URL:

https://downloads3.fxsound.com/fxsound/2/fxsound_setup.exe

Full analysis: https://app.any.run/tasks/74b88aab-80e2-4ec2-b17c-2de3fcb0001a
Verdict: Malicious activity
Analysis date: August 29, 2021, 13:39:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0E5FA4B1ED62312C8345C14D790DF3EE

SHA1:

821B97571AC06624BC3FBF88F311AD2BB3372864

SHA256:

09822F35A556E1245C5EBA9DF8ECBC6B09A7C4D79D47939D5BECA68681E5A7E8

SSDEEP:

3:N8SE4WLDUJLGT3LBKgNeB6HRu4A:2SGau1KV6HY4A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • fxsound_setup.exe (PID: 2668)
      • fxsound_setup.exe (PID: 1516)
      • fxdevcon32.exe (PID: 3480)
      • fxdevcon32.exe (PID: 1884)
      • DfxSetupDrv.exe (PID: 2916)
    • Writes to a start menu file

      • msiexec.exe (PID: 2908)
    • Loads dropped or rewritten executable

      • fxsound_setup.exe (PID: 1516)
      • MsiExec.exe (PID: 3228)
      • MsiExec.exe (PID: 2136)
      • MsiExec.exe (PID: 3592)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2552)
      • iexplore.exe (PID: 2580)
      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2908)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2552)
    • Drops a file that was compiled in debug mode

      • iexplore.exe (PID: 2552)
      • iexplore.exe (PID: 2580)
      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2908)
    • Checks supported languages

      • fxsound_setup.exe (PID: 1516)
      • fxdevcon32.exe (PID: 1884)
      • fxdevcon32.exe (PID: 3480)
      • DfxSetupDrv.exe (PID: 2916)
    • Reads the computer name

      • fxsound_setup.exe (PID: 1516)
      • fxdevcon32.exe (PID: 1884)
      • DfxSetupDrv.exe (PID: 2916)
      • fxdevcon32.exe (PID: 3480)
      • DrvInst.exe (PID: 2484)
    • Reads Environment values

      • fxsound_setup.exe (PID: 1516)
      • MsiExec.exe (PID: 2136)
      • vssvc.exe (PID: 3288)
      • MsiExec.exe (PID: 3228)
    • Creates files in the user directory

      • fxsound_setup.exe (PID: 1516)
    • Executed as Windows Service

      • msiexec.exe (PID: 2908)
      • vssvc.exe (PID: 3288)
    • Reads the Windows organization settings

      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2352)
      • msiexec.exe (PID: 2908)
    • Reads Windows owner or organization settings

      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2352)
      • msiexec.exe (PID: 2908)
    • Application launched itself

      • msiexec.exe (PID: 2908)
    • Starts Microsoft Installer

      • fxsound_setup.exe (PID: 1516)
    • Searches for installed software

      • msiexec.exe (PID: 2908)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 2908)
      • DrvInst.exe (PID: 2484)
      • fxdevcon32.exe (PID: 3480)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 2908)
    • Creates files in the program directory

      • msiexec.exe (PID: 2908)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2908)
    • Executed via COM

      • DrvInst.exe (PID: 2484)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2484)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 2484)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2484)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 2580)
      • iexplore.exe (PID: 2552)
      • msiexec.exe (PID: 2908)
      • MsiExec.exe (PID: 2136)
      • msiexec.exe (PID: 2352)
      • vssvc.exe (PID: 3288)
      • MsiExec.exe (PID: 3592)
      • MsiExec.exe (PID: 3228)
    • Checks supported languages

      • iexplore.exe (PID: 2580)
      • iexplore.exe (PID: 2552)
      • msiexec.exe (PID: 2908)
      • MsiExec.exe (PID: 2136)
      • msiexec.exe (PID: 2352)
      • vssvc.exe (PID: 3288)
      • MsiExec.exe (PID: 3228)
      • MsiExec.exe (PID: 3592)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2552)
      • iexplore.exe (PID: 2580)
      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2908)
      • msiexec.exe (PID: 2352)
      • fxdevcon32.exe (PID: 3480)
      • DrvInst.exe (PID: 2484)
    • Application launched itself

      • iexplore.exe (PID: 2580)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2552)
      • iexplore.exe (PID: 2580)
      • fxsound_setup.exe (PID: 1516)
      • msiexec.exe (PID: 2352)
      • msiexec.exe (PID: 2908)
      • fxdevcon32.exe (PID: 3480)
    • Changes internet zones settings

      • iexplore.exe (PID: 2580)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2580)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2580)
    • Check for Java to be installed

      • MsiExec.exe (PID: 2136)
      • MsiExec.exe (PID: 3228)
    • Reads Microsoft Office registry keys

