| File name: | Antivirus.exe |
| Full analysis: | https://app.any.run/tasks/43434fd9-e1ea-480f-91ec-d1ef538d2eb6 |
| Verdict: | Malicious activity |
| Analysis date: | January 13, 2025, 09:14:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 43CD42FE47AF2256E4414264F49AF1A8 |
| SHA1: | 3CCBBFFFD0DA76F72DD99AC39AFCFDFACD5F16E2 |
| SHA256: | 0918FA4B22D3E212A13FA449A5A7B5C3EC97759DD87DB6D281F387B1570E13C9 |
| SSDEEP: | 3072:fVGnJGXX4ftqRjLnohZR2NyDxHUSUIUyAUw5TmpAREl7j3:fVG4XX4ftqBLohjD9UXyAUtiO3 |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:07:14 20:09:51+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x310b |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 736 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6880.21347\salinewin.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6880.21347\salinewin.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1016 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3336 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2008 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=5340 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2144 | C:\Windows\System32\SecurityHealthHost.exe {E041C90B-68BA-42C9-991E-477B73A75C90} -Embedding | C:\Windows\System32\SecurityHealthHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Security Health Host Exit code: 0 Version: 4.18.1907.16384 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2420 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --mojo-platform-channel-handle=5896 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2672 | "C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe" | C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1073807364 Modules
| |||||||||||||||
| 3656 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5692 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 3700 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3420 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 3732 | C:\Windows\System32\SystemSettingsBroker.exe -Embedding | C:\Windows\System32\SystemSettingsBroker.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: System Settings Broker Exit code: 1073807364 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3812 | "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca | C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Shell Experience Host Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | \REGISTRY\A\{ec6344ba-7740-e13f-8dcc-37462428f73a}\LocalState |
| Operation: | write | Name: | placeholderLayout |
Value: 7B0022004900730052006500730069007A00610062006C00650022003A0074007200750065002C002200470072006F0075007000730022003A005B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0031002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022002C0022005400690074006C00650022003A0022004E006500740077006F0072006B0022002C002200490063006F006E0022003A00220077EE22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022002C0022005400690074006C00650022003A00220041006C006C002000730065007400740069006E006700730022002C002200490063006F006E0022003A00220013E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022002C0022005400690074006C00650022003A0022004C006F0063006100740069006F006E0022002C002200490063006F006E0022003A00220007E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022002C0022005400690074006C00650022003A00220046006F00630075007300200061007300730069007300740022002C002200490063006F006E0022003A00220008E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022002C0022005400690074006C00650022003A0022004E00690067006800740020006C00690067006800740022002C002200490063006F006E0022003A0022008CF022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022002C0022005400690074006C00650022003A002200560050004E0022002C002200490063006F006E0022003A00220005E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022002C0022005400690074006C00650022003A002200500072006F006A0065006300740022002C002200490063006F006E0022003A002200C6EB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022002C0022005400690074006C00650022003A00220043006F006E006E0065006300740022002C002200490063006F006E0022003A002200DEEB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022002C0022005400690074006C00650022003A002200530063007200650065006E00200073006E006900700022002C002200490063006F006E0022003A00220006F422002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220053006C006900640065007200470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0031002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D005D007D00000014CCCDA39B65DB01 | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.controlcenter.uistate\windows.data.controlcenter.uistate |
| Operation: | write | Name: | Data |
Value: 434201000A0201002A069DB393BC062A2B0EFD2A43420100D20AD4085B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006100740074006500720079005300610076006500720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C007500650074006F006F007400680022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005400610062006C00650074004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0052006F0074006100740069006F006E004C006F0063006B0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006C006F007200500072006F00660069006C00650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00430065006C006C0075006C006100720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004D006F00620069006C00650048006F007400730070006F00740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006900720070006C0061006E0065004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004E006500610072005300680061007200650022007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004200720069006700680074006E0065007300730022007D005D007D005D00D214E40C7B0022004900730052006500730069007A00610062006C00650022003A0074007200750065002C002200470072006F0075007000730022003A005B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0031002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022002