File name:

RedGiant Activation Service Unlocker 2026.0.0.exe

Full analysis: https://app.any.run/tasks/3bf0f2b1-1762-4e12-af7e-37d3dff8752a
Verdict: Malicious activity
Analysis date: February 20, 2026, 17:48:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

6B54BFCAF95BDEF652CC95D07C1F330F

SHA1:

8386FA7F47EAC2C550E8894227319FEC15F0467F

SHA256:

1478C1A39D7457ACED4C3B9E2ADB01B7C27FDEA0FFE4B1FC2C125FD4E6AA80F1

SSDEEP:

98304:3EEkGNf5ILuOvTOjo1yVRx1CbTn9nGxxBWuoUawl0b2a1d7YmIKsEuhx2DKtdYFQ:pSMHl6F4gMdRfR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • VC_redist.x64.exe (PID: 2996)
    • Proxy execution via Explorer

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
    • Starts NET.EXE for service management

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • net.exe (PID: 4728)
      • net.exe (PID: 8224)
      • net.exe (PID: 5536)
      • net.exe (PID: 8060)
      • net.exe (PID: 2900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 1068)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • VC_redist.x64.22.exe (PID: 8860)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • VC_redist.x64.exe (PID: 8544)
      • VC_redist.x64.exe (PID: 7516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7532)
      • deep.exe (PID: 5016)
      • deep.tmp (PID: 3924)
      • perl.exe (PID: 7192)
    • Reads the Windows owner or organization settings

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • msiexec.exe (PID: 5920)
      • deep.tmp (PID: 3924)
    • Mutex name with non-standard characters

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
    • Executing commands from a ".bat" file

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
    • Using the short paths format

      • cmd.exe (PID: 8252)
      • cmd.exe (PID: 1116)
      • VC_redist.x64.22.exe (PID: 8860)
      • VC_RED~1.EXE (PID: 3172)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7532)
    • Starts CMD.EXE for commands execution

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • deep.tmp (PID: 3924)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 8252)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 1116)
    • Using short paths in the command line

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • VC_redist.x64.22.exe (PID: 8860)
    • Starts a Microsoft application from unusual location

      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
    • Searches for installed software

      • VC_RED~1.EXE (PID: 3172)
      • dllhost.exe (PID: 4852)
      • VC_redist.x64.exe (PID: 8544)
      • VC_redist.x64.exe (PID: 7516)
    • Starts itself from another location

      • VC_RED~1.EXE (PID: 3172)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3404)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 5920)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
    • Application launched itself

      • VC_redist.x64.exe (PID: 8272)
      • VC_redist.x64.exe (PID: 8544)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 5260)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 5080)
    • Creates or modifies Windows services

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • deep.tmp (PID: 3924)
    • Uses TIMEOUT.EXE to delay execution

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
    • Uses TASKKILL.EXE to kill process

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • deep.tmp (PID: 3924)
    • The executable file from the user directory is run by the CMD process

      • perl.exe (PID: 1428)
      • perl.exe (PID: 7164)
      • perl.exe (PID: 5484)
      • perl.exe (PID: 7104)
      • perl.exe (PID: 9168)
      • perl.exe (PID: 8308)
      • perl.exe (PID: 1676)
      • perl.exe (PID: 2992)
      • perl.exe (PID: 6856)
      • perl.exe (PID: 8544)
      • perl.exe (PID: 3584)
      • perl.exe (PID: 6068)
      • perl.exe (PID: 6952)
      • perl.exe (PID: 8760)
      • perl.exe (PID: 8148)
      • perl.exe (PID: 6536)
      • perl.exe (PID: 2140)
      • perl.exe (PID: 9184)
      • perl.exe (PID: 8616)
      • perl.exe (PID: 3172)
      • perl.exe (PID: 2844)
      • perl.exe (PID: 7192)
      • perl.exe (PID: 6976)
      • perl.exe (PID: 2368)
      • perl.exe (PID: 9080)
      • perl.exe (PID: 5444)
      • perl.exe (PID: 1984)
      • perl.exe (PID: 4828)
    • Executing commands from ".cmd" file

