URL:

d3tl5rwi83n7i8.cloudfront.net/1Jj5UK0ZayDj.exe

Full analysis: https://app.any.run/tasks/80dc0497-b134-4407-89ff-1b24256f8cb2
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 10, 2024, 14:58:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
innosetup
loader
arch-exec
stealer
Indicators:
MD5:

F90F976825DDF1251B92A71839359B87

SHA1:

F90D712F093BAA1804D9F7B7C61A1F1D6B992CCF

SHA256:

0A032FD538D9065362F6942EDADF01FBE25A5E271793E8C9A68E8CF1291A9585

SSDEEP:

3:TWmcyJ0l/04xsCn:TWZMUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INNOSETUP has been detected (SURICATA)

      • file_0cB-pt1.tmp (PID: 7256)
    • Steals credentials from Web Browsers

      • setup.exe (PID: 6736)
      • setup.exe (PID: 5316)
      • setup.exe (PID: 2280)
      • installer.exe (PID: 5720)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 6736)
      • setup.exe (PID: 5316)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 2280)
      • installer.exe (PID: 5720)
    • The DLL Hijacking

      • Teams.exe (PID: 4876)
      • Teams.exe (PID: 6568)
    • Changes the autorun value in the registry

      • Teams.exe (PID: 7748)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Update.exe (PID: 1476)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • microsoft-teams_0cB-pt1.exe (PID: 7268)
      • microsoft-teams_0cB-pt1.tmp (PID: 7712)
      • file_0cB-pt1.tmp (PID: 7256)
      • file_0cB-pt1.exe (PID: 7804)
      • microsoft-teams_0cB-pt1.exe (PID: 4932)
      • OperaSetup.exe (PID: 6244)
      • setup.exe (PID: 5316)
      • setup.exe (PID: 6736)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 2280)
      • microsoft-teams.exe (PID: 3688)
      • Update.exe (PID: 1476)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6172)
      • assistant_installer.exe (PID: 4684)
      • installer.exe (PID: 5720)
      • installer.exe (PID: 5576)
    • Reads the Windows owner or organization settings

      • file_0cB-pt1.tmp (PID: 7256)
    • Process requests binary or script from the Internet

      • file_0cB-pt1.tmp (PID: 7256)
    • Access to an unwanted program domain was detected

      • file_0cB-pt1.tmp (PID: 7256)
    • Potential Corporate Privacy Violation

      • file_0cB-pt1.tmp (PID: 7256)
    • Reads security settings of Internet Explorer

      • microsoft-teams_0cB-pt1.tmp (PID: 7296)
      • file_0cB-pt1.tmp (PID: 7256)
      • setup.exe (PID: 6736)
      • browser_assistant.exe (PID: 6780)
    • Application launched itself

      • setup.exe (PID: 6736)
      • setup.exe (PID: 4996)
      • assistant_installer.exe (PID: 6796)
      • Teams.exe (PID: 6168)
      • Teams.exe (PID: 7748)
      • assistant_installer.exe (PID: 4684)
      • assistant_installer.exe (PID: 644)
      • browser_assistant.exe (PID: 6780)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 6724)
      • installer.exe (PID: 5576)
      • installer.exe (PID: 8980)
      • opera_autoupdate.exe (PID: 9112)
      • opera_autoupdate.exe (PID: 7400)
    • Checks Windows Trust Settings

      • setup.exe (PID: 6736)
      • browser_assistant.exe (PID: 6780)
    • Process drops legitimate windows executable

      • file_0cB-pt1.tmp (PID: 7256)
      • microsoft-teams.exe (PID: 3688)
      • Update.exe (PID: 1476)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6172)
      • assistant_installer.exe (PID: 4684)
    • Executes application which crashes

      • file_0cB-pt1.tmp (PID: 7256)
    • Starts itself from another location

      • setup.exe (PID: 6736)
    • The process drops C-runtime libraries

      • Update.exe (PID: 1476)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 7212)
      • regsvr32.exe (PID: 5460)
    • Searches for installed software

      • Update.exe (PID: 1476)
      • browser_assistant.exe (PID: 6780)
    • Creates a software uninstall entry

