMI2%2byQwORZK6M%2fF7q3uE4DqBXfllM0A%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5796
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2660
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.71
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.129
  • 20.190.159.75
  • 20.190.159.2
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted

Threats

PID
Process
Class
Message
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1196
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
No debug info