download:

/fr/driver-booster.php

Full analysis: https://app.any.run/tasks/6cc128bb-317b-4ac0-bbd3-e6ca1aa847ec
Verdict: Malicious activity
Analysis date: September 07, 2024, 10:20:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: text/html
File info: HTML document, Unicode text, UTF-8 text, with very long lines (882), with CRLF line terminators
MD5:

F22E0BF530CCA2103962F1BE472E8DFB

SHA1:

278D743A561D562485C4C866511ACEA23EFF4F0F

SHA256:

2904C602B9E9B778AF2DD822C4D1B5896C30B3B963C55D4C6C4BF0338E23D298

SSDEEP:

1536:989zyCnToDONg6tk3GvlrS0Sl03Ky6pXs97n1l:/C8CNnmGHKPk7n1l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs injected code in another process

      • ICONPIN64.exe (PID: 780)
    • Application was injected by another process

      • explorer.exe (PID: 4552)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • driver_booster_setup_trial.exe (PID: 3832)
      • driver_booster_setup_trial.exe (PID: 892)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.exe (PID: 5264)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • HWiNFO.exe (PID: 4784)
      • AutoUpdate.exe (PID: 6924)
      • onlinesr_en.exe (PID: 6488)
    • Reads security settings of Internet Explorer

      • driver_booster_setup_trial.tmp (PID: 7012)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • setup.exe (PID: 6020)
      • DriverBooster.exe (PID: 6500)
      • ScanWinUpd.exe (PID: 5244)
      • AUpdate.exe (PID: 3144)
      • ScanWinUpd.exe (PID: 6244)
      • AutoUpdate.exe (PID: 6924)
      • Manta.exe (PID: 304)
    • Reads the Windows owner or organization settings

      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.tmp (PID: 5276)
    • Process drops SQLite DLL files

      • driver_booster_setup_trial.tmp (PID: 5276)
    • Process drops legitimate windows executable

      • driver_booster_setup_trial.tmp (PID: 5276)
      • Backup.exe (PID: 6004)
    • Drops 7-zip archiver for unpacking

      • driver_booster_setup_trial.tmp (PID: 5276)
    • Drops a system driver (possible attempt to evade defenses)

      • HWiNFO.exe (PID: 4784)
    • Write to the desktop.ini file (may be used to cloak folders)

      • SetupHlp.exe (PID: 5144)
    • Searches for installed software

      • InstStat.exe (PID: 4976)
      • setup.exe (PID: 6020)
      • DriverBooster.exe (PID: 6500)
      • onlinesr_en.exe (PID: 6488)
      • dllhost.exe (PID: 3852)
    • Checks Windows Trust Settings

      • DriverBooster.exe (PID: 6500)
      • AutoUpdate.exe (PID: 6924)
      • drvinst.exe (PID: 6224)
    • Adds/modifies Windows certificates

      • DriverBooster.exe (PID: 6500)
    • Checks for Java to be installed

      • DriverBooster.exe (PID: 6500)
    • Checks for external IP

      • onlinesr_en.exe (PID: 6488)
      • svchost.exe (PID: 2256)
    • There is functionality for communication over UDP network (YARA)

      • DriverBooster.exe (PID: 6500)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7132)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6224)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 2384)
      • driver_booster_setup_trial.tmp (PID: 7012)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • setup.exe (PID: 6020)
      • identity_helper.exe (PID: 6492)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • HWiNFO.exe (PID: 4784)
      • SetupHlp.exe (PID: 5144)
      • InstStat.exe (PID: 4976)
      • DriverBooster.exe (PID: 6500)
      • SetupHlp.exe (PID: 3112)
      • Manta.exe (PID: 6252)
      • AutoUpdate.exe (PID: 6924)
      • NoteIcon.exe (PID: 6000)
      • Manta.exe (PID: 7080)
      • Manta.exe (PID: 3672)
      • SetupHlp.exe (PID: 5476)
      • ScanWinUpd.exe (PID: 5244)
      • DBDownloader.exe (PID: 3964)
      • Manta.exe (PID: 5276)
      • Manta.exe (PID: 4392)
      • DBDownloader.exe (PID: 6128)
      • AUpdate.exe (PID: 3144)
      • Manta.exe (PID: 936)
      • ScanWinUpd.exe (PID: 6244)
      • DriverBooster.exe (PID: 2476)
      • onlinesr_en.exe (PID: 6488)
      • Manta.exe (PID: 304)
      • Manta.exe (PID: 884)
      • Manta.exe (PID: 7056)
      • identity_helper.exe (PID: 3672)
      • Manta.exe (PID: 460)
      • Manta.exe (PID: 740)
      • Manta.exe (PID: 4040)
      • Manta.exe (PID: 236)
      • Manta.exe (PID: 5508)
      • DpInstX64.exe (PID: 5612)
      • drvinst.exe (PID: 6224)
      • Manta.exe (PID: 7064)
    • Checks supported languages

      • identity_helper.exe (PID: 2384)
      • driver_booster_setup_trial.exe (PID: 3832)
      • driver_booster_setup_trial.tmp (PID: 7012)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.exe (PID: 892)
      • identity_helper.exe (PID: 6492)
      • setup.exe (PID: 6020)
      • driver_booster_setup_trial.exe (PID: 5264)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • SetupHlp.exe (PID: 5144)
      • HWiNFO.exe (PID: 4784)
      • RttHlp.exe (PID: 6452)
      • InstStat.exe (PID: 4976)
      • ICONPIN64.exe (PID: 780)
      • SetupHlp.exe (PID: 3112)
      • Manta.exe (PID: 6252)
      • AutoUpdate.exe (PID: 6924)
      • DriverBooster.exe (PID: 6500)
      • ChangeIcon.exe (PID: 6452)
      • RttHlp.exe (PID: 1688)
      • NoteIcon.exe (PID: 6000)
      • Manta.exe (PID: 7080)
      • Manta.exe (PID: 3672)
      • SetupHlp.exe (PID: 5476)
      • FaultFixes.exe (PID: 6600)
      • FaultFixes.exe (PID: 4276)
      • RttHlp.exe (PID: 1748)
      • AUpdate.exe (PID: 3144)
      • ScanWinUpd.exe (PID: 5244)
      • Manta.exe (PID: 4392)
      • DBDownloader.exe (PID: 6128)
      • Manta.exe (PID: 5276)
      • ScanWinUpd.exe (PID: 6244)
      • DBDownloader.exe (PID: 3964)
      • Manta.exe (PID: 936)
      • onlinesr_en.exe (PID: 6488)
      • ChangeIcon.exe (PID: 6404)
      • DriverBooster.exe (PID: 2476)
      • ChangeIcon.exe (PID: 936)
      • ChangeIcon.exe (PID: 2724)
      • rma.exe (PID: 5164)
      • Manta.exe (PID: 884)
      • Manta.exe (PID: 304)
      • Manta.exe (PID: 7056)
      • identity_helper.exe (PID: 3672)
      • ChangeIcon.exe (PID: 6324)
      • Manta.exe (PID: 5508)
      • Manta.exe (PID: 236)
      • Manta.exe (PID: 740)
      • Manta.exe (PID: 4040)
      • Manta.exe (PID: 460)
      • DpInstX64.exe (PID: 5612)
      • ChangeIcon.exe (PID: 5504)
      • drvinst.exe (PID: 6224)
      • Backup.exe (PID: 6004)
      • Manta.exe (PID: 7064)
    • The process uses the downloaded file

      • iexplore.exe (PID: 6744)
      • msedge.exe (PID: 5772)
      • msedge.exe (PID: 6988)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • setup.exe (PID: 6020)
      • DriverBooster.exe (PID: 6500)
      • AutoUpdate.exe (PID: 6924)
      • explorer.exe (PID: 4552)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6988)
      • msedge.exe (PID: 4644)
    • Reads Environment values

