File name:

Fortect.exe

Full analysis: https://app.any.run/tasks/6bb52d1f-3a37-465f-b00f-d3f6b4e149c3
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 10, 2025, 22:31:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pua
adware
arch-exec
nodejs
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

5A41CC32C5850525EED30B45517A1A24

SHA1:

DE8FB0BA058B520FBE24409634473D912AA19A3C

SHA256:

1E73585D9296635760C25DD2A76830226615E59FD8F18736A589792B1B8B5A73

SSDEEP:

24576:sJ8m9NhX4gzEhSCy4JP9ifykBT6nQmaWb/21:sJ8mfhX4gEhSCy4JP9ifykBT6n1aWbe1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • svchost.exe (PID: 2196)
      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainService.exe (PID: 1056)
      • FortectMain.exe (PID: 7624)
      • MainDaemon.exe (PID: 1272)
    • Changes the autorun value in the registry

      • Fortect.exe (PID: 7192)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Fortect.exe (PID: 1348)
    • Reads security settings of Internet Explorer

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainProtection.exe (PID: 7184)
    • Executable content was dropped or overwritten

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
      • MainProtection.exe (PID: 7184)
      • FortectMain.exe (PID: 7480)
    • Application launched itself

      • Fortect.exe (PID: 1348)
      • FortectMain.exe (PID: 7480)
    • Access to an unwanted program domain was detected

      • svchost.exe (PID: 2196)
      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainService.exe (PID: 1056)
      • FortectMain.exe (PID: 7624)
      • MainDaemon.exe (PID: 1272)
    • There is functionality for taking screenshot (YARA)

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
    • The process drops C-runtime libraries

      • Fortect.exe (PID: 7192)
    • Drops 7-zip archiver for unpacking

      • Fortect.exe (PID: 7192)
    • Process drops legitimate windows executable

      • Fortect.exe (PID: 7192)
    • Drops a system driver (possible attempt to evade defenses)

      • Fortect.exe (PID: 7192)
      • MainProtection.exe (PID: 7184)
    • Executes as Windows Service

      • MainDaemon.exe (PID: 1272)
      • MainService.exe (PID: 1056)
    • Creates a software uninstall entry

      • Fortect.exe (PID: 7192)
    • Creates or modifies Windows services

      • MainProtection.exe (PID: 7184)
    • Reads the date of Windows installation

      • MainService.exe (PID: 1056)
    • Searches for installed software

      • MainService.exe (PID: 1056)
    • Creates files in the driver directory

      • MainService.exe (PID: 1056)
    • Reads the BIOS version

      • MainService.exe (PID: 1056)
    • Read disk information to detect sandboxing environments

      • MainService.exe (PID: 1056)
  • INFO

    • Create files in a temporary directory

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
      • FortectMain.exe (PID: 7480)
      • MainProtection.exe (PID: 7184)
    • Reads the computer name

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainDaemon.exe (PID: 1272)
      • MainService.exe (PID: 2600)
      • MainService.exe (PID: 1056)
      • MainProtection.exe (PID: 7184)
      • MainProtection.exe (PID: 7496)
      • FortectMain.exe (PID: 7480)
      • FortectMain.exe (PID: 7624)
      • FortectMain.exe (PID: 7616)
    • Checks supported languages

      • Fortect.exe (PID: 7192)
      • Fortect.exe (PID: 1348)
      • MainDaemon.exe (PID: 8112)
      • MainDaemon.exe (PID: 1272)
      • MainService.exe (PID: 2600)
      • MainService.exe (PID: 1056)
      • MainProtection.exe (PID: 7184)
      • MainProtection.exe (PID: 7496)
      • FortectTray.exe (PID: 7520)
      • FortectMain.exe (PID: 7480)
      • FortectMain.exe (PID: 7624)
      • FortectMain.exe (PID: 1128)
      • FortectMain.exe (PID: 7616)
    • Process checks computer location settings

      • Fortect.exe (PID: 1348)
      • FortectMain.exe (PID: 7480)
      • Fortect.exe (PID: 7192)
      • FortectMain.exe (PID: 1128)
    • Reads Environment values

      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainService.exe (PID: 1056)
      • MainService.exe (PID: 2600)
      • MainDaemon.exe (PID: 1272)
      • MainProtection.exe (PID: 7184)
      • MainProtection.exe (PID: 7496)
      • FortectMain.exe (PID: 7480)
    • Checks proxy server information

      • Fortect.exe (PID: 7192)
      • MainProtection.exe (PID: 7184)
      • FortectMain.exe (PID: 7480)
    • Reads the machine GUID from the registry

