File name:

anyconnect-win-4.2.00096-web-deploy-k9.exe

Full analysis: https://app.any.run/tasks/1c7a2253-1339-4640-8bd3-950ab993ea44
Verdict: Malicious activity
Analysis date: August 06, 2020, 12:49:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0CF1BA3693B211B83F632A68A855FCCF

SHA1:

FE0C7124E2F21E3370AD1149027984FB1DE4655D

SHA256:

14BCE2809A80EF7E70F14FF47BDEF4425B4BB3310CFEA6536B46463F5261216D

SSDEEP:

98304:4p6O35iqBU+/YV6VDj4P0Gv6cxevuRwxX3LU6sOObwqlVzQk:LOTBHYVSDj4P4qev9HLU6sVM6zQk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • InstallHelper.exe (PID: 4020)
      • InstallHelper.exe (PID: 2180)
      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
      • InstallHelper.exe (PID: 968)
      • MsiExec.exe (PID: 1708)
      • InstallHelper.exe (PID: 3928)
      • InstallHelper.exe (PID: 2464)
      • InstallHelper.exe (PID: 2716)
      • vpnagent.exe (PID: 1336)
      • InstallHelper.exe (PID: 3192)
      • InstallHelper.exe (PID: 3496)
      • InstallHelper.exe (PID: 2560)
    • Application was dropped or rewritten from another process

      • InstallHelper.exe (PID: 4020)
      • InstallHelper.exe (PID: 968)
      • InstallHelper.exe (PID: 2180)
      • InstallHelper.exe (PID: 3928)
      • VACon.exe (PID: 2804)
      • InstallHelper.exe (PID: 2716)
      • vpnagent.exe (PID: 1336)
      • VACon.exe (PID: 4004)
      • InstallHelper.exe (PID: 3192)
      • InstallHelper.exe (PID: 3496)
      • InstallHelper.exe (PID: 2464)
      • InstallHelper.exe (PID: 2560)
      • ManifestTool.exe (PID: 2148)
    • Changes the autorun value in the registry

      • VACon.exe (PID: 2804)
      • vpnagent.exe (PID: 1336)
    • Changes settings of System certificates

      • vpnagent.exe (PID: 1336)
    • Loads the Task Scheduler DLL interface

      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
      • VACon.exe (PID: 2804)
      • VACon.exe (PID: 4004)
      • DrvInst.exe (PID: 3104)
    • Removes files from Windows directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates COM task schedule object

      • MsiExec.exe (PID: 1708)
    • Creates files in the Windows directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates files in the driver directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates files in the program directory

      • InstallHelper.exe (PID: 2716)
      • ManifestTool.exe (PID: 2148)
    • Executed as Windows Service

      • vpnagent.exe (PID: 1336)
    • Executed via COM

      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
      • rundll32.exe (PID: 2464)
    • Adds / modifies Windows certificates

      • vpnagent.exe (PID: 1336)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1428)
      • MsiExec.exe (PID: 1868)
    • Reads the hosts file

      • vpnagent.exe (PID: 1336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:03:01 11:28:24+01:00
PEType: PE32
LinkerVersion: 9
CodeSize: 202240
InitializedDataSize: 88064
UninitializedDataSize: -
EntryPoint: 0x23cfa
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.2.96.0
ProductVersionNumber: 4.2.96.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cisco Systems, Inc.
FileDescription: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
FileVersion: 4.2.00096
InternalName: WinSetup-Release-web-deploy
LegalCopyright: Copyright (C) Cisco Systems, Inc.
OriginalFileName: WinSetup-Release-web-deploy.exe
ProductName: Cisco AnyConnect Secure Mobility Client
ProductVersion: 4.2.00096

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-Mar-2010 10:28:24
Detected languages:
  • English - United States
CompanyName: Cisco Systems, Inc.
FileDescription: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
FileVersion: 4.2.00096
InternalName: WinSetup-Release-web-deploy
LegalCopyright: Copyright (C) Cisco Systems, Inc.
OriginalFileName: WinSetup-Release-web-deploy.exe
ProductName: Cisco AnyConnect Secure Mobility Client
ProductVersion: 4.2.00096

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 01-Mar-2010 10:28:24
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00031556
0x00031600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.57687
.rdata
0x00033000
0x00007D4C
0x00007E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.95038
.data
0x0003B000
0x0000369C
0x00001800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.60755
.rsrc
0x0003F000
0x0000C07C
0x0000C200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.36743

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.2335
829
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.08438
744
Latin 1 / Western European
English - United States
RT_ICON
3
3.20315
488
Latin 1 / Western European
English - United States
RT_ICON
4
3.08623
296
Latin 1 / Western European
English - United States
RT_ICON
5
5.59298
3752
Latin 1 / Western European
English - United States
RT_ICON
6
6.02092
2216
Latin 1 / Western European
English - United States
RT_ICON
7
6.00379
1736
Latin 1 / Western European
English - United States
RT_ICON
8
4.59129
1384
Latin 1 / Western European
English - United States
RT_ICON
9
3.37783
1116
Latin 1 / Western European
English - United States
RT_STRING
10
3.35468
1136
Latin 1 / Western European
English - United States
RT_STRING

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
VERSION.dll
msi.dll (delay-loaded)
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
23
Malicious processes
12
Suspicious processes
2