      • Update.exe (PID: 1476)
    • Reads the date of Windows installation

      • installer.exe (PID: 5576)
      • opera.exe (PID: 6724)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 6724)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 9112)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 8016)
      • microsoft-teams_0cB-pt1.tmp (PID: 7296)
      • microsoft-teams_0cB-pt1.exe (PID: 7268)
      • file_0cB-pt1.exe (PID: 7804)
      • file_0cB-pt1.tmp (PID: 7256)
      • microsoft-teams_0cB-pt1.exe (PID: 4932)
      • OperaSetup.exe (PID: 6244)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 2280)
      • setup.exe (PID: 4996)
      • microsoft-teams.exe (PID: 7648)
      • Update.exe (PID: 1476)
      • identity_helper.exe (PID: 1572)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6172)
      • assistant_installer.exe (PID: 6796)
      • Squirrel.exe (PID: 6156)
      • Teams.exe (PID: 6168)
      • Update.exe (PID: 4164)
      • Teams.exe (PID: 7124)
      • Teams.exe (PID: 7748)
      • Teams.exe (PID: 4876)
      • Teams.exe (PID: 6568)
      • Teams.exe (PID: 556)
      • Teams.exe (PID: 3824)
      • Teams.exe (PID: 5992)
      • Teams.exe (PID: 7344)
      • installer.exe (PID: 5576)
      • assistant_installer.exe (PID: 4684)
      • assistant_installer.exe (PID: 644)
      • browser_assistant.exe (PID: 6780)
      • opera_crashreporter.exe (PID: 3864)
      • opera_crashreporter.exe (PID: 3508)
      • opera.exe (PID: 7528)
      • browser_assistant.exe (PID: 7384)
      • opera.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 1876)
      • setup.exe (PID: 5316)
      • installer.exe (PID: 5720)
      • opera.exe (PID: 3936)
      • opera.exe (PID: 644)
      • opera_crashreporter.exe (PID: 5964)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 3540)
      • opera_crashreporter.exe (PID: 4132)
      • opera.exe (PID: 1476)
      • opera.exe (PID: 6724)
      • opera.exe (PID: 6724)
      • opera.exe (PID: 1200)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 7612)
      • opera.exe (PID: 7664)
      • opera.exe (PID: 7464)
      • opera.exe (PID: 5652)
      • opera.exe (PID: 7312)
      • opera_gx_splash.exe (PID: 8276)
      • opera.exe (PID: 8448)
      • opera.exe (PID: 8456)
      • opera.exe (PID: 8464)
      • opera.exe (PID: 8532)
      • opera.exe (PID: 8608)
      • opera.exe (PID: 8688)
      • opera.exe (PID: 8952)
      • opera.exe (PID: 8960)
      • opera.exe (PID: 8976)
      • opera.exe (PID: 9008)
      • opera.exe (PID: 9044)
      • opera.exe (PID: 9060)
      • opera.exe (PID: 9000)
      • opera.exe (PID: 9068)
      • opera.exe (PID: 9096)
      • opera.exe (PID: 8660)
      • opera.exe (PID: 9016)
      • opera.exe (PID: 9088)
      • opera.exe (PID: 5888)
      • opera.exe (PID: 9080)
      • opera.exe (PID: 9120)
      • opera.exe (PID: 5256)
      • opera.exe (PID: 5616)
      • opera.exe (PID: 9072)
      • installer.exe (PID: 8980)
      • installer.exe (PID: 9196)
      • opera_autoupdate.exe (PID: 5712)
      • opera_autoupdate.exe (PID: 7400)
      • opera.exe (PID: 8944)
      • opera.exe (PID: 8292)
      • opera.exe (PID: 8920)
      • opera.exe (PID: 5888)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6424)
      • msedge.exe (PID: 6896)
    • Reads the computer name

