URL:

https://gamefabrique.com/games/city-transport-simulator-tram/

Full analysis: https://app.any.run/tasks/0d19093a-cdba-43fc-998e-fcc88f06e1d9
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: August 23, 2024, 22:29:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
netreactor
miner
cybergate
rat
Indicators:
MD5:

DF9DB4DFEDF755CBF9AE19EA8460C05F

SHA1:

5969BCD740E98E2F461FFB6B23051C51C61CD439

SHA256:

0A440C2798F98E171FC9D410149147920712F993C26C8F45EC123478590F1AD1

SSDEEP:

3:N8l0XMUhGGCEIzK1PUir/4Mz:22XMPVQt/4Mz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • UnifiedStub-installer.exe (PID: 7096)
      • rsEngineSvc.exe (PID: 7672)
    • Changes the autorun value in the registry

      • rundll32.exe (PID: 4276)
    • CYBERGATE has been detected (YARA)

      • rsEngineSvc.exe (PID: 7672)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 3672)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 1688)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 1072)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • prod0.exe (PID: 4292)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 3112)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • UnifiedStub-installer.exe (PID: 7096)
      • rsWSC.exe (PID: 6488)
      • rsEngineSvc.exe (PID: 6496)
      • rsEDRSvc.exe (PID: 7120)
      • rsEngineSvc.exe (PID: 7672)
    • Reads the date of Windows installation

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 3672)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 1688)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 1072)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • prod0.exe (PID: 4292)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 3112)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • rsEDRSvc.exe (PID: 7056)
      • rsEngineSvc.exe (PID: 7672)
    • Executable content was dropped or overwritten

      • City Transport Simulator Tram_hOR8M-1.exe (PID: 3112)
      • City Transport Simulator Tram_hOR8M-1.exe (PID: 6220)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 1060)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 6304)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4164)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4876)
      • prod0.exe (PID: 4292)
      • xpyf2ku3.exe (PID: 1048)
      • UnifiedStub-installer.exe (PID: 7096)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2616)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2816)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
    • Drops the executable file immediately after the start

      • City Transport Simulator Tram_hOR8M-1.exe (PID: 3112)
      • City Transport Simulator Tram_hOR8M-1.exe (PID: 6220)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 1060)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 6304)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4164)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4876)
      • prod0.exe (PID: 4292)
      • xpyf2ku3.exe (PID: 1048)
      • UnifiedStub-installer.exe (PID: 7096)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2816)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2616)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
    • Reads the Windows owner or organization settings

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
    • Potential Corporate Privacy Violation

      • qbittorrent.exe (PID: 1184)
    • Connects to unusual port

      • qbittorrent.exe (PID: 1184)
    • Process drops legitimate windows executable

      • xpyf2ku3.exe (PID: 1048)
      • UnifiedStub-installer.exe (PID: 7096)
      • icarus.exe (PID: 7860)
    • Searches for installed software

      • UnifiedStub-installer.exe (PID: 7096)
    • Creates a software uninstall entry

      • UnifiedStub-installer.exe (PID: 7096)
    • Executes as Windows Service

      • rsSyncSvc.exe (PID: 8140)
      • rsWSC.exe (PID: 6332)
      • rsClientSvc.exe (PID: 7812)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7056)
      • WmiApSrv.exe (PID: 7764)
    • Starts itself from another location

      • icarus.exe (PID: 4092)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 7860)
      • UnifiedStub-installer.exe (PID: 7096)
    • The process drops C-runtime libraries

      • UnifiedStub-installer.exe (PID: 7096)
      • icarus.exe (PID: 7860)
    • Drops 7-zip archiver for unpacking

      • UnifiedStub-installer.exe (PID: 7096)
    • Drops a system driver (possible attempt to evade defenses)

      • UnifiedStub-installer.exe (PID: 7096)
    • Adds/modifies Windows certificates

      • UnifiedStub-installer.exe (PID: 7096)
      • rsWSC.exe (PID: 6488)
    • Checks Windows Trust Settings

      • UnifiedStub-installer.exe (PID: 7096)
      • rsWSC.exe (PID: 6488)
      • rsWSC.exe (PID: 6332)
      • rsEngineSvc.exe (PID: 6496)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7120)
      • rsEDRSvc.exe (PID: 7056)
    • Creates files in the driver directory

      • UnifiedStub-installer.exe (PID: 7096)
    • Creates or modifies Windows services

      • UnifiedStub-installer.exe (PID: 7096)
      • rundll32.exe (PID: 4276)
    • Uses RUNDLL32.EXE to load library

      • UnifiedStub-installer.exe (PID: 7096)
    • Uses WEVTUTIL.EXE to install publishers and event logs from the manifest

      • UnifiedStub-installer.exe (PID: 7096)
    • The process verifies whether the antivirus software is installed

      • icarus.exe (PID: 7860)
      • rsEngineSvc.exe (PID: 7672)
    • Reads the BIOS version

      • rsEDRSvc.exe (PID: 7056)
      • rsEngineSvc.exe (PID: 7672)
    • Dropped object may contain URLs of mainers pools

      • rsEngineSvc.exe (PID: 7672)
    • Application launched itself

      • rsAppUI.exe (PID: 6772)
    • The process checks if it is being run in the virtual environment

      • rsEngineSvc.exe (PID: 7672)
    • Process checks is Powershell's Script Block Logging on

      • rsEDRSvc.exe (PID: 7056)
    • There is functionality for taking screenshot (YARA)

      • rsHelper.exe (PID: 7144)
  • INFO

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 6584)
      • chrome.exe (PID: 7292)
    • Reads the computer name

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 3672)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • qbittorrent.exe (PID: 1184)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 1688)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 1072)
      • prod0.exe (PID: 4292)
      • UnifiedStub-installer.exe (PID: 7096)
      • rsSyncSvc.exe (PID: 7860)
      • rsSyncSvc.exe (PID: 8140)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 3112)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
      • icarus.exe (PID: 8148)
      • rsWSC.exe (PID: 6488)
      • rsClientSvc.exe (PID: 5088)
      • rsWSC.exe (PID: 6332)
      • rsClientSvc.exe (PID: 7812)
      • rsEngineSvc.exe (PID: 6496)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7120)
      • rsHelper.exe (PID: 7144)
      • rsEDRSvc.exe (PID: 7056)
      • rsAppUI.exe (PID: 6772)
      • rsAppUI.exe (PID: 4920)
      • rsAppUI.exe (PID: 7464)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 6584)
    • Checks supported languages

      • City Transport Simulator Tram_hOR8M-1.exe (PID: 3112)
      • City Transport Simulator Tram_hOR8M-1.exe (PID: 6220)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 3672)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • qbittorrent.exe (PID: 1184)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 1060)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 1688)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 6304)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • qbittorrent.exe (PID: 7540)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4876)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 1072)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4164)
      • prod0.exe (PID: 4292)
      • qbittorrent.exe (PID: 3876)
      • xpyf2ku3.exe (PID: 1048)
      • UnifiedStub-installer.exe (PID: 7096)
      • rsSyncSvc.exe (PID: 7860)
      • rsSyncSvc.exe (PID: 8140)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2816)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 3112)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2616)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • qbittorrent.exe (PID: 3236)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 8148)
      • icarus.exe (PID: 7860)
      • rsWSC.exe (PID: 6488)
      • rsWSC.exe (PID: 6332)
      • rsClientSvc.exe (PID: 5088)
      • rsEngineSvc.exe (PID: 6496)
      • rsClientSvc.exe (PID: 7812)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7120)
      • rsHelper.exe (PID: 7144)
      • rsEDRSvc.exe (PID: 7056)
      • EPP.exe (PID: 6892)
      • rsAppUI.exe (PID: 6772)
      • rsAppUI.exe (PID: 7464)
      • rsAppUI.exe (PID: 4920)
      • rsAppUI.exe (PID: 4364)
      • rsLitmus.A.exe (PID: 1700)
      • rsAppUI.exe (PID: 4344)
    • Process checks computer location settings

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 3672)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 1688)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 1072)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • prod0.exe (PID: 4292)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 3112)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • rsAppUI.exe (PID: 6772)
      • rsAppUI.exe (PID: 4364)
      • rsAppUI.exe (PID: 4344)
    • Create files in a temporary directory

      • City Transport Simulator Tram_hOR8M-1.exe (PID: 3112)
      • City Transport Simulator Tram_hOR8M-1.exe (PID: 6220)
      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 1060)
      • City Transport Simulator Tram_K1NCd-1.exe (PID: 6304)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4876)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • City Transport Simulator Tram_S-yumz1.exe (PID: 4164)
      • prod0.exe (PID: 4292)
      • xpyf2ku3.exe (PID: 1048)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2616)
      • City Transport Simulator Tram_b-YV8K1.exe (PID: 2816)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
      • UnifiedStub-installer.exe (PID: 7096)
      • icarus.exe (PID: 8148)
      • rsAppUI.exe (PID: 6772)
    • Application launched itself

      • chrome.exe (PID: 6584)
    • Reads the software policy settings

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • prod0.exe (PID: 4292)
      • UnifiedStub-installer.exe (PID: 7096)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • rsWSC.exe (PID: 6488)
      • rsEngineSvc.exe (PID: 6496)
      • rsEngineSvc.exe (PID: 7672)
      • rsWSC.exe (PID: 6332)
      • rsEDRSvc.exe (PID: 7120)
      • rsEDRSvc.exe (PID: 7056)
    • Reads the machine GUID from the registry

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • qbittorrent.exe (PID: 1184)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • prod0.exe (PID: 4292)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • UnifiedStub-installer.exe (PID: 7096)
      • avg_antivirus_free_setup.exe (PID: 7136)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
      • icarus.exe (PID: 8148)
      • rsWSC.exe (PID: 6488)
      • rsWSC.exe (PID: 6332)
      • rsEngineSvc.exe (PID: 6496)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7120)
      • rsHelper.exe (PID: 7144)
      • rsEDRSvc.exe (PID: 7056)
      • rsAppUI.exe (PID: 6772)
    • Creates files or folders in the user directory

      • qbittorrent.exe (PID: 1184)
      • UnifiedStub-installer.exe (PID: 7096)
      • rsWSC.exe (PID: 6488)
      • rsAppUI.exe (PID: 6772)
      • rsEngineSvc.exe (PID: 7672)
      • rsAppUI.exe (PID: 7464)
    • Checks proxy server information

      • City Transport Simulator Tram_hOR8M-1.tmp (PID: 7272)
      • City Transport Simulator Tram_K1NCd-1.tmp (PID: 6148)
      • prod0.exe (PID: 4292)
      • City Transport Simulator Tram_S-yumz1.tmp (PID: 3424)
      • UnifiedStub-installer.exe (PID: 7096)
      • City Transport Simulator Tram_b-YV8K1.tmp (PID: 1156)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • rsWSC.exe (PID: 6488)
      • rsAppUI.exe (PID: 6772)
    • Disables trace logs

      • prod0.exe (PID: 4292)
      • UnifiedStub-installer.exe (PID: 7096)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7056)
    • Reads Environment values

      • prod0.exe (PID: 4292)
      • UnifiedStub-installer.exe (PID: 7096)
      • icarus.exe (PID: 7860)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7056)
      • rsAppUI.exe (PID: 6772)
    • Creates files in the program directory

      • UnifiedStub-installer.exe (PID: 7096)
      • avg_antivirus_free_online_setup.exe (PID: 5388)
      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
      • rsWSC.exe (PID: 6488)
      • rsEngineSvc.exe (PID: 7672)
      • rsEngineSvc.exe (PID: 6496)
      • rsEDRSvc.exe (PID: 7120)
      • rsEDRSvc.exe (PID: 7056)
    • .NET Reactor protector has been detected

      • UnifiedStub-installer.exe (PID: 7096)
      • rsWSC.exe (PID: 6332)
      • rsHelper.exe (PID: 7144)
      • rsEngineSvc.exe (PID: 7672)
      • rsEDRSvc.exe (PID: 7056)
    • Reads CPU info

      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 8148)
      • icarus.exe (PID: 7860)
      • rsEDRSvc.exe (PID: 7056)
      • rsEngineSvc.exe (PID: 7672)
    • Dropped object may contain TOR URL's

      • icarus.exe (PID: 4092)
      • icarus.exe (PID: 7860)
    • Manual execution by a user

      • Taskmgr.exe (PID: 7824)
      • Taskmgr.exe (PID: 7424)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 7424)
      • runonce.exe (PID: 2680)
    • Reads the time zone

      • runonce.exe (PID: 2680)
      • rsEDRSvc.exe (PID: 7056)
      • rsEngineSvc.exe (PID: 7672)
    • Reads product name

      • rsEDRSvc.exe (PID: 7056)
      • rsEngineSvc.exe (PID: 7672)
      • rsAppUI.exe (PID: 6772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
262
Monitored processes
112
Malicious processes
15
Suspicious processes
11

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs city transport simulator tram_hor8m-1.exe city transport simulator tram_hor8m-1.tmp no specs city transport simulator tram_hor8m-1.exe city transport simulator tram_hor8m-1.tmp chrome.exe no specs netsh.exe no specs conhost.exe no specs qbittorrent.exe chrome.exe no specs city transport simulator tram_k1ncd-1.exe city transport simulator tram_k1ncd-1.tmp no specs city transport simulator tram_k1ncd-1.exe city transport simulator tram_k1ncd-1.tmp chrome.exe no specs chrome.exe no specs netsh.exe no specs conhost.exe no specs qbittorrent.exe no specs chrome.exe no specs chrome.exe no specs city transport simulator tram_s-yumz1.exe city transport simulator tram_s-yumz1.tmp no specs city transport simulator tram_s-yumz1.exe city transport simulator tram_s-yumz1.tmp chrome.exe no specs prod0.exe netsh.exe no specs conhost.exe no specs xpyf2ku3.exe qbittorrent.exe no specs THREAT unifiedstub-installer.exe rssyncsvc.exe no specs conhost.exe no specs rssyncsvc.exe no specs chrome.exe city transport simulator tram_b-yv8k1.exe city transport simulator tram_b-yv8k1.tmp no specs city transport simulator tram_b-yv8k1.exe city transport simulator tram_b-yv8k1.tmp avg_antivirus_free_setup.exe netsh.exe no specs conhost.exe no specs qbittorrent.exe no specs avg_antivirus_free_online_setup.exe icarus.exe icarus.exe no specs icarus.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs taskmgr.exe no specs taskmgr.exe rundll32.exe runonce.exe no specs grpconv.exe no specs wevtutil.exe no specs conhost.exe no specs fltmc.exe no specs conhost.exe no specs wevtutil.exe no specs conhost.exe no specs rswsc.exe THREAT rswsc.exe no specs rsclientsvc.exe no specs conhost.exe no specs rsclientsvc.exe no specs rsenginesvc.exe no specs #CYBERGATE rsenginesvc.exe rsedrsvc.exe no specs THREAT rshelper.exe no specs THREAT rsedrsvc.exe epp.exe no specs rsappui.exe no specs wmiapsrv.exe no specs rsappui.exe no specs rsappui.exe no specs rsappui.exe no specs rslitmus.a.exe no specs conhost.exe no specs rsappui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4220 --field-trial-handle=1884,i,12440708698539543052,10181389266447784216,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
740"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4188 --field-trial-handle=1884,i,12440708698539543052,10181389266447784216,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1048"C:\Users\admin\AppData\Local\Temp\xpyf2ku3.exe" /silentC:\Users\admin\AppData\Local\Temp\xpyf2ku3.exe
prod0.exe
User:
admin
Company:
ReasonLabs
Integrity Level:
HIGH
Description:
ReasonLabs-setup-wizard.exe
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\xpyf2ku3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
1060"C:\Users\admin\Downloads\City Transport Simulator Tram_K1NCd-1.exe" C:\Users\admin\Downloads\City Transport Simulator Tram_K1NCd-1.exe
chrome.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Axium Audit, OOO Download Manager
Exit code:
0
Version:
3.334.90
Modules
Images
c:\users\admin\downloads\city transport simulator tram_k1ncd-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1060"C:\WINDOWS\system32\wevtutil.exe" im C:\Program Files\ReasonLabs\EPP\x64\elam\evntdrv.xmlC:\Windows\System32\wevtutil.exeUnifiedStub-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
87
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
1072"C:\Users\admin\AppData\Local\Temp\is-VSH5J.tmp\City Transport Simulator Tram_S-yumz1.tmp" /SL5="$D02AA,13603942,780800,C:\Users\admin\Downloads\City Transport Simulator Tram_S-yumz1.exe" C:\Users\admin\AppData\Local\Temp\is-VSH5J.tmp\City Transport Simulator Tram_S-yumz1.tmpCity Transport Simulator Tram_S-yumz1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vsh5j.tmp\city transport simulator tram_s-yumz1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
1156"C:\Users\admin\AppData\Local\Temp\is-K9AMS.tmp\City Transport Simulator Tram_b-YV8K1.tmp" /SL5="$1003A8,13603942,780800,C:\Users\admin\Downloads\City Transport Simulator Tram_b-YV8K1.exe" /SPAWNWND=$A0394 /NOTIFYWND=$6039A C:\Users\admin\AppData\Local\Temp\is-K9AMS.tmp\City Transport Simulator Tram_b-YV8K1.tmp
City Transport Simulator Tram_b-YV8K1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k9ams.tmp\city transport simulator tram_b-yv8k1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
1184"C:\Users\admin\AppData\Local\Temp\is-D47J9.tmp\qbittorrent.exe" magnet:?xt=urn:btih:BFF18AF5608F9196CF05BF0C1F0B54A18C3F0A77C:\Users\admin\AppData\Local\Temp\is-D47J9.tmp\qbittorrent.exe
City Transport Simulator Tram_hOR8M-1.tmp
User:
admin
Company:
The qBittorrent Project
Integrity Level:
HIGH
Description:
qBittorrent - A Bittorrent Client
Version:
v4.4.2
Modules
Images
c:\users\admin\appdata\local\temp\is-d47j9.tmp\qbittorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1288"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6464 --field-trial-handle=1884,i,12440708698539543052,10181389266447784216,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1292"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=6068 --field-trial-handle=1884,i,12440708698539543052,10181389266447784216,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
97 960
Read events
97 500
Write events
372
Delete events
88

Modification events

(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(6584) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(6584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
850
Suspicious files
616
Text files
226
Unknown types
125

Dropped files

PID
Process
Filename
Type
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF11eaf9.TMP
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF11eaf9.TMP
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Versiontext
MD5:FCE53E052E5CF7C20819320F374DEA88
SHA256:CD95DE277E746E92CC2C53D9FC92A8F6F0C3EDFB7F1AD9A4E9259F927065BC89
6584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
97
TCP/UDP connections
597
DNS requests
156
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4820
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4820
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4820
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6388
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7928
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6224
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5y4zivadphwjrwvp6ost3etk5a_1054/efniojlnjndmcbiieegkicadnoecjjef_1054_all_acwv5cki5hrz6m7phk5bmunngctq.crx3
unknown
whitelisted
6584
chrome.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
6224
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5y4zivadphwjrwvp6ost3etk5a_1054/efniojlnjndmcbiieegkicadnoecjjef_1054_all_acwv5cki5hrz6m7phk5bmunngctq.crx3
unknown
whitelisted
6584
chrome.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEDsZVc%2FqosnDkikuACh9Smw%3D
unknown
whitelisted
6584
chrome.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2088
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5500
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6840
chrome.exe
104.26.14.250:443
gamefabrique.com
CLOUDFLARENET
US
unknown
6584
chrome.exe
239.255.255.250:1900
whitelisted
6840
chrome.exe
173.194.69.84:443
accounts.google.com
GOOGLE
US
unknown
6840
chrome.exe
151.101.65.229:443
cdn.jsdelivr.net
FASTLY
US
unknown
6840
chrome.exe
142.250.186.104:443
www.googletagmanager.com
GOOGLE
US
unknown
6840
chrome.exe
142.250.185.106:443
ajax.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.206
whitelisted
gamefabrique.com
  • 104.26.14.250
  • 104.26.15.250
  • 172.67.68.207
whitelisted
accounts.google.com
  • 173.194.69.84
whitelisted
www.googletagmanager.com
  • 142.250.186.104
whitelisted
ajax.googleapis.com
  • 142.250.185.106
whitelisted
cdn.jsdelivr.net
  • 151.101.65.229
  • 151.101.193.229
  • 151.101.129.229
  • 151.101.1.229
whitelisted
d1pdf4c3hchi80.cloudfront.net
  • 99.86.1.105
  • 99.86.1.106
  • 99.86.1.120
  • 99.86.1.202
whitelisted
www.google-analytics.com
  • 172.217.16.206
  • 216.58.206.46
whitelisted
pogothere.xyz
  • 188.114.97.3
  • 188.114.96.3
unknown

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
Potentially Bad Traffic
ET HUNTING Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Potentially Bad Traffic
ET HUNTING Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT announce_peers request
Process
Message
qbittorrent.exe
QObject::startTimer: Timers cannot have negative intervals
rsEngineSvc.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\ReasonLabs\EPP\x64\SQLite.Interop.dll"...
rsEDRSvc.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\ReasonLabs\EDR\x64\SQLite.Interop.dll"...