File name:

nvidiaInspector.exe

Full analysis: https://app.any.run/tasks/d465020e-3ea2-4540-8040-becf25c4f179
Verdict: Malicious activity
Analysis date: May 04, 2020, 13:03:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

AB9818DCB8DB032A099F715B6E890EAE

SHA1:

698821629BBBDB11AC1DC2B8928A47864D341347

SHA256:

1362769BC91496AC96AD748F57581F1D8237C74D8E2D34015FD7FFFF868951EC

SSDEEP:

6144:UG3vfnqe9eAbrsxob7VurbzD96CyVUwwwwwwzwwwwzwwwwwwwwcwwwwwwwwwwwwU:UG3vL9eWR74Rim0JfqgfkAu0S

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 2536)
  • SUSPICIOUS

    • Creates files in the user directory

      • nvidiaInspector.exe (PID: 2632)
      • Skype.exe (PID: 1832)
      • Skype.exe (PID: 3544)
      • Skype.exe (PID: 1536)
    • Modifies the open verb of a shell class

      • Skype.exe (PID: 3544)
    • Changes IE settings (feature browser emulation)

      • AcroRd32.exe (PID: 3424)
    • Reads internet explorer settings

      • AcroRd32.exe (PID: 3424)
    • Reads CPU info

      • Skype.exe (PID: 3544)
    • Uses REG.EXE to modify Windows registry

      • Skype.exe (PID: 3544)
    • Application launched itself

      • Skype.exe (PID: 3544)
      • Skype.exe (PID: 1832)
      • Skype.exe (PID: 1536)
  • INFO

    • Reads settings of System Certificates

      • Skype.exe (PID: 3544)
    • Manual execution by user

      • AcroRd32.exe (PID: 3424)
      • Skype.exe (PID: 3544)
    • Reads the hosts file

      • RdrCEF.exe (PID: 3720)
      • Skype.exe (PID: 3544)
    • Reads Internet Cache Settings

      • AcroRd32.exe (PID: 3232)
      • AcroRd32.exe (PID: 3424)
    • Application launched itself

      • RdrCEF.exe (PID: 3720)
    • Creates files in the user directory

      • AcroRd32.exe (PID: 3424)
    • Dropped object may contain Bitcoin addresses

      • Skype.exe (PID: 3544)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (42.5)
.exe | InstallShield setup (25)
.exe | Win64 Executable (generic) (16)
.scr | Windows screen saver (7.6)
.dll | Win32 Dynamic Link Library (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:10:06 23:13:03+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 622592
InitializedDataSize: 640000
UninitializedDataSize: -
EntryPoint: 0x99e3a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.9.7.3
ProductVersionNumber: 1.9.7.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Orbmu2k
FileDescription: NVIDIA Inspector
FileVersion: 1.9.7.3
InternalName: nvidiaInspector.exe
LegalCopyright: Copyright © 2014 by Orbmu2k
OriginalFileName: nvidiaInspector.exe
ProductName: NVIDIA Inspector
ProductVersion: 1.9.7.3
AssemblyVersion: 1.9.7.3

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 06-Oct-2014 21:13:03
Debug artifacts:
  • c:\Users\Orbmu2k\Documents\Visual Studio 2010\Projects\GPUStatusReader\nvapiDirect\obj\Release\nvidiaInspector.pdb
CompanyName: Orbmu2k
FileDescription: NVIDIA Inspector
FileVersion: 1.9.7.3
InternalName: nvidiaInspector.exe
LegalCopyright: Copyright © 2014 by Orbmu2k
OriginalFilename: nvidiaInspector.exe
ProductName: NVIDIA Inspector
ProductVersion: 1.9.7.3
Assembly Version: 1.9.7.3

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 06-Oct-2014 21:13:03
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x00097E40
0x00098000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.24451
.reloc
0x0009A000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.10191
.rsrc
0x0009C000
0x00004234
0x00004400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.63031

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.04465
656
UNKNOWN
UNKNOWN
RT_MANIFEST
2
4.18303
1128
UNKNOWN
UNKNOWN
RT_ICON
3
3.61466
4264
UNKNOWN
UNKNOWN
RT_ICON
4
3.22706
9640
UNKNOWN
UNKNOWN
RT_ICON
32512
2.49203
48
UNKNOWN
UNKNOWN
RT_GROUP_ICON

