File name:

fastvd_bc.exe

Full analysis: https://app.any.run/tasks/ab33b58b-2b47-49f8-b3fc-75fbc6e388a2
Verdict: Malicious activity
Analysis date: February 25, 2024, 20:10:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A0378602CF315717FA81478CD7A8B089

SHA1:

0A029A2F6BA84600C379D8DBA629A2D07F5345FB

SHA256:

19CBB97C7EFEA408067522A621AA649D2C76A2758B43C327E64A96C8B274094C

SSDEEP:

98304:gSVglo0Y/mtnianoSUKRJGUx3fgT/UjAnmehSkLRWLTxO8iVwHFmwh5m/PwQ0brS:aLYaVg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fastvd_bc.exe (PID: 3944)
      • fastvd_bc.exe (PID: 3700)
      • fastvd_bc.tmp (PID: 3228)
    • Changes the autorun value in the registry

      • fastvd_bc.tmp (PID: 3228)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • fastvd_bc.tmp (PID: 3228)
    • Executable content was dropped or overwritten

      • fastvd_bc.tmp (PID: 3228)
      • fastvd_bc.exe (PID: 3700)
      • fastvd_bc.exe (PID: 3944)
    • Reads the Internet Settings

      • fastvd_bc.tmp (PID: 3228)
      • FastVD.exe (PID: 3964)
    • Reads security settings of Internet Explorer

      • fastvd_bc.tmp (PID: 3228)
      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 1776)
      • ScreenRecorder.exe (PID: 116)
    • Uses TASKKILL.EXE to kill process

      • fastvd_bc.tmp (PID: 3228)
    • Checks Windows Trust Settings

      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 116)
      • ScreenRecorder.exe (PID: 1776)
    • Reads settings of System Certificates

      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 1776)
      • ScreenRecorder.exe (PID: 116)
    • Adds/modifies Windows certificates

      • FastVD.exe (PID: 3964)
    • Reads Microsoft Outlook installation path

      • FastVD.exe (PID: 3964)
    • Reads Internet Explorer settings

      • FastVD.exe (PID: 3964)
  • INFO

    • Create files in a temporary directory

      • fastvd_bc.exe (PID: 3944)
      • fastvd_bc.tmp (PID: 3228)
      • fastvd_bc.exe (PID: 3700)
    • Checks supported languages

      • fastvd_bc.exe (PID: 3944)
      • fastvd_bc.tmp (PID: 2160)
      • fastvd_bc.tmp (PID: 3228)
      • FastVD.exe (PID: 3964)
      • fastvd_bc.exe (PID: 3700)
      • ScreenRecorder.exe (PID: 116)
      • ScreenRecorder.exe (PID: 1776)
    • Reads the computer name

      • fastvd_bc.tmp (PID: 2160)
      • fastvd_bc.tmp (PID: 3228)
      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 1776)
      • ScreenRecorder.exe (PID: 116)
    • Creates files in the program directory

      • fastvd_bc.tmp (PID: 3228)
    • Creates a software uninstall entry

      • fastvd_bc.tmp (PID: 3228)
    • Creates files or folders in the user directory

      • fastvd_bc.tmp (PID: 3228)
      • FastVD.exe (PID: 3964)
    • Application launched itself

      • msedge.exe (PID: 3276)
      • msedge.exe (PID: 2596)
      • msedge.exe (PID: 3112)
    • Reads the machine GUID from the registry

      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 1776)
      • ScreenRecorder.exe (PID: 116)
    • Reads the software policy settings

      • FastVD.exe (PID: 3964)
      • ScreenRecorder.exe (PID: 1776)
      • ScreenRecorder.exe (PID: 116)
    • Reads Environment values

      • FastVD.exe (PID: 3964)
    • Manual execution by a user

      • msedge.exe (PID: 2596)
    • Checks proxy server information

      • FastVD.exe (PID: 3964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 132096
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: FastPCTools
FileDescription: Fast Video Downloader
FileVersion: 4.0.0.0
LegalCopyright:
ProductName: Fast VD
ProductVersion: 4.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
79
Monitored processes
37
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fastvd_bc.exe fastvd_bc.tmp no specs fastvd_bc.exe fastvd_bc.tmp taskkill.exe no specs msedge.exe no specs fastvd.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs screenrecorder.exe no specs screenrecorder.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\FastPCTools\Fast VD\ScreenRecorder.exe" C:\Program Files\FastPCTools\Fast VD\ScreenRecorder.exeFastVD.exe
User:
admin
Company:
FastPCTools
Integrity Level:
HIGH
Description:
ScreenRecorder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\fastpctools\fast vd\screenrecorder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
968"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1196 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1192"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=3464 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1196"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3896 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1232"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2180 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2184 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1624"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1664 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1736"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1452 --field-trial-handle=1204,i,422001989467396273,12810652651572958681,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Program Files\FastPCTools\Fast VD\ScreenRecorder.exe" C:\Program Files\FastPCTools\Fast VD\ScreenRecorder.exeFastVD.exe
User:
admin
Company:
FastPCTools
Integrity Level:
HIGH
Description:
ScreenRecorder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\fastpctools\fast vd\screenrecorder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1992"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1472 --field-trial-handle=1344,i,2935745086502663942,11869475712034034181,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
28 336
Read events
28 075
Write events
231
Delete events
30

Modification events

(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
9C0C0000D29FC0B72668DA01
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
7F99B53BD9AB440D4AE69F04234744095E57507D5396C05508DB1FBBCD8851D8
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\FastPCTools\Fast VD\FastVD.exe
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
36ABCB8CC434152B373F0599250D56F24F8359F5CFA05AAEA8F5FB749C116AA7
(PID) Process:(3228) fastvd_bc.tmpKey:HKEY_CURRENT_USER\Software\FastPCTools\Fast VD
Operation:writeName:Language
Value:
en
Executable files
54
Suspicious files
25
Text files
61
Unknown types
43

Dropped files

PID
Process
Filename
Type
3944fastvd_bc.exeC:\Users\admin\AppData\Local\Temp\is-2OB3C.tmp\fastvd_bc.tmpexecutable
MD5:48204BCF63BA2BA5174DAED79C7F3084
SHA256:38F20CCC4BDD9C88DD8C20B6B8DE0EC6B5A173AD442595C65D470B293A84D778
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-1SIFH.tmpexecutable
MD5:E0B39D5AF41479B058FB09C60EAC8F1F
SHA256:F7C261EE3D021906F08B974D4EC7CB4A4707A1A22C3962A76AD025D8656F2238
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-TL6OS.tmpexecutable
MD5:04737FACA431ABC95CF0A42AE53E14DE
SHA256:6337316F7AFB0A298C489D544776D0B7ABA9D5794495C55835DA6C72AEBBF653
3700fastvd_bc.exeC:\Users\admin\AppData\Local\Temp\is-AU25B.tmp\fastvd_bc.tmpexecutable
MD5:48204BCF63BA2BA5174DAED79C7F3084
SHA256:38F20CCC4BDD9C88DD8C20B6B8DE0EC6B5A173AD442595C65D470B293A84D778
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\ScreenRecorder.exe.configxml
MD5:9E5C38CFE6D551AB59DA51D99F705594
SHA256:86962A74734AD629B911DA891A17A43650E618F6B6E6532EC3EA53B9E6026AB5
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-UCL7G.tmptext
MD5:C08DD1BC4B94C3A0B5E6B863101EF566
SHA256:2ACCAA5B42C3124610C4F0B40597344159DEEE9107E897D6175BA9E7920E7D51
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-ENTAN.tmpexecutable
MD5:05C9849856ABC683BCBC5C8D7921C146
SHA256:49284B31F28D0A62D797CFCF17F464C8C2B22B29D0E8AB7C15C94724D83E595C
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\videohelper license.txttext
MD5:C08DD1BC4B94C3A0B5E6B863101EF566
SHA256:2ACCAA5B42C3124610C4F0B40597344159DEEE9107E897D6175BA9E7920E7D51
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-95ATF.tmpexecutable
MD5:936ACE863919B97A08073AA3B5FF8F70
SHA256:4A73CDCE423FD3AB79A45F73E88F529F03561F77DB9BB2BC12471DE984E872BC
3228fastvd_bc.tmpC:\Program Files\FastPCTools\Fast VD\is-2LFJ0.tmpexecutable
MD5:42EDF51C86E726F00379CCBDAD2BC796
SHA256:F7E6FB7F23AC191CCAE310DEAEA112D03A17D507755D3E041D4213C02AD7BE9D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
59
DNS requests
41
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3964
FastVD.exe
GET
200
104.21.31.160:80
http://fastytd.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=85b2983869c46a64
unknown
text
57.0 Kb
unknown
3964
FastVD.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c9b06e0a7efc0637
unknown
unknown
3964
FastVD.exe
GET
403
104.21.31.160:80
http://fastytd.com/video_list.html
unknown
html
6.36 Kb
unknown
3964
FastVD.exe
GET
200
142.250.185.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
3964
FastVD.exe
GET
200
142.250.185.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3964
FastVD.exe
GET
200
142.250.185.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEH1ZfRmkcbmIEJt1GKpWSOU%3D
unknown
binary
471 b
unknown
3964
FastVD.exe
GET
200
142.250.185.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3964
FastVD.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?fc91d912a85a08d5
unknown
compressed
65.2 Kb
unknown
3964
FastVD.exe
GET
200
142.250.185.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEDZaTWA6V9G7CUUeg6KYX9I%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2596
msedge.exe
239.255.255.250:1900
unknown
2384
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2384
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2384
msedge.exe
172.67.178.68:443
www.fastytd.com
CLOUDFLARENET
US
unknown
3964
FastVD.exe
172.67.180.12:443
www.fastpctools.com
CLOUDFLARENET
US
unknown
3964
FastVD.exe
104.21.31.160:80
fastytd.com
CLOUDFLARENET
unknown
3964
FastVD.exe
142.250.186.100:443
www.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.fastytd.com
  • 172.67.178.68
unknown
edge.microsoft.com
  • 13.107.21.239
whitelisted
www.fastpctools.com
  • 172.67.180.12
unknown
fastytd.com
  • 104.21.31.160
unknown
www.google.com
  • 142.250.186.100
whitelisted
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
challenges.cloudflare.com
  • 104.17.3.184
whitelisted
www.bing.com
  • 13.107.21.200
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 184.25.51.59
whitelisted

Threats

PID
Process
Class
Message
2384
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
2384
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Process
Message
msedge.exe
[0225/201147.253:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)