Behavior graph

Click at the process to see the details
start anyconnect-win-4.2.00096-web-deploy-k9.exe msiexec.exe no specs msiexec.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs msiexec.exe no specs vacon.exe runonce.exe grpconv.exe no specs installhelper.exe no specs vpnagent.exe vacon.exe drvinst.exe no specs drvinst.exe installhelper.exe no specs rundll32.exe no specs installhelper.exe no specs installhelper.exe no specs manifesttool.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{6b1465c5-bb9d-4211-d3d2-161a556b4c26}\vpnva-6.inf" "0" "658dd218b" "000005BC" "WinSta0\Default" "000003AC" "208" "c:\program files\cisco\cisco anyconnect secure mobility client"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
872"C:\Users\admin\AppData\Local\Temp\anyconnect-win-4.2.00096-web-deploy-k9.exe" C:\Users\admin\AppData\Local\Temp\anyconnect-win-4.2.00096-web-deploy-k9.exe
explorer.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
Exit code:
0
Version:
4.2.00096
Modules
Images
c:\users\admin\appdata\local\temp\anyconnect-win-4.2.00096-web-deploy-k9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
968"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveFiles "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\l10n\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\l10n\\" "*.*"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1336"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
services.exe
User:
SYSTEM
Company:
Cisco Systems, Inc.
Integrity Level:
SYSTEM
Description:
VPN Agent Service
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\vpnagent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
1428C:\Windows\system32\MsiExec.exe -Embedding 495956A8AD033CC1E951A45E984624F4C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1708"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnapi.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1868C:\Windows\system32\MsiExec.exe -Embedding AA1CA48EF8D0F84D7D1412C238EF34FC M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2148"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\ManifestTool.exe" -i "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\VPNManifestClient.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\ManifestTool.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
Cisco AnyConnect Secure Mobility Client ManifestTool
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\manifesttool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2180"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveIfExist "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\preferences_global.xml" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\preferences_global.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2464"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveFiles "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\Profile\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\Profile\\" "*.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
825
Read events
380
Write events
400
Delete events
45

Modification events

(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\InProcServer32
Operation:writeName:(default)
Value:
C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnapi.dll
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Operation:writeName:(default)
Value:
PSFactoryBuffer
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Operation:writeName:(default)
Value:
IPromptEntry
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\NumMethods
Operation:writeName:(default)
Value:
16
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}
Operation:writeName:(default)
Value:
IFirewallInfo
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}\NumMethods
Operation:writeName:(default)
Value:
13
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E0854B5E-16D3-46B5-8767-420EB1F48041}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Executable files
40
Suspicious files
24
Text files
148
Unknown types
13

Dropped files

PID
Process
Filename
Type
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\company_logo.pngimage
MD5:5C000A89472BF6D3903FB71E6144D92D
SHA256:C0B767DCF4709C7DC8BADFB295F2688A91528EA30D7152EDE561539CB2A68269
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\mftogglebtn-down.pngimage
MD5:AE225F74EED0361CCDDE3D2B8C12B016
SHA256:07905AD3A11A6CB42DC6A563CE93C3BE190EAC55B701425624826E58CBA911EB
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\gradient.pngimage
MD5:04C5DE9F86CC2F0381A0042E73093CF5
SHA256:03663DB3E312F320A51002847E9D66107ED51D20C9D191217DCB97A41B734605
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\company_logo_alt.pngimage
MD5:321558205DD79F1D1FC13F81A106CC94
SHA256:D0CDA8087D53031C77D3BDF3DE29B4352934E23FAEA41014AC73BA5589FFD93D
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\mftogglebtn.pngimage
MD5:F454DF3C51D87CA76BE504B09589116A
SHA256:1779ADC0BA85406A1D2654571369931EFEC0B903E1B4647165997F1F53C35F6D
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\status_ico_error.pngimage
MD5:8F39E2F34F65B6E0D8340E7A3ECDE0C3
SHA256:278759468DC931E03F33AC9B3641D7F5844243A3BAF5745A4F8EC3A3C26DC268
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\status_ico_attention.pngimage
MD5:DCE9C781307B2C03F63F677657719FF8
SHA256:6A91020F4C5AA819382DBC81C73A242E7109E93FF591FAF8EC804E42D0792D40
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\toast_vpn.pngimage
MD5:CA0DE0B6D1921833D273BAC247811239
SHA256:3A2D2D9F97200CA77856F9CC2E5311EA3A728A3C3BD5FF312034120B3D31761C
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\status_ico_trusted.pngimage
MD5:60ACC1AE09E20F12790EB73FE032110B
SHA256:576F420A4F0CE0552C15AF1FFB20D2AA681A420AE82F8A573FA13C1937A8C10D
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\status_ico_good.pngimage
MD5:2FAA735660336BDD04425128C3BCA5BD
SHA256:31723BE1895BBE20BC83925CBCACBC9ADE11320C751F1A549A870C6C462CDDF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1336
vpnagent.exe
GET
72.163.1.80:80
http://72.163.1.80/
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1336
vpnagent.exe
72.163.1.80:80
mus.cisco.com
Cisco Systems, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
mus.cisco.com
  • 72.163.1.80
whitelisted

Threats

No threats detected
Process
Message
VACon.exe
VACON: -install