C0022005400690074006C00650022003A0022004E006500740077006F0072006B0022002C002200490063006F006E0022003A00220077EE22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022002C0022005400690074006C00650022003A00220041006C006C002000730065007400740069006E006700730022002C002200490063006F006E0022003A00220013E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022002C0022005400690074006C00650022003A0022004C006F0063006100740069006F006E0022002C002200490063006F006E0022003A00220007E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022002C0022005400690074006C00650022003A00220046006F00630075007300200061007300730069007300740022002C002200490063006F006E0022003A00220008E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022002C0022005400690074006C00650022003A0022004E00690067006800740020006C00690067006800740022002C002200490063006F006E0022003A0022008CF022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022002C0022005400690074006C00650022003A002200560050004E0022002C002200490063006F006E0022003A00220005E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022002C0022005400690074006C00650022003A002200500072006F006A0065006300740022002C002200490063006F006E0022003A002200C6EB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022002C0022005400690074006C00650022003A00220043006F006E006E0065006300740022002C002200490063006F006E0022003A002200DEEB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022002C0022005400690074006C00650022003A002200530063007200650065006E00200073006E006900700022002C002200490063006F006E0022003A00220006F422002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220053006C006900640065007200470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0031002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D005D007D0000000000 | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | \REGISTRY\A\{ec6344ba-7740-e13f-8dcc-37462428f73a}\LocalState |
| Operation: | write | Name: | layout |
Value: 5B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006100740074006500720079005300610076006500720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C007500650074006F006F007400680022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005400610062006C00650074004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0052006F0074006100740069006F006E004C006F0063006B0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006C006F007200500072006F00660069006C00650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00430065006C006C0075006C006100720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004D006F00620069006C00650048006F007400730070006F00740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006900720070006C0061006E0065004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004E006500610072005300680061007200650022007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004200720069006700680074006E0065007300730022007D005D007D005D000000274DCBA39B65DB01 | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture |
| Operation: | write | Name: | GroupCount |
Value: 3 | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture |
| Operation: | write | Name: | Toggles |
Value: Toggles,Microsoft.QuickAction.AvailableNetworks:false,Microsoft.QuickAction.AllSettings:false,Microsoft.QuickAction.Location:false,Microsoft.QuickAction.QuietHours:false,Microsoft.QuickAction.BlueLightReduction:false,Microsoft.QuickAction.Vpn:false,Microsoft.QuickAction.Project:false,Microsoft.QuickAction.Connect:false,Microsoft.QuickAction.ScreenClipping:false | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture |
| Operation: | write | Name: | Flows |
Value: Flows | |||
| (PID) Process: | (3812) ShellExperienceHost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture |
| Operation: | write | Name: | Sliders |
Value: Sliders | |||
| (PID) Process: | (6500) Antivirus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\vtuploader |
| Operation: | write | Name: | Icon |
Value: C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe,0 | |||
| (PID) Process: | (6500) Antivirus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Virustotal\VTUploader |
| Operation: | write | Name: | Install_Dir |
Value: C:\Program Files (x86)\VirusTotalUploader2 | |||
| (PID) Process: | (6500) Antivirus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VTUploader |
| Operation: | write | Name: | DisplayName |
Value: VirusTotal Uploader 2.2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1465ec.TMP | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1465ec.TMP | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1465ec.TMP | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1465ec.TMP | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF1465fc.TMP | — | |
MD5:— | SHA256:— | |||
| 7552 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5268 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/mleab47izotil6qv3goi2qnzb4_20250105.712697894.14/obedbbhbpmojnkanicioggnmelmoomoc_20250105.712697894.14_all_ENUS500000_adrawdzru5huqzgurwx7xv4jv3ua.crx3 | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5592 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5592 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
6840 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5268 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads7ltfl2gw6hxwgakn3sxrkoijq_9.53.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.53.0_all_iky7dhj3jd5su3axccoshyd4xm.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 40.119.249.228:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | SG | unknown |
5064 | SearchApp.exe | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 40.119.249.228:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | SG | unknown |
4712 | MoUsoCoreWorker.exe | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
r.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7724 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
7724 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |