File name:

anyconnect-win-4.2.00096-web-deploy-k9.exe

Full analysis: https://app.any.run/tasks/1c7a2253-1339-4640-8bd3-950ab993ea44
Verdict: Malicious activity
Analysis date: August 06, 2020, 12:49:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0CF1BA3693B211B83F632A68A855FCCF

SHA1:

FE0C7124E2F21E3370AD1149027984FB1DE4655D

SHA256:

14BCE2809A80EF7E70F14FF47BDEF4425B4BB3310CFEA6536B46463F5261216D

SSDEEP:

98304:4p6O35iqBU+/YV6VDj4P0Gv6cxevuRwxX3LU6sOObwqlVzQk:LOTBHYVSDj4P4qev9HLU6sVM6zQk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
      • InstallHelper.exe (PID: 2180)
      • InstallHelper.exe (PID: 3928)
      • InstallHelper.exe (PID: 2464)
      • InstallHelper.exe (PID: 4020)
      • MsiExec.exe (PID: 1708)
      • InstallHelper.exe (PID: 968)
      • InstallHelper.exe (PID: 2716)
      • vpnagent.exe (PID: 1336)
      • InstallHelper.exe (PID: 3192)
      • InstallHelper.exe (PID: 3496)
      • InstallHelper.exe (PID: 2560)
    • Application was dropped or rewritten from another process

      • InstallHelper.exe (PID: 3928)
      • InstallHelper.exe (PID: 2464)
      • InstallHelper.exe (PID: 4020)
      • InstallHelper.exe (PID: 968)
      • VACon.exe (PID: 2804)
      • InstallHelper.exe (PID: 2180)
      • InstallHelper.exe (PID: 2716)
      • vpnagent.exe (PID: 1336)
      • VACon.exe (PID: 4004)
      • InstallHelper.exe (PID: 3192)
      • InstallHelper.exe (PID: 3496)
      • InstallHelper.exe (PID: 2560)
      • ManifestTool.exe (PID: 2148)
    • Changes the autorun value in the registry

      • VACon.exe (PID: 2804)
      • vpnagent.exe (PID: 1336)
    • Changes settings of System certificates

      • vpnagent.exe (PID: 1336)
    • Loads the Task Scheduler DLL interface

      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • anyconnect-win-4.2.00096-web-deploy-k9.exe (PID: 872)
      • VACon.exe (PID: 2804)
      • VACon.exe (PID: 4004)
      • DrvInst.exe (PID: 3104)
    • Creates COM task schedule object

      • MsiExec.exe (PID: 1708)
    • Removes files from Windows directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates files in the Windows directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates files in the driver directory

      • VACon.exe (PID: 2804)
      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
    • Creates files in the program directory

      • InstallHelper.exe (PID: 2716)
      • ManifestTool.exe (PID: 2148)
    • Executed via COM

      • DrvInst.exe (PID: 308)
      • DrvInst.exe (PID: 3104)
      • rundll32.exe (PID: 2464)
    • Adds / modifies Windows certificates

      • vpnagent.exe (PID: 1336)
    • Executed as Windows Service

      • vpnagent.exe (PID: 1336)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1428)
      • MsiExec.exe (PID: 1868)
    • Reads the hosts file

      • vpnagent.exe (PID: 1336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:03:01 11:28:24+01:00
PEType: PE32
LinkerVersion: 9
CodeSize: 202240
InitializedDataSize: 88064
UninitializedDataSize: -
EntryPoint: 0x23cfa
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.2.96.0
ProductVersionNumber: 4.2.96.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cisco Systems, Inc.
FileDescription: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
FileVersion: 4.2.00096
InternalName: WinSetup-Release-web-deploy
LegalCopyright: Copyright (C) Cisco Systems, Inc.
OriginalFileName: WinSetup-Release-web-deploy.exe
ProductName: Cisco AnyConnect Secure Mobility Client
ProductVersion: 4.2.00096

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-Mar-2010 10:28:24
Detected languages:
  • English - United States
CompanyName: Cisco Systems, Inc.
FileDescription: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
FileVersion: 4.2.00096
InternalName: WinSetup-Release-web-deploy
LegalCopyright: Copyright (C) Cisco Systems, Inc.
OriginalFileName: WinSetup-Release-web-deploy.exe
ProductName: Cisco AnyConnect Secure Mobility Client
ProductVersion: 4.2.00096

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 01-Mar-2010 10:28:24
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00031556
0x00031600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.57687
.rdata
0x00033000
0x00007D4C
0x00007E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.95038
.data
0x0003B000
0x0000369C
0x00001800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.60755
.rsrc
0x0003F000
0x0000C07C
0x0000C200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.36743

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.2335
829
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.08438
744
Latin 1 / Western European
English - United States
RT_ICON
3
3.20315
488
Latin 1 / Western European
English - United States
RT_ICON
4
3.08623
296
Latin 1 / Western European
English - United States
RT_ICON
5
5.59298
3752
Latin 1 / Western European
English - United States
RT_ICON
6
6.02092
2216
Latin 1 / Western European
English - United States
RT_ICON
7
6.00379
1736
Latin 1 / Western European
English - United States
RT_ICON
8
4.59129
1384
Latin 1 / Western European
English - United States
RT_ICON
9
3.37783
1116
Latin 1 / Western European
English - United States
RT_STRING
10
3.35468
1136
Latin 1 / Western European
English - United States
RT_STRING

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
VERSION.dll
msi.dll (delay-loaded)
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
23
Malicious processes
12
Suspicious processes
2

Behavior graph

Click at the process to see the details
start anyconnect-win-4.2.00096-web-deploy-k9.exe msiexec.exe no specs msiexec.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs msiexec.exe no specs vacon.exe runonce.exe grpconv.exe no specs installhelper.exe no specs vpnagent.exe vacon.exe drvinst.exe no specs drvinst.exe installhelper.exe no specs rundll32.exe no specs installhelper.exe no specs installhelper.exe no specs manifesttool.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{6b1465c5-bb9d-4211-d3d2-161a556b4c26}\vpnva-6.inf" "0" "658dd218b" "000005BC" "WinSta0\Default" "000003AC" "208" "c:\program files\cisco\cisco anyconnect secure mobility client"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
872"C:\Users\admin\AppData\Local\Temp\anyconnect-win-4.2.00096-web-deploy-k9.exe" C:\Users\admin\AppData\Local\Temp\anyconnect-win-4.2.00096-web-deploy-k9.exe
explorer.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
Exit code:
0
Version:
4.2.00096
Modules
Images
c:\users\admin\appdata\local\temp\anyconnect-win-4.2.00096-web-deploy-k9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
968"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveFiles "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\l10n\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\l10n\\" "*.*"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1336"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
services.exe
User:
SYSTEM
Company:
Cisco Systems, Inc.
Integrity Level:
SYSTEM
Description:
VPN Agent Service
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\vpnagent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
1428C:\Windows\system32\MsiExec.exe -Embedding 495956A8AD033CC1E951A45E984624F4C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1708"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnapi.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1868C:\Windows\system32\MsiExec.exe -Embedding AA1CA48EF8D0F84D7D1412C238EF34FC M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2148"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\ManifestTool.exe" -i "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\VPNManifestClient.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\ManifestTool.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
Cisco AnyConnect Secure Mobility Client ManifestTool
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\manifesttool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2180"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveIfExist "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\preferences_global.xml" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\preferences_global.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2464"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveFiles "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\Profile\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\Profile\\" "*.xml"C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 2, 00096
Modules
Images
c:\program files\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
825
Read events
380
Write events
400
Delete events
45

Modification events

(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\InProcServer32
Operation:writeName:(default)
Value:
C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnapi.dll
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Operation:writeName:(default)
Value:
PSFactoryBuffer
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Operation:writeName:(default)
Value:
IPromptEntry
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}\NumMethods
Operation:writeName:(default)
Value:
16
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}
Operation:writeName:(default)
Value:
IFirewallInfo
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F71DC93F-C07D-44A3-95B4-864177AE0F7E}\NumMethods
Operation:writeName:(default)
Value:
13
(PID) Process:(1708) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E0854B5E-16D3-46B5-8767-420EB1F48041}\ProxyStubClsid32
Operation:writeName:(default)
Value:
{548A1F06-AECE-4506-8ABB-5E3D3A99B67B}
Executable files
40
Suspicious files
24
Text files
148
Unknown types
13

Dropped files

PID
Process
Filename
Type
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\decoder.dllexecutable
MD5:143DA6747FFF236A473BDF6007629490
SHA256:75F59CFBA8C75D7646A697609A9BAEFB3388B1B6E66DB37C50924E3FCBA68893
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\app_logo.pngimage
MD5:E811B7C24EBC20C49FFF29D43B58A910
SHA256:376BE58FB4B1C86678638F3B84D9463916BC11FC06DC514BD4B2A9A0711A683C
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\about_hover.pngimage
MD5:0C44B5F59F8456672BEEDD77BF660F75
SHA256:0B048FA4AAE9BCBDAEA34DD9F150585DFF30583D12F74EA0AE264A1BEFF25166
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\company_logo.pngimage
MD5:5C000A89472BF6D3903FB71E6144D92D
SHA256:C0B767DCF4709C7DC8BADFB295F2688A91528EA30D7152EDE561539CB2A68269
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\gradient.pngimage
MD5:04C5DE9F86CC2F0381A0042E73093CF5
SHA256:03663DB3E312F320A51002847E9D66107ED51D20C9D191217DCB97A41B734605
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\mftogglebtn-down-solid.pngimage
MD5:23621A086EDE9B1FD7E2BC47D34E6411
SHA256:3F57C1F1EC3585BFF41ED202C122755778439DF44E3CC31FF298E449DD1B6411
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\company_logo_alt.pngimage
MD5:321558205DD79F1D1FC13F81A106CC94
SHA256:D0CDA8087D53031C77D3BDF3DE29B4352934E23FAEA41014AC73BA5589FFD93D
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\cues_bg.jpgimage
MD5:43799F121ABD219A50DBE0DD6B14CF79
SHA256:6107CF742CAB2FFACDEB7B54905AAE6FDE1912B363E60130DBD22DCE2EB9C97E
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\status_ico_attention.pngimage
MD5:DCE9C781307B2C03F63F677657719FF8
SHA256:6A91020F4C5AA819382DBC81C73A242E7109E93FF591FAF8EC804E42D0792D40
872anyconnect-win-4.2.00096-web-deploy-k9.exeC:\Users\admin\AppData\Local\Temp\install\E4F580C\res\mftogglebtn-down.pngimage
MD5:AE225F74EED0361CCDDE3D2B8C12B016
SHA256:07905AD3A11A6CB42DC6A563CE93C3BE190EAC55B701425624826E58CBA911EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1336
vpnagent.exe
GET
72.163.1.80:80
http://72.163.1.80/
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1336
vpnagent.exe
72.163.1.80:80
mus.cisco.com
Cisco Systems, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
mus.cisco.com
  • 72.163.1.80
whitelisted

Threats

No threats detected
Process
Message
VACon.exe
VACON: -install