      • identity_helper.exe (PID: 2384)
      • identity_helper.exe (PID: 6492)
      • identity_helper.exe (PID: 3672)
    • Application launched itself

      • msedge.exe (PID: 6988)
      • msedge.exe (PID: 2612)
      • msedge.exe (PID: 1184)
    • Create files in a temporary directory

      • driver_booster_setup_trial.exe (PID: 3832)
      • driver_booster_setup_trial.exe (PID: 892)
      • setup.exe (PID: 6020)
      • driver_booster_setup_trial.exe (PID: 5264)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • HWiNFO.exe (PID: 4784)
      • ICONPIN64.exe (PID: 780)
      • explorer.exe (PID: 4552)
      • DriverBooster.exe (PID: 6500)
      • Backup.exe (PID: 6004)
      • DpInstX64.exe (PID: 5612)
    • Process checks computer location settings

      • driver_booster_setup_trial.tmp (PID: 7012)
      • driver_booster_setup_trial.tmp (PID: 7056)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • setup.exe (PID: 6020)
      • DriverBooster.exe (PID: 6500)
      • AutoUpdate.exe (PID: 6924)
    • Reads the software policy settings

      • slui.exe (PID: 6796)
      • DriverBooster.exe (PID: 6500)
      • AutoUpdate.exe (PID: 6924)
      • slui.exe (PID: 7160)
      • drvinst.exe (PID: 6224)
    • Creates files in the program directory

      • setup.exe (PID: 6020)
      • driver_booster_setup_trial.tmp (PID: 5276)
      • SetupHlp.exe (PID: 5144)
      • RttHlp.exe (PID: 6452)
      • InstStat.exe (PID: 4976)
      • DriverBooster.exe (PID: 6500)
      • Manta.exe (PID: 6252)
      • AutoUpdate.exe (PID: 6924)
      • ChangeIcon.exe (PID: 6452)
      • DBDownloader.exe (PID: 6128)
      • onlinesr_en.exe (PID: 6488)
      • Manta.exe (PID: 304)
      • Backup.exe (PID: 6004)
    • Sends debugging messages

      • setup.exe (PID: 6020)
      • ICONPIN64.exe (PID: 780)
      • InstStat.exe (PID: 4976)
      • explorer.exe (PID: 4552)
      • DriverBooster.exe (PID: 6500)
      • Manta.exe (PID: 6252)
      • ChangeIcon.exe (PID: 6452)
      • AutoUpdate.exe (PID: 6924)
      • Manta.exe (PID: 3672)
      • NoteIcon.exe (PID: 6000)
      • Manta.exe (PID: 7080)
      • RttHlp.exe (PID: 1748)
      • Manta.exe (PID: 4392)
      • Manta.exe (PID: 5276)
      • ChangeIcon.exe (PID: 6404)
      • Manta.exe (PID: 936)
      • onlinesr_en.exe (PID: 6488)
      • ChangeIcon.exe (PID: 936)
      • ChangeIcon.exe (PID: 2724)
      • Manta.exe (PID: 304)
      • Manta.exe (PID: 884)
      • Manta.exe (PID: 7056)
      • ChangeIcon.exe (PID: 6324)
      • Manta.exe (PID: 740)
      • Manta.exe (PID: 460)
      • Manta.exe (PID: 4040)
      • Manta.exe (PID: 236)
      • Manta.exe (PID: 5508)
      • Backup.exe (PID: 6004)
      • Manta.exe (PID: 7064)
      • ChangeIcon.exe (PID: 5504)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6020)
      • explorer.exe (PID: 4552)
      • InstStat.exe (PID: 4976)
      • DriverBooster.exe (PID: 6500)
      • FaultFixes.exe (PID: 4276)
      • AUpdate.exe (PID: 3144)
      • DpInstX64.exe (PID: 5612)
      • Backup.exe (PID: 6004)
    • Creates a software uninstall entry