      • identity_helper.exe (PID: 8016)
      • microsoft-teams_0cB-pt1.tmp (PID: 7296)
      • file_0cB-pt1.tmp (PID: 7256)
      • microsoft-teams.exe (PID: 7648)
      • Squirrel.exe (PID: 6156)
      • Teams.exe (PID: 6168)
      • Teams.exe (PID: 7124)
      • Update.exe (PID: 4164)
      • Teams.exe (PID: 6568)
      • Teams.exe (PID: 556)
      • Teams.exe (PID: 7748)
      • installer.exe (PID: 5576)
      • Teams.exe (PID: 7344)
      • assistant_installer.exe (PID: 644)
      • opera.exe (PID: 6200)
      • opera.exe (PID: 1476)
      • opera.exe (PID: 7528)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 6724)
      • opera.exe (PID: 7312)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 8688)
      • opera_gx_splash.exe (PID: 8276)
      • opera.exe (PID: 8944)
      • opera_autoupdate.exe (PID: 9112)
    • Application launched itself

      • msedge.exe (PID: 6424)
    • Reads Environment values

      • identity_helper.exe (PID: 8016)
      • Teams.exe (PID: 6168)
      • Teams.exe (PID: 7748)
    • The process uses the downloaded file

      • msedge.exe (PID: 7508)
      • msedge.exe (PID: 6424)
      • file_0cB-pt1.tmp (PID: 7256)
      • explorer.exe (PID: 4488)
      • Update.exe (PID: 1476)
    • Process checks computer location settings

      • microsoft-teams_0cB-pt1.tmp (PID: 7296)
      • file_0cB-pt1.tmp (PID: 7256)
      • Teams.exe (PID: 7748)
      • Teams.exe (PID: 5992)
      • opera.exe (PID: 6724)
      • opera.exe (PID: 8456)
      • opera.exe (PID: 8532)
      • opera.exe (PID: 7664)
      • opera.exe (PID: 8960)
      • opera.exe (PID: 8660)
      • opera.exe (PID: 3732)
    • Create files in a temporary directory

      • microsoft-teams_0cB-pt1.exe (PID: 7268)
      • file_0cB-pt1.exe (PID: 7804)
      • file_0cB-pt1.tmp (PID: 7256)
      • setup.exe (PID: 6736)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 2280)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6172)
      • Teams.exe (PID: 7748)
      • installer.exe (PID: 5720)
    • Reads the software policy settings

      • microsoft-teams_0cB-pt1.tmp (PID: 7712)
      • file_0cB-pt1.tmp (PID: 7256)
      • setup.exe (PID: 6736)
      • WerFault.exe (PID: 7040)
      • WerFault.exe (PID: 3620)
      • Update.exe (PID: 1476)
      • Update.exe (PID: 4164)
      • Squirrel.exe (PID: 6156)
      • Teams.exe (PID: 7748)
      • installer.exe (PID: 5576)
      • browser_assistant.exe (PID: 6780)
    • Reads the machine GUID from the registry

      • file_0cB-pt1.tmp (PID: 7256)
      • setup.exe (PID: 6736)
      • Update.exe (PID: 1476)
      • Squirrel.exe (PID: 6156)
      • Update.exe (PID: 4164)
      • Teams.exe (PID: 7748)
      • installer.exe (PID: 5576)
      • browser_assistant.exe (PID: 6780)
      • opera.exe (PID: 6724)
    • The sample compiled with english language support

      • file_0cB-pt1.tmp (PID: 7256)
      • OperaSetup.exe (PID: 6244)
      • setup.exe (PID: 5316)
      • setup.exe (PID: 6736)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 2280)
      • Update.exe (PID: 1476)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6172)
      • assistant_installer.exe (PID: 4684)
      • installer.exe (PID: 5720)
      • installer.exe (PID: 5576)
    • Creates files or folders in the user directory

      • setup.exe (PID: 5316)
      • setup.exe (PID: 6736)
      • WerFault.exe (PID: 7040)
      • Update.exe (PID: 1476)
      • Teams.exe (PID: 6168)
      • Update.exe (PID: 4164)
      • Teams.exe (PID: 7748)
      • setup.exe (PID: 4996)
      • Teams.exe (PID: 556)
    • Checks proxy server information