      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • MainService.exe (PID: 2600)
      • MainProtection.exe (PID: 7184)
      • MainService.exe (PID: 1056)
      • FortectMain.exe (PID: 7480)
    • Creates files or folders in the user directory

      • Fortect.exe (PID: 7192)
      • MainProtection.exe (PID: 7184)
      • FortectMain.exe (PID: 7480)
      • FortectMain.exe (PID: 7624)
    • Reads the software policy settings

      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 8112)
      • slui.exe (PID: 7360)
      • MainProtection.exe (PID: 7184)
      • MainService.exe (PID: 1056)
    • The sample compiled with english language support

      • Fortect.exe (PID: 1348)
      • Fortect.exe (PID: 7192)
      • MainProtection.exe (PID: 7184)
    • Creates files in the program directory

      • MainDaemon.exe (PID: 8112)
      • Fortect.exe (PID: 7192)
      • MainDaemon.exe (PID: 1272)
      • MainService.exe (PID: 2600)
      • MainService.exe (PID: 1056)
      • MainProtection.exe (PID: 7184)
    • Manual execution by a user

      • FortectTray.exe (PID: 7520)
      • FortectMain.exe (PID: 7480)
    • Reads product name

      • FortectMain.exe (PID: 7480)
      • MainService.exe (PID: 1056)
    • Reads CPU info

      • MainService.exe (PID: 1056)
    • Node.js compiler has been detected

      • FortectMain.exe (PID: 7480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.2.2.5
ProductVersionNumber: 7.2.2.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Fortect
FileDescription: Fortect Setup
FileVersion: 7.2.2.5
InternalName: Fortect.exe
LegalCopyright: © Fortect
LegalTrademarks: © Fortect
OriginalFileName: Fortect.exe
ProductName: Fortect
ProductVersion: 7.2.2.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
18
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start fortect.exe #ADWARE fortect.exe sppextcomobj.exe no specs slui.exe #ADWARE svchost.exe #ADWARE maindaemon.exe slui.exe #ADWARE maindaemon.exe mainservice.exe no specs #ADWARE mainservice.exe mainprotection.exe mainprotection.exe no specs fortecttray.exe no specs fortectmain.exe fortectmain.exe no specs #ADWARE fortectmain.exe fortectmain.exe no specs fortectmain.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1056"C:\Program Files\Fortect\MainService.exe"C:\Program Files\Fortect\MainService.exe
services.exe
User:
SYSTEM
Company:
Fortect LTD.
Integrity Level:
SYSTEM
Description:
Fortect Service
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\mainservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1128"C:\Program Files\Fortect\FortectMain.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Fortect" --app-user-model-id=" " --app-path="C:\Program Files\Fortect\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=1916,i,10698546625209034245,7399380634735584572,262144 --enable-features=PdfUseShowSaveFilePicker --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=2620 /prefetch:1C:\Program Files\Fortect\FortectMain.exeFortectMain.exe
User:
admin
Company:
Fortect LTD®
Integrity Level:
MEDIUM
Description:
Fortect Main
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\fortectmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272"C:\Program Files\Fortect\bin\MainDaemon.exe"C:\Program Files\Fortect\bin\MainDaemon.exe
services.exe
User:
SYSTEM
Company:
Fortect Ltd.
Integrity Level:
SYSTEM
Description:
Fortect Daemon
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\bin\maindaemon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1348"C:\Users\admin\AppData\Local\Temp\Fortect.exe" C:\Users\admin\AppData\Local\Temp\Fortect.exe
explorer.exe
User:
admin
Company:
Fortect
Integrity Level:
MEDIUM
Description:
Fortect Setup
Exit code:
2
Version:
7.2.2.5
Modules
Images
c:\users\admin\appdata\local\temp\fortect.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2600"C:\Program Files\Fortect\MainService.exe" --install --hostId 8a3dee36982280f9964c4c545c7b600246cdea575fb22971dd9699b657fc3036C:\Program Files\Fortect\MainService.exeFortect.exe
User:
admin
Company:
Fortect LTD.
Integrity Level:
HIGH
Description:
Fortect Service
Exit code:
0
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\mainservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
4056"C:\Program Files\Fortect\FortectMain.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --user-data-dir="C:\Users\admin\AppData\Roaming\Fortect" --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1916,i,10698546625209034245,7399380634735584572,262144 --enable-features=PdfUseShowSaveFilePicker --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=3412 /prefetch:8C:\Program Files\Fortect\FortectMain.exeFortectMain.exe
User:
admin
Company:
Fortect LTD®
Integrity Level:
MEDIUM
Description:
Fortect Main
Exit code:
0
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\fortectmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5048C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7184"C:\Program Files\Fortect\MainProtection.exe" -installC:\Program Files\Fortect\MainProtection.exe
Fortect.exe
User:
admin
Company:
Fortect LTD
Integrity Level:
HIGH
Description:
Fortect Protection
Exit code:
0
Version:
7.2.2.5
Modules
Images
c:\program files\fortect\mainprotection.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
7192"C:\Users\admin\AppData\Local\Temp\Fortect.exe" /UAC=newC:\Users\admin\AppData\Local\Temp\Fortect.exe
Fortect.exe
User:
admin
Company:
Fortect
Integrity Level:
HIGH
Description:
Fortect Setup
Exit code:
0
Version:
7.2.2.5
Modules
Images
c:\users\admin\appdata\local\temp\fortect.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
12 735 264
Read events
12 735 183
Write events
63
Delete events
18

Modification events

(PID) Process:(7192) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7192) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7192) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7192) Fortect.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Engine
Operation:writeName:lang
Value:
1033
(PID) Process:(7192) Fortect.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon
Operation:writeName:Version
Value:
7.2.2.5
(PID) Process:(8112) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:user_settings
Value:
(PID) Process:(8112) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:daily_license
Value:
(PID) Process:(8112) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:ack_event
Value:
(PID) Process:(8112) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:notifications
Value:
(PID) Process:(8112) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:recheck
Value:
Executable files
137
Suspicious files
284
Text files
114
Unknown types
15

Dropped files

PID
Process
Filename
Type
7192Fortect.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\FortectSetup64[1].tgz
MD5:
SHA256:
7192Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\FortectSetup64.7z
MD5:
SHA256:
1348Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\LogEx.dllexecutable
MD5:9C3BC2EF57B3D38DD4738FB82F5643F2
SHA256:1D445ECD219B93D07FD1A6F04180C2260C35F368CD469BA6624F150E364F34FC
1348Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\System.dllexecutable
MD5:074A2FECD36EF94675CB4623884B762C
SHA256:4C7C26BB007517A74CCB1EBBD78E2EBDABD75A33CE6CEAFCF8C3D868A7404D50
7192Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\fUtil.dllexecutable
MD5:2E1D935FF172C75439D1F2C7988B58BF
SHA256:8E53C0F84AE060735E5F17A53D4CC025E1EEA45F757723705C65744CDEEBF4F3
7192Fortect.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C1740A6FE054581A27E6EAF0834CA468
SHA256:3B965E94BB29DE1DF7250CDB7A6D90B2585B52FC3D3CD6A5C0D486DDE6124A02
7192Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\INetC.dllexecutable
MD5:5C9E0E104B41CA4AE11D31D202B1941A
SHA256:C0D3ED3AB5B9FBBF6408A4558F4A9B52EC5B08DB66297E8AFB8614DB898EB3B8
7192Fortect.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
1348Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\UserInfo.dllexecutable
MD5:1EEB5C2C318E7A3DCDA394BDD64E4886
SHA256:76AB09A1F1EC889003753A29E592D8295260D6011A80D19306BAEDB1DE77FE08
7192Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\nsProcess.dllexecutable
MD5:866B43B8390F943F3E74C0DBF16D6CB5
SHA256:5C8DF12BABC6BADB49DBD14B555E45A4E1D564DFDDF2C1F57669A2513ECF5FF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
69
DNS requests
29
Threats
46

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7192
Fortect.exe
GET
200
142.250.185.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
7192
Fortect.exe
GET
200
142.250.185.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7924
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7924
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7184
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7184
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7184
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAYWounW1yoM1LbA47gYwNs%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7192
Fortect.exe
172.67.75.40:443
app.fortect.com
CLOUDFLARENET
US
unknown
7192
Fortect.exe
142.250.185.67:80
c.pki.goog
GOOGLE
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
google.com
  • 142.250.186.142
whitelisted
app.fortect.com
  • 172.67.75.40
  • 104.26.2.16
  • 104.26.3.16
unknown
c.pki.goog
  • 142.250.185.67
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.14
  • 20.190.160.67
  • 20.190.160.20
  • 20.190.160.2
  • 20.190.160.17
  • 40.126.32.138
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
cloud.fortect.com
  • 104.26.3.16
  • 104.26.2.16
  • 172.67.75.40
unknown

Threats

PID
Process
Class
Message
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
7192
Fortect.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
7192
Fortect.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
8112
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
8112
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
8112
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
8112
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
1056
MainService.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
No debug info