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3720.0.316440497\2087281907" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.23.20053.211670
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1092C:\Windows\system32\reg.exe QUERY HKCU\Software\Microsoft\Skype /v RestartForUpdateC:\Windows\system32\reg.exeSkype.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1536"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=E91E35A533B8E6E99A8011351954FDD0 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=E91E35A533B8E6E99A8011351954FDD0 --renderer-client-id=3 --mojo-platform-channel-handle=1572 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
Modules
Images
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
1832"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=64C5E73145CF6877328953F2CBE39418 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=1 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=64C5E73145CF6877328953F2CBE39418 --renderer-client-id=4 --mojo-platform-channel-handle=2632 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
Modules
Images
c:\systemroot\system32\ntdll.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
2536C:\Windows\system32\reg.exe ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Skype for Desktop" /t REG_SZ /d "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" /fC:\Windows\system32\reg.exe
Skype.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2552"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Skype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
2
Version:
8.29.0.50
Modules
Images
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
2632"C:\Users\admin\AppData\Local\Temp\nvidiaInspector.exe" C:\Users\admin\AppData\Local\Temp\nvidiaInspector.exe
explorer.exe
User:
admin
Company:
Orbmu2k
Integrity Level:
HIGH
Description:
NVIDIA Inspector
Exit code:
0
Version:
1.9.7.3
Modules
Images
c:\users\admin\appdata\local\temp\nvidiainspector.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3224"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Skype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
Modules
Images
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
3232"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=rendererC:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3424"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
explorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
Total events
1 026
Read events
835
Write events
190
Delete events
1

Modification events

(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2632) nvidiaInspector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nvidiaInspector_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
0
Suspicious files
27
Text files
46
Unknown types
17

Dropped files

PID
Process
Filename
Type
2632nvidiaInspector.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\UWT88ZPW4YPVK35CED1F.temp
MD5:
SHA256:
3232AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
MD5:
SHA256:
3424AcroRd32.exeC:\Users\admin\AppData\Local\Temp\Cab4BD1.tmp
MD5:
SHA256:
3424AcroRd32.exeC:\Users\admin\AppData\Local\Temp\Tar4BD2.tmp
MD5:
SHA256:
2632nvidiaInspector.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\67aa4630353323e9.customDestinations-msbinary
MD5:8726A32FC3288A0F17EB915217917246
SHA256:923823AEF8E74B9128A6227DDE7108699F6333AA3EE74A6F4CC2EF86914B42DF
3232AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessagessqlite
MD5:942DB0172D96E165921026BDEB334BF5
SHA256:665E082A43651E6F94833B60AA4A9D06E04643133CD351B92153587AD7A773F2
3424AcroRd32.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:967327433F1497F60EABA266395E7AF4
SHA256:1FB0FC5B53ABFBAE18C6911C45F42E74FF81C6440B8A6C8DAFBF860AB6CDB81B
3424AcroRd32.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1E11E75149C17A93653DA7DC0B8CF53F_749B9A9B118BA4E1D6722941AEB1C623binary
MD5:483A0DF4570384805DD7DF8E5FEBFFC1
SHA256:2FA2F6AC6FED192D427014FA5758AB4F33E90B6C56778CB2296B3C327BCAF812
3424AcroRd32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\en[1].jstext
MD5:848E99DD978FF845CC70752B51D3E7D3
SHA256:7F7C4C26E58106DC8B6DF50CA899CECDC303182E8B1459E3518069BE6301A36D
3424AcroRd32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\snthemes[1].jstext
MD5:21133064D3867BCFA938F38BA9636B59
SHA256:DABA9B47E72FB80C6509D96E0E2E6FFBD74A06F61DB60E46B023118995EC1783
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
27
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2632
nvidiaInspector.exe
GET
200
93.186.200.78:80
http://download.orbmu2k.de/files/nvidiaInspector.ver
DE
text
7 b
unknown
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAlQfMXhN5Dl295xp4R4RBM%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAtb9ltrp%2FvQiykNkEU33uA%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
192.124.249.36:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
US
der
1.69 Kb
whitelisted
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAza5nSVYZrPeIlAtSf0Rcs%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
192.124.249.36:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
US
der
1.66 Kb
whitelisted
3424
AcroRd32.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAFT5zSjKfJcBOJBfeXVZHY%3D
US
der
471 b
whitelisted
3424
AcroRd32.exe
GET
200
192.124.249.36:80
http://ocsp.godaddy.com//MEgwRjBEMEIwQDAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CB206dZYDOTM%3D
US
der
1.73 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2632
nvidiaInspector.exe
93.186.200.78:80
download.orbmu2k.de
myLoc managed IT AG
DE
unknown
3424
AcroRd32.exe
52.209.221.40:443
ims-na1.adobelogin.com
Amazon.com, Inc.
IE
unknown
3424
AcroRd32.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3424
AcroRd32.exe
52.48.164.75:443
adobeid-na1.services.adobe.com
Amazon.com, Inc.
IE
unknown
3424
AcroRd32.exe
13.224.187.69:443
static.adobelogin.com
US
unknown
3424
AcroRd32.exe
52.50.184.22:443
dpm.demdex.net
Amazon.com, Inc.
IE
unknown
3424
AcroRd32.exe
52.0.132.68:443
l.betrad.com
Amazon.com, Inc.
US
unknown
3424
AcroRd32.exe
35.181.91.36:443
sstats.adobe.com
CA
suspicious
3424
AcroRd32.exe
72.247.225.88:443
assets.adobedtm.com
Akamai Technologies, Inc.
US
whitelisted
3424
AcroRd32.exe
2.21.36.142:443
www.adobe.com
GTT Communications Inc.
FR
malicious

DNS requests

Domain
IP
Reputation
download.orbmu2k.de
  • 93.186.200.78
unknown
ims-na1.adobelogin.com
  • 52.209.221.40
  • 52.208.125.115
  • 3.248.173.199
  • 18.203.6.206
  • 18.202.114.136
  • 52.213.183.135
  • 52.213.87.190
  • 52.214.26.197
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
adobeid-na1.services.adobe.com
  • 52.48.164.75
  • 52.208.231.187
  • 108.128.106.210
  • 52.19.22.175
  • 52.208.22.194
  • 34.240.34.174
  • 34.253.101.66
  • 52.49.253.118
whitelisted
www.adobe.com
  • 2.21.36.142
whitelisted
static.adobelogin.com
  • 13.224.187.69
whitelisted
wwwimages2.adobe.com
  • 72.247.224.120
whitelisted
c.evidon.com
  • 2.20.168.134
whitelisted
assets.adobedtm.com
  • 72.247.225.88
whitelisted
use.typekit.net
  • 2.16.186.49
  • 2.16.186.59
whitelisted

Threats

No threats detected
Process
Message
Skype.exe
[3224:2720:0504/140445.672:VERBOSE1:crash_service.cc(304)] checkpoint is C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\crash_checkpoint.txt server is https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload maximum 128 reports/day reporter is electron-crash-service
Skype.exe
[3224:2720:0504/140445.672:VERBOSE1:crash_service.cc(304)] checkpoint is C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\crash_checkpoint.txt server is https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload maximum 128 reports/day reporter is electron-crash-service
Skype.exe
[3224:2720:0504/140445.672:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[3224:2720:0504/140445.672:VERBOSE1:crash_service.cc(145)] window handle is 00030300
Skype.exe
[3224:2720:0504/140445.672:VERBOSE1:crash_service_main.cc(94)] Ready to process crash requests
Skype.exe
[3224:2572:0504/140445.672:VERBOSE1:crash_service.cc(333)] client start. pid = 3544
Skype.exe
[3224:2572:0504/140447.825:VERBOSE1:crash_service.cc(333)] client start. pid = 1536
Skype.exe
[3776:3204:0504/140448.041:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[3776:3204:0504/140448.042:VERBOSE1:crash_service.cc(300)] pipe name is \\.\pipe\skype-preview Crash Service dumps at C:\Users\admin\AppData\Local\Temp\skype-preview Crashes
Skype.exe
[3776:3204:0504/140448.042:ERROR:crash_service.cc(311)] could not start dumper