      • file_0cB-pt1.tmp (PID: 7256)
      • setup.exe (PID: 6736)
      • WerFault.exe (PID: 7040)
      • WerFault.exe (PID: 3620)
      • Update.exe (PID: 1476)
      • Teams.exe (PID: 7748)
      • explorer.exe (PID: 4488)
      • Squirrel.exe (PID: 6156)
      • opera.exe (PID: 6724)
      • browser_assistant.exe (PID: 6780)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4488)
    • Manual execution by a user

      • microsoft-teams.exe (PID: 3688)
    • Sends debugging messages

      • Update.exe (PID: 1476)
      • assistant_installer.exe (PID: 6796)
      • Squirrel.exe (PID: 6156)
      • Update.exe (PID: 4164)
      • assistant_installer.exe (PID: 4684)
      • assistant_installer.exe (PID: 644)
      • browser_assistant.exe (PID: 6780)
    • Reads Microsoft Office registry keys

      • Squirrel.exe (PID: 6156)
      • Update.exe (PID: 4164)
      • Teams.exe (PID: 7748)
    • Reads product name

      • Teams.exe (PID: 6168)
    • Disables trace logs

      • Update.exe (PID: 4164)
    • Reads CPU info

      • Teams.exe (PID: 7748)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
312
Monitored processes
172
Malicious processes
19
Suspicious processes
4

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs microsoft-teams_0cb-pt1.exe microsoft-teams_0cb-pt1.tmp no specs microsoft-teams_0cb-pt1.exe microsoft-teams_0cb-pt1.tmp file_0cb-pt1.exe #INNOSETUP file_0cb-pt1.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs operasetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe microsoft-teams.exe no specs microsoft-teams.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs update.exe werfault.exe identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs werfault.exe msedge.exe no specs rundll32.exe no specs assistant_114.0.5282.21_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe no specs msedge.exe no specs squirrel.exe teams.exe no specs update.exe teams.exe no specs teams.exe no specs teams.exe teams.exe no specs teams.exe teams.exe no specs teams.exe no specs msedge.exe no specs teams.exe no specs teams.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs installer.exe installer.exe assistant_installer.exe assistant_installer.exe no specs assistant_installer.exe assistant_installer.exe no specs browser_assistant.exe opera.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera_crashreporter.exe no specs browser_assistant.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera_crashreporter.exe no specs opera.exe unsecapp.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera_gx_splash.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe no specs opera.exe no specs installer.exe no specs opera_autoupdate.exe no specs opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --field-trial-handle=3116,i,3039716824808083466,17911402124988841619,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3100 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
115.0.5322.77
556"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --enable-wer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --mojo-platform-channel-handle=2204 --field-trial-handle=1844,i,11604109287136300604,1955575335313240033,131072 --enable-features=ContextBridgeMutability,SharedArrayBuffer,WinUseBrowserSpellChecker,WinUseHybridSpellChecker --disable-features=CalculateNativeWinOcclusion,ExtraCookieValidityChecks,ForcedColors,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Teams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Version:
1.7.00.26062
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
644"C:\Users\admin\AppData\Local\Programs\Opera\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --run-assistant --allusers=0C:\Users\admin\AppData\Local\Programs\Opera\assistant\assistant_installer.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
114.0.5282.21
Modules
Images
c:\users\admin\appdata\local\programs\opera\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
644"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --field-trial-handle=2428,i,8206137282727233129,6668262214738778496,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=2436 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
115.0.5322.77
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
836"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --field-trial-handle=3688,i,3039716824808083466,17911402124988841619,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=8732 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
115.0.5322.77
880"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --extension-process --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=54 --field-trial-handle=10016,i,3039716824808083466,17911402124988841619,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=6456 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
115.0.5322.77
1200"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --field-trial-handle=2424,i,3039716824808083466,17911402124988841619,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=2368 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
115.0.5322.77
1476"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . --rerunningWithoutUAC --exeName=microsoft-teams.exeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
microsoft-teams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams classic
Exit code:
0
Version:
3.3.13.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1476"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --show-intro-overlay --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera\opera.exeinstaller.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Internet Browser
Exit code:
24
Version:
115.0.5322.77
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1572"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4240 --field-trial-handle=2324,i,15560796447333297652,13151938044983711067,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\bcrypt.dll
Total events
73 398
Read events
72 407
Write events
941
Delete events
50