      • deep.tmp (PID: 3924)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
  • INFO

    • Create files in a temporary directory

      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 1068)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • VC_redist.x64.exe (PID: 8544)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
      • deep.exe (PID: 5016)
      • deep.tmp (PID: 3924)
    • Reads security settings of Internet Explorer

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 8544)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
      • explorer.exe (PID: 5180)
    • Checks supported languages

      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 1068)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • identity_helper.exe (PID: 5460)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • VC_redist.x64.22.exe (PID: 8860)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • msiexec.exe (PID: 5920)
      • VC_redist.x64.exe (PID: 8272)
      • VC_redist.x64.exe (PID: 8544)
      • VC_redist.x64.exe (PID: 7516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7532)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
      • Maxon.exe (PID: 8648)
      • deep.exe (PID: 5016)
      • deep.tmp (PID: 3924)
      • perl.exe (PID: 1428)
      • perl.exe (PID: 7104)
      • perl.exe (PID: 7164)
      • perl.exe (PID: 5484)
      • perl.exe (PID: 8308)
      • perl.exe (PID: 1676)
      • perl.exe (PID: 9168)
      • perl.exe (PID: 2992)
      • perl.exe (PID: 8544)
      • perl.exe (PID: 6856)
      • perl.exe (PID: 3584)
      • perl.exe (PID: 6068)
      • perl.exe (PID: 6952)
      • perl.exe (PID: 8760)
      • perl.exe (PID: 8148)
      • perl.exe (PID: 6536)
      • perl.exe (PID: 9184)
      • perl.exe (PID: 8616)
      • perl.exe (PID: 3172)
      • perl.exe (PID: 2844)
      • perl.exe (PID: 7192)
      • perl.exe (PID: 2140)
      • perl.exe (PID: 6976)
      • perl.exe (PID: 2368)
      • perl.exe (PID: 5444)
      • perl.exe (PID: 9080)
      • perl.exe (PID: 1984)
      • perl.exe (PID: 4828)
      • Maxon.exe (PID: 4116)
    • Process checks computer location settings

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 8544)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
    • Reads the computer name

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • identity_helper.exe (PID: 5460)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • VC_redist.x64.22.exe (PID: 8860)
      • msiexec.exe (PID: 5920)
      • VC_redist.x64.exe (PID: 8544)
      • VC_redist.x64.exe (PID: 7516)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
      • Maxon.exe (PID: 8648)
      • deep.exe (PID: 5016)
      • deep.tmp (PID: 3924)
      • Maxon.exe (PID: 4116)
    • Compiled with Borland Delphi (YARA)

      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 1068)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
    • Detects InnoSetup installer (YARA)

      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 1068)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 8396)
      • RedGiant Activation Service Unlocker 2026.0.0.exe (PID: 8300)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
    • Manual execution by a user

      • msedge.exe (PID: 6504)
    • Reads Environment values

      • identity_helper.exe (PID: 5460)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
    • Application launched itself

      • msedge.exe (PID: 6504)
    • The sample compiled with english language support

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • VC_redist.x64.22.exe (PID: 8860)
      • VC_RED~1.EXE (PID: 3172)
      • VC_redist.x64.exe (PID: 2996)
      • msiexec.exe (PID: 5920)
      • VC_redist.x64.exe (PID: 8544)
      • VC_redist.x64.exe (PID: 7516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7532)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
    • Process checks whether UAC notifications are on

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
    • Reads CPU info

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6504)
      • msiexec.exe (PID: 5920)
    • Reads the time zone

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
    • Drops script file

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • cmd.exe (PID: 8252)
      • cmd.exe (PID: 1116)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • deep.tmp (PID: 3924)
      • cmd.exe (PID: 9068)
      • cmd.exe (PID: 7760)
    • Creates files in the program directory

      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
      • VC_redist.x64.exe (PID: 2996)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7532)
      • RedGiant Activation Service Unlocker 2026.0.0.tmp (PID: 412)
      • deep.tmp (PID: 3924)
      • perl.exe (PID: 7192)
    • Manages system restore points

      • SrTasks.exe (PID: 5044)
    • Launching a file from a Registry key

      • VC_redist.x64.exe (PID: 2996)
    • Creates a software uninstall entry

      • VC_redist.x64.exe (PID: 2996)
      • msiexec.exe (PID: 5920)
    • Reads the machine GUID from the registry

      • VC_redist.x64.exe (PID: 2996)
      • msiexec.exe (PID: 5920)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 5920)
      • wermgr.exe (PID: 4020)
      • Maxon.exe (PID: 8648)
      • Maxon.exe (PID: 4116)
    • Checks proxy server information

      • slui.exe (PID: 3796)
      • wermgr.exe (PID: 4020)
      • MicrosoftEdgeUpdate.exe (PID: 5260)
    • There is functionality for taking screenshot (YARA)

      • Maxon_App_2026.1.0_Win.exe (PID: 1784)
      • Maxon_App_2026.1.0_Win.exe (PID: 8608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:15 01:30:50+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 834048
InitializedDataSize: 73728
UninitializedDataSize: -
EntryPoint: 0xccbd0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2026.0.0.0
ProductVersionNumber: 2026.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Red Giant, LLC
FileDescription: Activation Service Unlocker Setup
FileVersion: 2026.0.0.0
LegalCopyright: © Red Giant LLC
OriginalFileName:
ProductName: Activation Service Unlocker
ProductVersion: 2026.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
332
Monitored processes
170
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details
start redgiant activation service unlocker 2026.0.0.exe redgiant activation service unlocker 2026.0.0.tmp no specs redgiant activation service unlocker 2026.0.0.exe redgiant activation service unlocker 2026.0.0.tmp msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs maxon_app_2026.1.0_win.exe no specs maxon_app_2026.1.0_win.exe no specs maxon_app_2026.1.0_win.exe maxon_app_2026.1.0_win.exe cmd.exe no specs conhost.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs vc_redist.x64.22.exe vc_red~1.exe vc_redist.x64.exe SPPSurrogate no specs vssvc.exe no specs msedge.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe vc_redist.x64.exe no specs vc_redist.x64.exe vc_redist.x64.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe explorer.exe no specs explorer.exe no specs maxon.exe net.exe no specs conhost.exe no specs net1.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs timeout.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs timeout.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs deep.exe deep.tmp taskkill.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe cmd.exe no specs conhost.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs perl.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs timeout.exe no specs conhost.exe no specs maxon.exe

Process information

PID
CMD
Path
Indicators
Parent process
404\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
412"C:\Users\admin\AppData\Local\Temp\is-VDL82.tmp\RedGiant Activation Service Unlocker 2026.0.0.tmp" /SL5="$1002A6,8166887,908800,C:\Users\admin\AppData\Local\Temp\RedGiant Activation Service Unlocker 2026.0.0.exe" /SPAWNWND=$B03F4 /NOTIFYWND=$1003CE C:\Users\admin\AppData\Local\Temp\is-VDL82.tmp\RedGiant Activation Service Unlocker 2026.0.0.tmp
RedGiant Activation Service Unlocker 2026.0.0.exe
User:
admin
Company:
Red Giant, LLC
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vdl82.tmp\redgiant activation service unlocker 2026.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
488reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxon App v2025.2.1" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
756"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffd6f4cf208,0x7ffd6f4cf214,0x7ffd6f4cf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
768"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5356,i,4972155419272084089,13752632424229910648,262144 --variations-seed-version --mojo-platform-channel-handle=5140 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
796reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxon App v2.1.0" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1040reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxon App v2023.2.2" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1068"C:\Users\admin\AppData\Local\Temp\RedGiant Activation Service Unlocker 2026.0.0.exe" C:\Users\admin\AppData\Local\Temp\RedGiant Activation Service Unlocker 2026.0.0.exe
explorer.exe
User:
admin
Company:
Red Giant, LLC
Integrity Level:
MEDIUM
Description:
Activation Service Unlocker Setup
Exit code:
0
Version:
2026.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\redgiant activation service unlocker 2026.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1116C:\WINDOWS\system32\cmd.exe /s /c ""C:\Users\admin\AppData\Local\Temp\FUSE-W~1.BAT""C:\Windows\System32\cmd.exeMaxon_App_2026.1.0_Win.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
1400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2664,i,4972155419272084089,13752632424229910648,262144 --variations-seed-version --mojo-platform-channel-handle=6876 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
28 222
Read events
27 176
Write events
660
Delete events
386

Modification events

(PID) Process:(8608) Maxon_App_2026.1.0_Win.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem
Operation:writeName:LongPathsEnabled
Value:
1
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000CFD0B26191A2DC01F4120000BC1F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2996) VC_redist.x64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000AD82B26191A2DC01B40B000004080000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000008453036291A2DC01F4120000BC1F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000FEE3FB6191A2DC01F4120000BC1F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000120BFC6191A2DC01F4120000BC1F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000049A7FC6191A2DC01F4120000BC1F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
15
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
480000000000000087311D6291A2DC01F4120000BC1F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4852) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000068901F6291A2DC01F4120000F4110000E80300000100000000000000000000004D153F9EA370254CA576051E25F22A2800000000000000000000000000000000
Executable files
359
Suspicious files
342
Text files
601
Unknown types
33

Dropped files

PID
Process
Filename
Type
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e6753.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e6753.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e6762.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e6762.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e6782.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1e6782.TMP
MD5:
SHA256:
6504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
359
TCP/UDP connections
100
DNS requests
107
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2600
svchost.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6644
msedge.exe
GET
304
150.171.27.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
US
whitelisted
6644
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
US
text
4.30 Kb
whitelisted
6644
msedge.exe
POST
200
142.251.143.106:443
https://www.googleapis.com/chromewebstore/v1.1/items/verify
US
text
483 b
whitelisted
6644
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:09dqYqZAP6G-KgjwRq_9Yds-qt5xVwNE2gSLSkwYIdI&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
101 b
whitelisted
6644
msedge.exe
GET
200
13.107.246.45:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
6644
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
295 b
whitelisted
6644
msedge.exe
GET
200
23.55.110.70:443
https://ntp.msn.com/edge/ntp?locale=en-US&title=New%20tab&dsp=1&sp=Bing&startpage=1&PC=U531
NL
html
47.0 Kb
whitelisted
6644
msedge.exe
GET
200
2.16.241.207:443
https://www.bing.com/qbox?query=&language=en-US&pt=EdgBox&cvid=baaffccd2fa64ccba8db9f2ad6780737&oit=0&richanswersentity=1
NL
text
179 b
whitelisted
6644
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2600
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8068
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.207:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
6644
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6644
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6644
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6644
msedge.exe
23.55.110.70:443
ntp.msn.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.222
  • 2.16.241.218
  • 2.16.241.205
  • 92.123.104.52
  • 92.123.104.59
  • 92.123.104.50
  • 92.123.104.45
  • 92.123.104.49
  • 92.123.104.62
  • 92.123.104.61
  • 92.123.104.56
  • 92.123.104.63
whitelisted
google.com
  • 216.58.206.46
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
ntp.msn.com
  • 23.55.110.70
  • 23.55.110.66
whitelisted
api.edgeoffer.microsoft.com
  • 13.107.246.45
  • 13.107.213.45
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
  • 2.16.164.98
  • 2.16.164.83
  • 2.16.164.42
  • 2.16.164.106
  • 2.16.164.96
  • 2.16.164.114
  • 2.16.164.59
  • 2.16.164.40
  • 2.16.164.99
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.52.181.212
whitelisted

Threats

PID
Process
Class
Message
2600
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
6644
msedge.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
6644
msedge.exe
Misc activity
ET INFO Packed Executable Download
Process
Message
msiexec.exe
Failed to release Service
Maxon.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Maxon.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Maxon.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Maxon.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.