      • MsiExec.exe (PID: 2136)
      • MsiExec.exe (PID: 3228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
15
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe fxsound_setup.exe no specs fxsound_setup.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe msiexec.exe fxdevcon32.exe no specs dfxsetupdrv.exe no specs fxdevcon32.exe no specs drvinst.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1516"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\fxsound_setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\fxsound_setup.exe
iexplore.exe
User:
admin
Company:
FxSound LLC
Integrity Level:
HIGH
Description:
FxSound Installer
Exit code:
0
Version:
1.1.9.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\fxsound_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1884"C:\Program Files\FxSound LLC\FxSound\Drivers\win7\x86\fxdevcon32.exe" remove *DFX12C:\Program Files\FxSound LLC\FxSound\Drivers\win7\x86\fxdevcon32.exeMsiExec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Modules
Images
c:\program files\fxsound llc\fxsound\drivers\win7\x86\fxdevcon32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2136C:\Windows\system32\MsiExec.exe -Embedding 0ED92E34F85E96798600DE29861C3CF3 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2352"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\FxSound LLC\FxSound 1.1.9.0\install\fxsound.msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\fxsound_setup.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\" EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1630243723 " AI_EUIMSI=""C:\Windows\system32\msiexec.exefxsound_setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2384rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{202900a0-e6a2-7f5e-e723-3c6ae7233c6a} Global\{40e55541-064f-0a1d-703d-150d59ee457f} C:\Windows\System32\DriverStore\Temp\{5590f643-8e34-49f5-fbf3-86317ff41d3d}\fxvad.inf C:\Windows\System32\DriverStore\Temp\{5590f643-8e34-49f5-fbf3-86317ff41d3d}\fxvadNTx86.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2484DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{241ceaad-4a1c-5f44-a6d3-4649c77b2c64}\fxvad.inf" "0" "6143399a7" "000005C8" "WinSta0\Default" "000003E4" "208" "c:\program files\fxsound llc\fxsound\drivers\win7\x86"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2552"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2580 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2580"C:\Program Files\Internet Explorer\iexplore.exe" "https://downloads3.fxsound.com/fxsound/2/fxsound_setup.exe"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
2668"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\fxsound_setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\fxsound_setup.exeiexplore.exe
User:
admin
Company:
FxSound LLC
Integrity Level:
MEDIUM
Description:
FxSound Installer
Exit code:
3221226540
Version:
1.1.9.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\fxsound_setup.exe
c:\windows\system32\ntdll.dll
2908C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
Total events
26 645
Read events
26 164
Write events
468
Delete events
13

Modification events

(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30907611
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30907611
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2580) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
44
Suspicious files
20
Text files
35
Unknown types
16

Dropped files

PID
Process
Filename
Type
1516fxsound_setup.exeC:\Users\admin\AppData\Roaming\FxSound LLC\FxSound 1.1.9.0\install\holder0.aiph
MD5:
SHA256:
1516fxsound_setup.exeC:\Users\admin\AppData\Local\Temp\MSI1B18.LOG
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF9647E12F7B420E4F.TMPgmc
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62der
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fbinary
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fder
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FC5A820A001B41D68902E051F36A5282_E68774D253E609323A136F0BCDF12D93der
MD5:
SHA256:
2552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
62
TCP/UDP connections
11
DNS requests
7
Threats
56

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
2552
iexplore.exe
GET
200
143.204.101.74:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
2552
iexplore.exe
GET
200
143.204.101.74:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAq%2B8pVyrGYz72fbz%2BKjFOA%3D
US
der
471 b
whitelisted
2552
iexplore.exe
GET
200
143.204.101.99:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
POST
200
3.209.18.1:80
http://collect.installeranalytics.com/
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2552
iexplore.exe
143.204.98.16:443
downloads3.fxsound.com
US
malicious
2552
iexplore.exe
67.27.158.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2552
iexplore.exe
143.204.101.99:80
o.ss2.us
US
suspicious
2552
iexplore.exe
143.204.101.190:80
ocsp.rootg2.amazontrust.com
US
whitelisted
2552
iexplore.exe
143.204.101.74:80
ocsp.rootg2.amazontrust.com
US
whitelisted
3.209.18.1:80
collect.installeranalytics.com
US
malicious
1408
svchost.exe
67.27.158.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
downloads3.fxsound.com
  • 143.204.98.16
  • 143.204.98.47
  • 143.204.98.67
  • 143.204.98.29
malicious
ctldl.windowsupdate.com
  • 67.27.158.254
  • 67.27.158.126
  • 67.27.233.126
  • 67.27.235.254
  • 67.26.139.254
whitelisted
o.ss2.us
  • 143.204.101.99
  • 143.204.101.195
  • 143.204.101.123
  • 143.204.101.177
whitelisted
ocsp.rootg2.amazontrust.com
  • 143.204.101.190
  • 143.204.101.124
  • 143.204.101.74
  • 143.204.101.42
whitelisted
ocsp.rootca1.amazontrust.com
  • 143.204.101.74
  • 143.204.101.42
  • 143.204.101.190
  • 143.204.101.124
shared
ocsp.sca1b.amazontrust.com
  • 143.204.101.74
  • 143.204.101.188
  • 143.204.101.52
  • 143.204.101.143
whitelisted
collect.installeranalytics.com
  • 3.209.18.1
  • 3.232.36.43
malicious

Threats

Found threats are available for the paid subscriptions
56 ETPRO signatures available at the full report
Process
Message
MsiExec.exe
Logger::SetLogFile( C:\Users\admin\AppData\Roaming\Caphyon\Advanced Installer\AI_ResourceCleaner.log ) while OLD path is:
MsiExec.exe
Logger::SetLogFile( C:\Users\admin\AppData\Roaming\Caphyon\Advanced Installer\AI_ResourceCleaner.log ) while OLD path is:
MsiExec.exe
Logger::SetLogFile( C:\Users\admin\AppData\Roaming\Caphyon\Advanced Installer\AI_ResourceCleaner.log ) while OLD path is: