File name:

SIQuester.Setup.exe

Full analysis: https://app.any.run/tasks/e3b37a30-b382-4329-a6bb-3ef7f37ecf50
Verdict: Malicious activity
Analysis date: October 23, 2023, 16:58:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

28EFCA7088805F0E73E0F5840A3B45C8

SHA1:

431AF761CF92A6BA269F60CB5A55A486962C9D3D

SHA256:

10F6D8E221B0825866F83924E936D484999B96D881038CBB99211D17F1D52F84

SSDEEP:

12288:mzNB0JfiwSdYSui8zZH94I3H1v1KR22v9cLtoov:6NsfiTdYSuVzZH9tH1v1KvcLOov

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2980)
      • SIQuester.Setup.exe (PID: 3632)
      • SIQuester.Setup.exe (PID: 2940)
      • msiexec.exe (PID: 2628)
      • SIQuester.Setup.exe (PID: 2392)
      • SIQuester.Setup.exe (PID: 2224)
    • Loads dropped or rewritten executable

      • SIQuester.Setup.exe (PID: 3612)
      • msiexec.exe (PID: 3768)
      • SIQuester.exe (PID: 3272)
      • msiexec.exe (PID: 3408)
      • SIQuester.Setup.exe (PID: 2940)
      • SIQuester.Setup.exe (PID: 2392)
  • SUSPICIOUS

    • Starts itself from another location

      • SIQuester.Setup.exe (PID: 2980)
      • SIQuester.Setup.exe (PID: 2224)
      • SIQuester.Setup.exe (PID: 3632)
    • Searches for installed software

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2940)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads the Internet Settings

      • SIQuester.Setup.exe (PID: 3612)
      • msiexec.exe (PID: 3768)
      • SIQuester.exe (PID: 3272)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads security settings of Internet Explorer

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads settings of System Certificates

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.exe (PID: 3272)
      • SIQuester.Setup.exe (PID: 2392)
    • Checks Windows Trust Settings

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2628)
    • Creates a software uninstall entry

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2940)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2628)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2628)
    • Changes default file association

      • msiexec.exe (PID: 2628)
  • INFO

    • Checks supported languages

      • SIQuester.Setup.exe (PID: 2980)
      • SIQuester.Setup.exe (PID: 3612)
      • wmpnscfg.exe (PID: 388)
      • msiexec.exe (PID: 2628)
      • msiexec.exe (PID: 3768)
      • SIQuester.exe (PID: 3272)
      • ngen.exe (PID: 2996)
      • ngen.exe (PID: 3664)
      • SIQuester.Setup.exe (PID: 3632)
      • SIQuester.Setup.exe (PID: 2940)
      • msiexec.exe (PID: 3408)
      • ngen.exe (PID: 280)
      • ngen.exe (PID: 2544)
      • SIQuester.Setup.exe (PID: 2224)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads the computer name

      • SIQuester.Setup.exe (PID: 3612)
      • wmpnscfg.exe (PID: 388)
      • msiexec.exe (PID: 2628)
      • msiexec.exe (PID: 3768)
      • ngen.exe (PID: 2996)
      • ngen.exe (PID: 3664)
      • SIQuester.exe (PID: 3272)
      • msiexec.exe (PID: 3408)
      • SIQuester.Setup.exe (PID: 2940)
      • ngen.exe (PID: 280)
      • ngen.exe (PID: 2544)
      • SIQuester.Setup.exe (PID: 2392)
    • Create files in a temporary directory

      • SIQuester.Setup.exe (PID: 2980)
      • SIQuester.Setup.exe (PID: 3612)
      • msiexec.exe (PID: 2628)
      • SIQuester.exe (PID: 3272)
      • SIQuester.Setup.exe (PID: 3632)
      • SIQuester.Setup.exe (PID: 2224)
      • SIQuester.Setup.exe (PID: 2940)
      • SIQuester.Setup.exe (PID: 2392)
    • Checks proxy server information

      • SIQuester.Setup.exe (PID: 3612)
      • SIQuester.Setup.exe (PID: 2392)
    • Creates files or folders in the user directory

      • SIQuester.Setup.exe (PID: 3612)
      • msiexec.exe (PID: 2628)
      • SIQuester.exe (PID: 3272)
      • SIQuester.Setup.exe (PID: 2392)
    • Reads the machine GUID from the registry

      • SIQuester.Setup.exe (PID: 3612)
      • msiexec.exe (PID: 2628)
      • msiexec.exe (PID: 3768)
      • wmpnscfg.exe (PID: 388)
      • SIQuester.exe (PID: 3272)
      • SIQuester.Setup.exe (PID: 2940)
      • msiexec.exe (PID: 3408)
      • SIQuester.Setup.exe (PID: 2392)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 388)
      • explorer.exe (PID: 1240)
      • SIQuester.Setup.exe (PID: 3632)
      • SIQuester.Setup.exe (PID: 2224)
    • Application launched itself

      • msiexec.exe (PID: 2628)
    • Creates files in the program directory

      • SIQuester.exe (PID: 3272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

ProductVersion: 5.10.6
ProductName: SIQuester
OriginalFileName: SIQuester.Setup.exe
LegalCopyright: Copyright (c) Khil-soft. All rights reserved.
InternalName: setup
FileVersion: 5.10.6
FileDescription: SIQuester
CompanyName: Khil-soft
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 5.10.6.0
FileVersionNumber: 5.10.6.0
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x2df71
UninitializedDataSize: -
InitializedDataSize: 177664
CodeSize: 299008
LinkerVersion: 14.16
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
TimeStamp: 2019:09:17 05:33:38+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
16
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start siquester.setup.exe no specs siquester.setup.exe wmpnscfg.exe no specs msiexec.exe no specs msiexec.exe no specs ngen.exe no specs ngen.exe no specs siquester.exe explorer.exe no specs siquester.setup.exe no specs siquester.setup.exe no specs msiexec.exe no specs ngen.exe no specs ngen.exe no specs siquester.setup.exe no specs siquester.setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
280C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe uninstall "C:\Users\admin\AppData\Local\Khil-soft\SIQuester\SIQuester.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
388"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1240"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
2224"C:\Users\admin\Downloads\SIQuester.Setup.exe" C:\Users\admin\Downloads\SIQuester.Setup.exeexplorer.exe
User:
admin
Company:
Khil-soft
Integrity Level:
MEDIUM
Description:
SIQuester
Exit code:
1602
Version:
5.10.6
Modules
Images
c:\users\admin\downloads\siquester.setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2392"C:\Users\admin\AppData\Local\Temp\{5F9879A5-CFCE-4A65-B792-01C6EF4465DA}\.cr\SIQuester.Setup.exe" -burn.clean.room="C:\Users\admin\Downloads\SIQuester.Setup.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{5F9879A5-CFCE-4A65-B792-01C6EF4465DA}\.cr\SIQuester.Setup.exe
SIQuester.Setup.exe
User:
admin
Company:
Khil-soft
Integrity Level:
MEDIUM
Description:
SIQuester
Exit code:
1602
Version:
5.10.6
Modules
Images
c:\users\admin\appdata\local\temp\{5f9879a5-cfce-4a65-b792-01c6ef4465da}\.cr\siquester.setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
2544C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe update /queueC:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
2628C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
2940"C:\Users\admin\AppData\Local\Temp\{3448524D-D22F-43B9-90A8-3C5F505997BD}\.cr\SIQuester.Setup.exe" -burn.clean.room="C:\Users\admin\Downloads\SIQuester.Setup.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{3448524D-D22F-43B9-90A8-3C5F505997BD}\.cr\SIQuester.Setup.exeSIQuester.Setup.exe
User:
admin
Company:
Khil-soft
Integrity Level:
MEDIUM
Description:
SIQuester
Exit code:
0
Version:
5.10.6
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\{3448524d-d22f-43b9-90a8-3c5f505997bd}\.cr\siquester.setup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2980"C:\Users\admin\Downloads\SIQuester.Setup.exe" C:\Users\admin\Downloads\SIQuester.Setup.exeexplorer.exe
User:
admin
Company:
Khil-soft
Integrity Level:
MEDIUM
Description:
SIQuester
Exit code:
0
Version:
5.10.6
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\users\admin\downloads\siquester.setup.exe
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2996C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "C:\Users\admin\AppData\Local\Khil-soft\SIQuester\SIQuester.exe" /AppBase:"C:\Users\admin\AppData\Local\Khil-soft\SIQuester\\"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
Total events
31 990
Read events
31 588
Write events
243
Delete events
159

Modification events

(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3612) SIQuester.Setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(388) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{62318C53-1FED-46E2-8EDD-4B83342ECBDE}\{363103F6-21D4-4DEA-81F1-9620AE6C01A3}
Operation:delete keyName:(default)
Value:
Executable files
32
Suspicious files
39
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\SIQuester.Setup.x86
MD5:
SHA256:
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Package Cache\.unverified\SIQuester.Setup.x86
MD5:
SHA256:
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Package Cache\{5FDB2936-E0AB-4AB9-9DCD-F5D941494DA2}v5.10.6\SIQuester.x86.msi
MD5:
SHA256:
2628msiexec.exeC:\Windows\Installer\223fa3.msi
MD5:
SHA256:
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\.ba\thm.xmlxml
MD5:2024CE179FCEA503B404FFE5256D06D9
SHA256:85961B7034EF258D16EEA1631CF0ECF98DB99236114A35BF372072DCD748CE0A
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\.ba\BootstrapperApplicationData.xmlxml
MD5:B4490ADA65EE76886EC799B4D28F034B
SHA256:1DD1D3A183435FC650A6D6B2290DDA597740F933845C05CC02B33E996F8418EA
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\.ba\logo.pngimage
MD5:CDF496756BBC1B886DECFFFE0907122B
SHA256:ECBCA6FD0CA147D207F6D3713B0643456914205F227AA1C103AF468AC5331407
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\.ba\thm.wxlxml
MD5:FA66E0257E3086FB5C1C8D362F30451F
SHA256:5AF9CE462057E7BD678325383143F299AACFA5EA886C1D3D37B4BFE079B7F849
3612SIQuester.Setup.exeC:\Users\admin\AppData\Local\Temp\{67596D6C-4070-45F2-98F6-9A54D67BEC0D}\.ba\wixstdba.dllexecutable
MD5:FE7E0BD53F52E6630473C31299A49FDD
SHA256:2BEA14D70943A42D344E09B7C9DE5562FA7E109946E1C615DD584DA30D06CC80
3612SIQuester.Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\50CD3D75D026C82E2E718570BD6F44D0_D222662A57BAA60D2F5EA0D2CC7B2F1Cbinary
MD5:68633AC4B612795B0D3FA5B3B9AFF111
SHA256:FA023037A426458F6E7AE197E0E34E225C5B01EE3A466AB6969D044AFB08BF52
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
15
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3612
SIQuester.Setup.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
unknown
3612
SIQuester.Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
unknown
der
471 b
unknown
3612
SIQuester.Setup.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b112caba801af15f
unknown
compressed
4.66 Kb
unknown
3272
SIQuester.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?312ac606aaef5861
unknown
compressed
61.6 Kb
unknown
3612
SIQuester.Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrHR6YzPN2BNbByL0VoiTIBBMAOAQUCrwIKReMpTlteg7OM8cus%2B37w3oCEAzQqL7GMs%2FmReygqbCE%2Bxw%3D
unknown
binary
312 b
unknown
3272
SIQuester.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7b73bfac20a48690
unknown
compressed
61.6 Kb
unknown
3612
SIQuester.Setup.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
unknown
binary
779 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3612
SIQuester.Setup.exe
140.82.121.3:443
github.com
GITHUB
US
unknown
3612
SIQuester.Setup.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3612
SIQuester.Setup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3612
SIQuester.Setup.exe
185.199.108.133:443
objects.githubusercontent.com
FASTLY
US
unknown
3272
SIQuester.exe
149.202.89.80:443
vladimirkhil.com
OVH SAS
FR
unknown
3272
SIQuester.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2392
SIQuester.Setup.exe
140.82.121.3:443
github.com
GITHUB
US
unknown
2392
SIQuester.Setup.exe
185.199.108.133:443
objects.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
github.com
  • 140.82.121.3
shared
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
objects.githubusercontent.com
  • 185.199.108.133
shared
crl3.digicert.com
  • 192.229.221.95
whitelisted
vladimirkhil.com
  • 149.202.89.80
whitelisted

Threats

No threats detected
No debug info