Modification events

(PID) Process:(4488) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000005029E
Operation:writeName:VirtualDesktop
Value:
1000000030304456A48A294F7A40804AB924005FF030B61F
(PID) Process:(6424) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
4DCB83FF81872F00
(PID) Process:(6424) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
449A8DFF81872F00
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328350
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1324B458-167E-46A7-923F-EB6CA97C9C41}
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328350
Operation:writeName:WindowTabManagerFileMappingId
Value:
{8B6ECB07-BDF8-4515-8498-6881A02C882D}
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6424) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A
Value:
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
Executable files
387
Suspicious files
690
Text files
352
Unknown types
103

Dropped files

PID
Process
Filename
Type
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1355d4.TMP
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1355d4.TMP
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1355d4.TMP
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1355e3.TMP
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1355f3.TMP
MD5:
SHA256:
6424msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
96
TCP/UDP connections
159
DNS requests
167
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6424
msedge.exe
GET
200
23.53.43.50:80
http://sslcom.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDkJwSV9oyR1tDse0lOpN8c
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.24.77.35:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6424
msedge.exe
GET
200
34.237.184.165:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQMDtATfnJO6JAXDQoHl8pAaJdhTQQU3QQJB6L1en1SUxKSle44gCUNplkCEFt%2FVDgl5BqhKt4hQ5zf5m8%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2356
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6424
msedge.exe
GET
200
18.244.18.92:80
http://crls.ssl.com/ssl.com-rsa-RootCA.crl
unknown
whitelisted
6424
msedge.exe
GET
200
34.237.184.165:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS0UJ9%2FZn2kc3RfVu9A%2FfyFSdQVAwQURPou5oAhpEaXDmroM7xTEWZNqbkCEF4bdHMJUrH6Pg1KnFCo2r4%3D
unknown
whitelisted
6424
msedge.exe
GET
200
18.244.18.92:80
http://crls.ssl.com/DTNT-Intermediate-codeSigning-RSA-4096-R2.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
184.24.77.35:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2356
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
92.123.104.35:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4188
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 184.24.77.35
  • 184.24.77.12
  • 2.16.241.19
  • 2.16.241.12
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 88.221.169.152
whitelisted
google.com
  • 142.250.186.110
  • 142.250.185.142
  • 142.250.185.174
whitelisted
www.bing.com
  • 92.123.104.35
  • 92.123.104.41
  • 92.123.104.43
  • 92.123.104.34
  • 92.123.104.37
  • 92.123.104.40
  • 92.123.104.38
  • 92.123.104.33
  • 92.123.104.36
  • 2.23.209.176
  • 2.23.209.167
  • 2.23.209.177
  • 2.23.209.174
  • 2.23.209.166
  • 2.23.209.178
  • 2.23.209.173
  • 2.23.209.171
  • 2.23.209.168
  • 2.23.209.169
  • 2.23.209.184
  • 2.23.209.183
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.188
  • 2.23.209.185
  • 2.23.209.192
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.140
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.76
  • 40.126.32.68
  • 20.190.160.14
  • 20.190.160.22
  • 20.190.159.23
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.0
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
d3tl5rwi83n7i8.cloudfront.net
  • 18.245.62.131
  • 18.245.62.119
  • 18.245.62.176
  • 18.245.62.50
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

PID
Process
Class
Message
7256
file_0cB-pt1.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
7256
file_0cB-pt1.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Process
Message
Update.exe
Update.exe Information: 0 :
Update.exe
Starting TelemetryManager constructor
Update.exe
Update.exe Information: 0 :
Update.exe
TelemetryManagerImpl creation started
Update.exe
Update.exe Information: 0 :
Update.exe
Performance counters are disabled. Skipping creation of counters category.
Update.exe
Update.exe Information: 0 :
Update.exe
RecordBatcherTask with ID 4 started.
Update.exe
DataPackageSender with UserAgent name: AST-exe-C#, version: 3.3.13.0, [Ast_Default_Source]
Update.exe
Update.exe Information: 0 :