File name:

darkguard_0.1.0_x64-setup.exe

Full analysis: https://app.any.run/tasks/e21215e3-ed9c-48a9-9afe-785a95dde82e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 03, 2026, 02:56:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

57963CD0C8613D7CEBB7216E5FC5CB2D

SHA1:

C8177AD2390A752F07202E1E74C29D15E664888B

SHA256:

230B91DD4ECB22CA7333C3ED76032A392AC3EE1CE07813A12DD04665D58DB24D

SSDEEP:

98304:x0z13sQ3jThjAGDbqYn8ho15qtKWSLBH8gq+gaPOKkDMwtAFZFSmCpP9bfTVHZO8:qxxy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • msiexec.exe (PID: 1368)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2288)
      • powershell.exe (PID: 1092)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • MicrosoftEdgeUpdate.exe (PID: 3088)
    • Searches for installed software

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • setup.exe (PID: 6332)
      • msedgewebview2.exe (PID: 8320)
    • Process drops legitimate windows executable

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • setup.exe (PID: 6332)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • setup.exe (PID: 6332)
      • wireguard.exe (PID: 752)
      • powershell.exe (PID: 9072)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 3088)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 3088)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6920)
      • MicrosoftEdgeUpdate.exe (PID: 2760)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6644)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7476)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • wireguard.exe (PID: 7204)
      • wireguard.exe (PID: 752)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • setup.exe (PID: 6332)
      • msedgewebview2.exe (PID: 8320)
      • msiexec.exe (PID: 1368)
      • wireguard.exe (PID: 7204)
      • wireguard.exe (PID: 8372)
      • msedgewebview2.exe (PID: 8824)
    • The process creates files with name similar to system file names

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 9072)
    • The process bypasses the loading of PowerShell profile settings

      • DarkGuard.exe (PID: 3636)
      • DarkGuard.exe (PID: 8964)
    • Starts POWERSHELL.EXE for commands execution

      • DarkGuard.exe (PID: 3636)
      • DarkGuard.exe (PID: 8964)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 1368)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1368)
    • Reads the date of Windows installation

      • wireguard.exe (PID: 8372)
    • Starts process via Powershell

      • powershell.exe (PID: 2288)
      • powershell.exe (PID: 6896)
      • powershell.exe (PID: 1092)
    • Drops a system driver (possible attempt to evade defenses)

      • wireguard.exe (PID: 752)
      • drvinst.exe (PID: 1128)
    • Starts SC.EXE for service management

      • DarkGuard.exe (PID: 8964)
    • Windows service management via SC.EXE

      • sc.exe (PID: 3436)
      • sc.exe (PID: 1084)
      • sc.exe (PID: 3048)
      • sc.exe (PID: 3548)
      • sc.exe (PID: 8340)
      • sc.exe (PID: 148)
      • sc.exe (PID: 4696)
      • sc.exe (PID: 2288)
      • sc.exe (PID: 4352)
      • sc.exe (PID: 1760)
      • sc.exe (PID: 4728)
      • sc.exe (PID: 7704)
      • sc.exe (PID: 5356)
      • sc.exe (PID: 5180)
      • sc.exe (PID: 8740)
      • sc.exe (PID: 4140)
      • sc.exe (PID: 3048)
      • sc.exe (PID: 7724)
      • sc.exe (PID: 7280)
      • sc.exe (PID: 1524)
      • sc.exe (PID: 7156)
      • sc.exe (PID: 4024)
      • sc.exe (PID: 6552)
      • sc.exe (PID: 7524)
      • sc.exe (PID: 1792)
      • sc.exe (PID: 8824)
      • sc.exe (PID: 6404)
      • sc.exe (PID: 3032)
      • sc.exe (PID: 2232)
      • sc.exe (PID: 1868)
      • sc.exe (PID: 6036)
      • sc.exe (PID: 9064)
      • sc.exe (PID: 2148)
      • sc.exe (PID: 8032)
  • INFO

    • Checks supported languages

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • MicrosoftEdgeUpdate.exe (PID: 2760)
      • MicrosoftEdgeUpdate.exe (PID: 1044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6644)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6920)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7476)
      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • MicrosoftEdgeUpdate.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 8788)
      • MicrosoftEdgeUpdate.exe (PID: 8824)
      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • setup.exe (PID: 6332)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • setup.exe (PID: 4804)
      • MicrosoftEdgeUpdate.exe (PID: 5780)
      • DarkGuard.exe (PID: 3636)
      • msedgewebview2.exe (PID: 8556)
      • msedgewebview2.exe (PID: 8320)
      • msedgewebview2.exe (PID: 7636)
      • msedgewebview2.exe (PID: 2252)
      • msedgewebview2.exe (PID: 6352)
      • msedgewebview2.exe (PID: 2248)
      • msiexec.exe (PID: 1368)
      • msiexec.exe (PID: 7448)
      • msiexec.exe (PID: 1836)
      • wireguard.exe (PID: 5448)
      • wireguard.exe (PID: 8372)
      • wireguard.exe (PID: 7204)
      • wireguard.exe (PID: 7304)
      • DarkGuard.exe (PID: 8964)
      • msedgewebview2.exe (PID: 5484)
      • msedgewebview2.exe (PID: 5392)
      • msedgewebview2.exe (PID: 8824)
      • msedgewebview2.exe (PID: 6848)
      • msedgewebview2.exe (PID: 4728)
      • msedgewebview2.exe (PID: 1400)
      • wireguard.exe (PID: 752)
      • drvinst.exe (PID: 1128)
      • wireguard.exe (PID: 3552)
      • wg.exe (PID: 8520)
      • wg.exe (PID: 1856)
      • wg.exe (PID: 8400)
      • wg.exe (PID: 2220)
      • drvinst.exe (PID: 1824)
      • wg.exe (PID: 5160)
      • wg.exe (PID: 4760)
      • wg.exe (PID: 3988)
      • wg.exe (PID: 8428)
      • wg.exe (PID: 8660)
      • wg.exe (PID: 8536)
      • wg.exe (PID: 5580)
      • wg.exe (PID: 9068)
      • wg.exe (PID: 2340)
      • wg.exe (PID: 4072)
      • wg.exe (PID: 2220)
      • wg.exe (PID: 8436)
      • msedgewebview2.exe (PID: 1340)
      • wg.exe (PID: 8264)
      • wg.exe (PID: 6804)
      • wg.exe (PID: 6440)
      • wg.exe (PID: 3644)
      • wg.exe (PID: 8196)
      • wg.exe (PID: 6992)
      • wg.exe (PID: 3188)
      • wg.exe (PID: 7992)
      • wg.exe (PID: 7860)
      • wg.exe (PID: 6392)
      • curl.exe (PID: 8140)
      • wg.exe (PID: 7280)
      • msedgewebview2.exe (PID: 1876)
      • wg.exe (PID: 5680)
      • wg.exe (PID: 4604)
      • wireguard.exe (PID: 6332)
      • wg.exe (PID: 8408)
    • Create files in a temporary directory

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • msedgewebview2.exe (PID: 8320)
      • DarkGuard.exe (PID: 8964)
    • The sample compiled with english language support

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • setup.exe (PID: 6332)
      • powershell.exe (PID: 9072)
      • msiexec.exe (PID: 1368)
      • drvinst.exe (PID: 1128)
      • wireguard.exe (PID: 752)
    • Creates files in the program directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 3516)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • setup.exe (PID: 6332)
      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • wireguard.exe (PID: 7204)
      • DarkGuard.exe (PID: 8964)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • MicrosoftEdgeUpdate.exe (PID: 2760)
      • MicrosoftEdgeUpdate.exe (PID: 1044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6644)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6920)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7476)
      • MicrosoftEdgeUpdate.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • MicrosoftEdgeUpdate.exe (PID: 8824)
      • MicrosoftEdgeUpdate.exe (PID: 8788)
      • MicrosoftEdge_X64_144.0.3719.93.exe (PID: 5524)
      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • MicrosoftEdgeUpdate.exe (PID: 5780)
      • DarkGuard.exe (PID: 3636)
      • msedgewebview2.exe (PID: 8320)
      • msedgewebview2.exe (PID: 7636)
      • msedgewebview2.exe (PID: 2252)
      • setup.exe (PID: 6332)
      • msiexec.exe (PID: 1368)
      • msiexec.exe (PID: 7448)
      • wireguard.exe (PID: 8372)
      • msiexec.exe (PID: 1836)
      • wireguard.exe (PID: 7204)
      • wireguard.exe (PID: 7304)
      • DarkGuard.exe (PID: 8964)
      • wireguard.exe (PID: 5448)
      • msedgewebview2.exe (PID: 8824)
      • wireguard.exe (PID: 752)
      • wireguard.exe (PID: 3552)
      • drvinst.exe (PID: 1128)
      • drvinst.exe (PID: 1824)
      • curl.exe (PID: 8140)
      • msedgewebview2.exe (PID: 1876)
      • wireguard.exe (PID: 6332)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 8788)
      • MicrosoftEdgeUpdate.exe (PID: 5780)
      • msedgewebview2.exe (PID: 8320)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • msedgewebview2.exe (PID: 8320)
      • wireguard.exe (PID: 8372)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 7664)
      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • msedgewebview2.exe (PID: 8320)
      • powershell.exe (PID: 9072)
      • slui.exe (PID: 5164)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 3088)
      • setup.exe (PID: 6332)
      • msedgewebview2.exe (PID: 8320)
      • msedgewebview2.exe (PID: 2248)
      • wireguard.exe (PID: 8372)
      • msedgewebview2.exe (PID: 5484)
    • There is functionality for taking screenshot (YARA)

      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
    • Drops script file

      • setup.exe (PID: 6332)
      • powershell.exe (PID: 6896)
      • powershell.exe (PID: 9072)
      • powershell.exe (PID: 2288)
      • powershell.exe (PID: 1092)
    • Creates a software uninstall entry

      • setup.exe (PID: 6332)
      • darkguard_0.1.0_x64-setup.exe (PID: 7392)
      • msiexec.exe (PID: 1368)
    • Creates files or folders in the user directory

      • msedgewebview2.exe (PID: 8320)
      • msedgewebview2.exe (PID: 8556)
      • msedgewebview2.exe (PID: 7636)
      • msiexec.exe (PID: 1368)
      • msedgewebview2.exe (PID: 1876)
    • Reads the machine GUID from the registry

      • msedgewebview2.exe (PID: 8320)
      • msiexec.exe (PID: 1368)
      • wireguard.exe (PID: 8372)
      • wireguard.exe (PID: 7204)
      • drvinst.exe (PID: 1128)
      • msedgewebview2.exe (PID: 1876)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1368)
    • The sample compiled with chinese language support

      • msiexec.exe (PID: 1368)
      • powershell.exe (PID: 9072)
    • Manual execution by a user

      • DarkGuard.exe (PID: 8964)
      • cmd.exe (PID: 8400)
    • Disables trace logs

      • powershell.exe (PID: 9072)
    • Execution of CURL command

      • cmd.exe (PID: 8400)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:08 23:05:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x369f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.1.0.0
ProductVersionNumber: 0.1.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: darkguard
FileVersion: 0.1.0
LegalCopyright: -
ProductName: darkguard
ProductVersion: 0.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
350
Monitored processes
188
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
148"sc" query WireGuardTunnel$cloudflareC:\Windows\System32\sc.exeDarkGuard.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
752"C:\Program Files\WireGuard\wireguard.exe" /tunnelservice C:\Users\admin\AppData\Local\Temp\cloudflare.confC:\Program Files\WireGuard\wireguard.exe
services.exe
User:
SYSTEM
Company:
WireGuard LLC
Integrity Level:
SYSTEM
Description:
WireGuard: Fast, Modern, Secure VPN Tunnel
Exit code:
0
Version:
0.5.3
Modules
Images
c:\program files\wireguard\wireguard.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptbase.dll
876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
888C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1044"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.217.3
Modules
Images
c:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1084"sc" query WireGuardTunnel$cloudflareC:\Windows\System32\sc.exeDarkGuard.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1092"powershell" -NoProfile -Command "Start-Process 'C:\Program Files\WireGuard\wireguard.exe' -ArgumentList '/uninstalltunnelservice', 'cloudflare' -Verb RunAs -WindowStyle Hidden -Wait"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDarkGuard.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1128DrvInst.exe "4" "9" "C:\WINDOWS\Temp\20fd762521a3b73c22f36d3fa26728d7cf2cb03caa0b4be4bab0b5a6fd696395\wireguard.inf" "9" "43f3a2977" "00000000000001CC" "Service-0x0-3e7$\Default" "00000000000001D4" "208" "C:\WINDOWS\Temp\20fd762521a3b73c22f36d3fa26728d7cf2cb03caa0b4be4bab0b5a6fd696395"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1340"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\144.0.3719.93\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\systems.banat.darkguard\EBWebView" --webview-exe-name=DarkGuard.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --skip-read-main-dll --metrics-shmem-handle=4120,i,11456158096244038381,11692542832399373015,524288 --field-trial-handle=1860,i,9190552724943748697,17610928704542699058,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708995682289984 --mojo-platform-channel-handle=4108 /prefetch:8C:\Program Files (x86)\Microsoft\EdgeWebView\Application\144.0.3719.93\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
144.0.3719.93
Modules
Images
c:\program files (x86)\microsoft\edgewebview\application\144.0.3719.93\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edgewebview\application\144.0.3719.93\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
53 162
Read events
50 735
Write events
2 262
Delete events
165

Modification events

(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:delete keyName:(default)
Value:
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\MicrosoftEdgeUpdate.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\MicrosoftEdgeUpdate.exe
Operation:writeName:AppID
Value:
{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:LocalService
Value:
edgeupdate
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:ServiceParameters
Value:
/comsvc
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\edgeupdate
Operation:writeName:EventMessageFile
Value:
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.217.3\msedgeupdate.dll
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}\ProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}\VersionIndependentProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:delete keyName:(default)
Value:
(PID) Process:(1044) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:AppID
Value:
{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Executable files
231
Suspicious files
118
Text files
140
Unknown types
0

Dropped files

PID
Process
Filename
Type
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsw50B0.tmp\modern-header.bmpimage
MD5:368F434F2B74417F540EF920B66F4554
SHA256:518EECCACEFC90B8839F50A36A89EE8B8600039C08CE1EC101D900E2A3EC2DC1
3516MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EU5FF0.tmp\msedgeupdate.dllexecutable
MD5:05A084F88F628C5EAD832619EB9E5E77
SHA256:275F6BF9750EDED145E37B11DFA7C0580C88036E80C21395E8A4A77C66D51090
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsw50B0.tmp\System.dllexecutable
MD5:9B38A1B07A0EBC5C7E59E63346ECC2DB
SHA256:C881253DAFCF1322A771139B1A429EC1E78C507CA81A218A20DC1A4B25ABBFE7
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsw50B0.tmp\modern-wizard.bmpimage
MD5:631227DF085BA169C1EC73327757EE1D
SHA256:E92EC1F4F133E41F1A2010788F05D567DE720A809D5091BBD762EB29FDE8F17C
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsw50B0.tmp\nsDialogs.dllexecutable
MD5:8F0E7415F33843431DF308BB8E06AF81
SHA256:BB49F15FA83452370047A7801E39FC7F64E70C7545B8999BB85AA4749EAA048B
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsw50B0.tmp\NSISdl.dllexecutable
MD5:8EABBE36E8B52E69322780D0F541FD19
SHA256:DDF40229DD9D6B268902D8DEA88C8A04AACF1AF218DD29F6DCD35BABC54AC08D
7392darkguard_0.1.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeexecutable
MD5:2A03C75247273698224AEECC32D71735
SHA256:D75E4FB20D4E8AB50AB77D43C139AA0F654ECCA9C504552761EFB435917A01E5
3516MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EU5FF0.tmp\CopilotUpdate.exeexecutable
MD5:3C709C9F20D2817BA2595B7B22A743B0
SHA256:EEEA69973B36D977F80E5BBBEF3B0B3B914C5E9E52236E4057FBC5EB001FC913
3516MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EU5FF0.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:EC013A26B4CEEA8505B5E06645A4CBF4
SHA256:DCA43FDE8ABDB0C0782F2777E03605C7030A8F415702C48ADDE64A44E07A0711
3516MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EU5FF0.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:229AF2A53A7B3741BE616C1648637D47
SHA256:BC8A862A95852B7D102C99910DABE38DD053E54D7ED8C40743AEB9B6A82AC4E5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
52
TCP/UDP connections
54
DNS requests
40
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
7428
svchost.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
4544
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
4544
SIHClient.exe
GET
200
40.69.42.241:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
4544
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
4544
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7392
darkguard_0.1.0_x64-setup.exe
GET
200
199.232.210.172:80
http://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/6610a652-5edd-4c88-99ad-6d23094fd465/MicrosoftEdgeWebview2Setup.exe
US
executable
1.60 Mb
whitelisted
7392
darkguard_0.1.0_x64-setup.exe
GET
301
88.221.169.205:80
http://go.microsoft.com/fwlink/p/?LinkId=2124703
US
whitelisted
7664
MicrosoftEdgeUpdate.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.217.3?clientId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&appChannel_edgeupdate=6&appConsentState_edgeupdate=0&appDayOfInstall_edgeupdate=0&appInactivityBadgeApplied_edgeupdate=0&appInactivityBadgeCleared_edgeupdate=0&appInactivityBadgeDuration_edgeupdate=0&appInstallTimeDiffSec_edgeupdate=0&appIsPinnedSystem_edgeupdate=false&appLastLaunchCount_edgeupdate=0&appLastLaunchTime_edgeupdate=0&appLastLaunchTimeJson_edgeupdate=0&appLastLaunchTimeDaysAgo_edgeupdate=0&appVersion_edgeupdate=1.3.217.3&appUpdateCheckIsUpdateDisabled_edgeupdate=false&appUpdatesAllowedForMeteredNetworks_edgeupdate=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=6&hwPhysmemory=6&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=DELL&oemProductName=DELL&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.4046&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=otherinstallcmd&requestIsMachine=true&requestOmahaShellVersion=1.3.217.3&requestOmahaVersion=1.3.217.3
US
text
430 b
unknown
8788
MicrosoftEdgeUpdate.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.217.3?clientId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4
US
text
415 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7428
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
876
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7392
darkguard_0.1.0_x64-setup.exe
88.221.169.205:80
go.microsoft.com
AKAMAI-AS
US
whitelisted
7392
darkguard_0.1.0_x64-setup.exe
199.232.210.172:80
msedge.sf.dl.delivery.mp.microsoft.com
FASTLY
US
whitelisted
7664
MicrosoftEdgeUpdate.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8788
MicrosoftEdgeUpdate.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
self.events.data.microsoft.com
  • 13.69.239.79
  • 20.189.173.23
whitelisted
google.com
  • 142.251.140.174
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.248
whitelisted
go.microsoft.com
  • 88.221.169.205
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
config.edge.skype.com
  • 150.171.22.17
  • 52.123.224.68
  • 52.123.224.74
  • 52.123.243.79
whitelisted
msedge.api.cdp.microsoft.com
  • 74.178.76.44
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.65
  • 20.190.160.3
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.68
  • 20.190.160.14
  • 40.126.32.138
  • 20.190.160.67
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted

Threats

PID
Process
Class
Message
7392
darkguard_0.1.0_x64-setup.exe
Misc activity
ET INFO Packed Executable Download
7428
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
6756
svchost.exe
Misc activity
ET INFO Packed Executable Download
9072
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\systems.banat.darkguard directory exists )
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\systems.banat.darkguard\EBWebView directory exists )
msedgewebview2.exe
[0202/215847.875:ERROR:third_party\crashpad\crashpad\util\win\exception_handler_server.cc:529] ConnectNamedPipe: The pipe is being closed. (0xE8)