File name:

usb_network_gate.exe

Full analysis: https://app.any.run/tasks/515905cb-29a1-4b3a-a5b5-846bc955e29e
Verdict: Malicious activity
Analysis date: December 20, 2023, 18:36:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

01DD7E71E16459E3EF224F23F6C64AD2

SHA1:

7FD7A1B0164239D32A9B8AEBA32075B200004A4C

SHA256:

1B8277F98A52778B48E882CED05B3898BFAAC7E33B89482F2A71571BDC93D1D5

SSDEEP:

98304:BgmqdDcCn54qVyhTJAZFRxIPwdRaGrfgYmTTZxWnagGOJYC6KW5pqCnxGc0BuEAt:yMrTdrlPX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • usb_network_gate.exe (PID: 2124)
      • usb_network_gate.exe (PID: 2024)
      • usb_network_gate.tmp (PID: 2016)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 1816)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1816)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • usb_network_gate.tmp (PID: 2016)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 1816)
    • Reads the Windows owner or organization settings

      • usb_network_gate.tmp (PID: 2016)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1216)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 2000)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 1216)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 796)
      • UsbService.exe (PID: 2884)
      • drvinst.exe (PID: 632)
      • UsbConfig.exe (PID: 3076)
    • Reads security settings of Internet Explorer

      • setup_server_ung.exe (PID: 1040)
      • UsbConfig.exe (PID: 3076)
    • Reads settings of System Certificates

      • setup_server_ung.exe (PID: 1040)
      • UsbConfig.exe (PID: 3076)
    • Executes as Windows Service

      • UsbService.exe (PID: 2884)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • usb_network_gate.tmp (PID: 2016)
    • Searches for installed software

      • UsbConfig.exe (PID: 3076)
    • Reads the history of recent RDP connections

      • UsbConfig.exe (PID: 3076)
    • Reads the BIOS version

      • UsbService.exe (PID: 2884)
    • Reads the Internet Settings

      • UsbConfig.exe (PID: 3076)
    • Adds/modifies Windows certificates

      • UsbService.exe (PID: 2884)
    • Reads Internet Explorer settings

      • UsbConfig.exe (PID: 3076)
    • Reads Microsoft Outlook installation path

      • UsbConfig.exe (PID: 3076)
  • INFO

    • Checks supported languages

      • usb_network_gate.exe (PID: 2124)
      • usb_network_gate.exe (PID: 2024)
      • usb_network_gate.tmp (PID: 2016)
      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 632)
      • drvinst.exe (PID: 796)
      • UsbService.exe (PID: 2760)
      • UsbService.exe (PID: 2804)
      • UsbService.exe (PID: 2892)
      • UsbService.exe (PID: 2884)
      • UsbConfig.exe (PID: 3076)
      • setup_server_ung.exe (PID: 1040)
      • usb_network_gate.tmp (PID: 2044)
    • Reads the computer name

      • usb_network_gate.tmp (PID: 2044)
      • usb_network_gate.tmp (PID: 2016)
      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 796)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 632)
      • UsbService.exe (PID: 2760)
      • UsbService.exe (PID: 2892)
      • UsbService.exe (PID: 2884)
      • UsbConfig.exe (PID: 3076)
    • Creates files in the program directory

      • usb_network_gate.tmp (PID: 2016)
      • UsbService.exe (PID: 2760)
      • UsbService.exe (PID: 2884)
      • UsbConfig.exe (PID: 3076)
    • Create files in a temporary directory

      • usb_network_gate.tmp (PID: 2016)
      • usb_network_gate.exe (PID: 2024)
      • usb_network_gate.exe (PID: 2124)
      • setup_server_ung.exe (PID: 1040)
    • Reads the machine GUID from the registry

      • setup_server_ung.exe (PID: 1040)
      • drvinst.exe (PID: 1216)
      • drvinst.exe (PID: 2000)
      • drvinst.exe (PID: 1816)
      • drvinst.exe (PID: 796)
      • UsbService.exe (PID: 2760)
      • drvinst.exe (PID: 632)
      • UsbConfig.exe (PID: 3076)
      • UsbService.exe (PID: 2884)
    • Reads CPU info

      • UsbService.exe (PID: 2760)
      • UsbService.exe (PID: 2884)
    • Checks proxy server information

      • UsbConfig.exe (PID: 3076)
    • Creates files or folders in the user directory

      • UsbConfig.exe (PID: 3076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 16:39:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 9.2.2372.0
ProductVersionNumber: 9.2.2372.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Electronic Team
FileDescription: USB Network Gate
FileVersion: Usb Network Gate 9.2
LegalCopyright: Copyright © 2000-2021 Electronic Team, Inc. All rights reserved.
ProductName: USB Network Gate
ProductVersion: Usb Network Gate 9.2.2372
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
17
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start usb_network_gate.exe no specs usb_network_gate.tmp no specs usb_network_gate.exe usb_network_gate.tmp no specs setup_server_ung.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs usbservice.exe usbservice.exe no specs usbservice.exe no specs usbservice.exe netsh.exe no specs netsh.exe no specs usbconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
632DrvInst.exe "1" "200" "UsbEStub\Devices\0004" "" "" "6c5c6bf7f" "00000000" "000005D8" "000005F0"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
796DrvInst.exe "1" "200" "UsbEStub\Devices\0000" "" "" "655b45ca3" "00000000" "000005F4" "00000610"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1040"C:\Program Files\Electronic Team\USB Network Gate\drv\NT6\setup_server_ung.exe"C:\Program Files\Electronic Team\USB Network Gate\drv\NT6\setup_server_ung.exeusb_network_gate.tmp
User:
admin
Company:
Electronic Team, Inc.
Integrity Level:
HIGH
Description:
Setup USB drivers
Exit code:
0
Version:
2.6.2
Modules
Images
c:\program files\electronic team\usb network gate\drv\nt6\setup_server_ung.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1216DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{635d1c88-866b-239a-1721-d841cc30d606}\UsbStub.inf" "0" "62ab9136b" "00000300" "WinSta0\Default" "00000570" "208" "C:\Program Files\Electronic Team\USB Network Gate\drv\NT6"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1816DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "vuh.inf:Electronic.NTx86:VUHUB_Device:9.1.2285.0:vuhub" "625e1bb63" "000005D8" "000005E0" "000005E8"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2000DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7df729a4-bacb-1893-820d-e301cc30d606}\vuh.inf" "0" "625e1bb63" "000005D8" "WinSta0\Default" "000005D4" "208" "c:\program files\electronic team\usb network gate\drv\nt6"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2016"C:\Users\admin\AppData\Local\Temp\is-UQJKV.tmp\usb_network_gate.tmp" /SL5="$501AC,5203441,121344,C:\Users\admin\AppData\Local\Temp\usb_network_gate.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-UQJKV.tmp\usb_network_gate.tmpusb_network_gate.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-uqjkv.tmp\usb_network_gate.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2024"C:\Users\admin\AppData\Local\Temp\usb_network_gate.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\usb_network_gate.exe
usb_network_gate.tmp
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
0
Version:
Usb Network Gate 9.2
Modules
Images
c:\users\admin\appdata\local\temp\usb_network_gate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2044"C:\Users\admin\AppData\Local\Temp\is-F8VD8.tmp\usb_network_gate.tmp" /SL5="$301AA,5203441,121344,C:\Users\admin\AppData\Local\Temp\usb_network_gate.exe" C:\Users\admin\AppData\Local\Temp\is-F8VD8.tmp\usb_network_gate.tmpusb_network_gate.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-f8vd8.tmp\usb_network_gate.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2124"C:\Users\admin\AppData\Local\Temp\usb_network_gate.exe" C:\Users\admin\AppData\Local\Temp\usb_network_gate.exeexplorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
Usb Network Gate 9.2
Modules
Images
c:\users\admin\appdata\local\temp\usb_network_gate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
32 016
Read events
31 372
Write events
638
Delete events
6

Modification events

(PID) Process:(1040) setup_server_ung.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1216) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2000) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1816) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1816) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
130000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F00000010000000110000001200000013000000
(PID) Process:(1816) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
140000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000
(PID) Process:(632) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(632) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
140000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000
(PID) Process:(632) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Extended Base
Value:
150000000100000002000000040000000300000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000
(PID) Process:(796) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
50
Suspicious files
87
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\is-FRS84.tmpexecutable
MD5:62C43330335F00DA95502443D6F15F45
SHA256:14232E0E3B568E726BE2E80A47526AABCB36DAC2A0F92FBE06A9CAB39CE08C56
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\unins000.exeexecutable
MD5:62C43330335F00DA95502443D6F15F45
SHA256:14232E0E3B568E726BE2E80A47526AABCB36DAC2A0F92FBE06A9CAB39CE08C56
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\drv\NT6\is-VO9ER.tmpexecutable
MD5:D212BBAF21AA448B5A1EEC5214E7C02A
SHA256:6CF405F72D78EDA427DD806283DCC6764C8A61776DC4A7C351395DCCAB7BA4D3
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\drv\NT6\fusbhub.sysexecutable
MD5:D212BBAF21AA448B5A1EEC5214E7C02A
SHA256:6CF405F72D78EDA427DD806283DCC6764C8A61776DC4A7C351395DCCAB7BA4D3
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\usb4citrix.dllexecutable
MD5:9D7AAA9B7FE5ADEDCBC49FCB0A206191
SHA256:D1F8C662AA6B7656D7C7C38A17AE21C9A2FA7AED3C8E783071DD045ACC8E8BF4
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\is-O6T18.tmpexecutable
MD5:9D7AAA9B7FE5ADEDCBC49FCB0A206191
SHA256:D1F8C662AA6B7656D7C7C38A17AE21C9A2FA7AED3C8E783071DD045ACC8E8BF4
2024usb_network_gate.exeC:\Users\admin\AppData\Local\Temp\is-UQJKV.tmp\usb_network_gate.tmpexecutable
MD5:62C43330335F00DA95502443D6F15F45
SHA256:14232E0E3B568E726BE2E80A47526AABCB36DAC2A0F92FBE06A9CAB39CE08C56
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\drv\NT6\setup_server_ung.exeexecutable
MD5:069D60D341C44C96318443CC07A905D8
SHA256:AA2652F57D6FF7D40B5BE9F36CADB3023D705BD0A888C989DB968B6E7A03958F
2016usb_network_gate.tmpC:\Users\admin\AppData\Local\Temp\is-TCDGB.tmp\reset.dllexecutable
MD5:1FB1431779318F095681607EACCC1C04
SHA256:EF4465A8765B207BAB591CB1BD2BB0402CE60A1F99C5391B1BEB65936BC6869C
2016usb_network_gate.tmpC:\Program Files\Electronic Team\USB Network Gate\drv\NT6\is-VHL3G.tmpbinary
MD5:2EE9CB85E29B064AD60F0F18680EFBFC
SHA256:9799115598A14BDFE92B348693654EA1F43CC03E8D4130983529ABF892BFF88C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
33
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3076
UsbConfig.exe
GET
200
2.19.198.34:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ea717df1b8693c10
unknown
compressed
4.66 Kb
unknown
2884
UsbService.exe
GET
200
2.19.198.34:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2dbf7c822febf98c
unknown
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
2.19.198.41:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?89bca2e7018c82c0
unknown
unknown
3076
UsbConfig.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
3076
UsbConfig.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
binary
2.18 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2760
UsbService.exe
78.46.96.38:443
appstatico.electronic.us
Hetzner Online GmbH
DE
unknown
2884
UsbService.exe
2.19.198.34:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2884
UsbService.exe
188.40.191.126:443
activate.electronic.us
Hetzner Online GmbH
DE
unknown
2884
UsbService.exe
78.46.96.38:443
appstatico.electronic.us
Hetzner Online GmbH
DE
unknown
3076
UsbConfig.exe
192.168.100.255:5474
whitelisted
3076
UsbConfig.exe
156.146.33.138:443
cdn.electronic.us
Datacamp Limited
DE
unknown
3076
UsbConfig.exe
2.19.198.34:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
appstatico.electronic.us
  • 78.46.96.38
unknown
ctldl.windowsupdate.com
  • 2.19.198.34
  • 23.32.239.74
  • 2.19.198.41
  • 2.19.198.66
  • 2.19.198.48
  • 2.19.198.56
  • 2.19.198.42
  • 23.32.238.163
  • 23.32.238.147
  • 2.19.198.64
  • 2.19.198.49
whitelisted
activate.electronic.us
  • 188.40.191.126
unknown
cdn.electronic.us
  • 156.146.33.138
  • 212.102.56.182
  • 212.102.56.178
  • 156.146.33.141
  • 195.181.175.40
  • 195.181.170.19
  • 195.181.175.16
unknown
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info