      • driver_booster_setup_trial.tmp (PID: 5276)
    • Reads the machine GUID from the registry

      • ICONPIN64.exe (PID: 780)
      • DriverBooster.exe (PID: 6500)
      • DBDownloader.exe (PID: 3964)
      • AutoUpdate.exe (PID: 6924)
      • onlinesr_en.exe (PID: 6488)
      • drvinst.exe (PID: 6224)
    • Reads CPU info

      • DriverBooster.exe (PID: 6500)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4552)
    • Checks proxy server information

      • ScanWinUpd.exe (PID: 5244)
      • DriverBooster.exe (PID: 6500)
      • AUpdate.exe (PID: 3144)
      • ScanWinUpd.exe (PID: 6244)
      • slui.exe (PID: 7160)
    • Manual execution by a user

      • DriverBooster.exe (PID: 2476)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

HTTPEquivXUACompatible: IE=edge
Viewport: width=device-width, initial-scale=1
Title: IObit Driver Booster 11 Free - Meilleur logiciel de mise à jour des pilotes gratuit pour windows
Description: Driver Bosster 11 free, logiciel pour mettre à jour les pilotes gratuit, vous permet de mettre à jour tous les pilotes obsolètes gratuitement sur Windows. Téléchargez Driver Booster 11 Free maintenant pour une mise à jour de drivers gratuite et rapide !
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
308
Monitored processes
170
Malicious processes
10
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs driver_booster_setup_trial.exe driver_booster_setup_trial.tmp no specs driver_booster_setup_trial.exe driver_booster_setup_trial.tmp msedge.exe msedge.exe no specs slui.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe driver_booster_setup_trial.exe driver_booster_setup_trial.tmp hwinfo.exe setuphlp.exe no specs rtthlp.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs iconpin64.exe inststat.exe THREAT driverbooster.exe setuphlp.exe no specs manta.exe autoupdate.exe changeicon.exe noteicon.exe rtthlp.exe no specs manta.exe manta.exe scanwinupd.exe faultfixes.exe no specs faultfixes.exe no specs rtthlp.exe setuphlp.exe no specs aupdate.exe manta.exe manta.exe dbdownloader.exe scanwinupd.exe dbdownloader.exe changeicon.exe manta.exe onlinesr_en.exe rma.exe no specs svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs driverbooster.exe no specs changeicon.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs changeicon.exe manta.exe msedge.exe no specs msedge.exe no specs manta.exe manta.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs changeicon.exe manta.exe manta.exe manta.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs manta.exe manta.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs backup.exe dpinstx64.exe no specs drvinst.exe no specs msedge.exe no specs msedge.exe no specs changeicon.exe manta.exe msedge.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
208"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6612 --field-trial-handle=2192,i,5754902200168932700,9970079759344099136,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
236"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe" /CommStat /DoCommStat /Code="a160" /Days=0C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe
DriverBooster.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Manta
Exit code:
0
Version:
11.2.0.11
Modules
Images
c:\program files (x86)\iobit\driver booster\11.6.0\manta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
304"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe" /appgoto /to="trialbuy_10" /base /promote /tdataC:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe
DriverBooster.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Manta
Exit code:
0
Version:
11.2.0.11
Modules
Images
c:\program files (x86)\iobit\driver booster\11.6.0\manta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
460"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe" /CommStat /DoCommStat /Code="b160" /Days=7C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe
DriverBooster.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Manta
Exit code:
0
Version:
11.2.0.11
Modules
Images
c:\program files (x86)\iobit\driver booster\11.6.0\manta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3924 --field-trial-handle=2260,i,6612400154005919245,1043863189746519876,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6472 --field-trial-handle=2260,i,6612400154005919245,1043863189746519876,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5420 --field-trial-handle=2260,i,6612400154005919245,1043863189746519876,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5456 --field-trial-handle=2336,i,6152879397347264196,15518548025493663482,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
740"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe" /CommStat /DoCommStat /Code="a160" /Days=0C:\Program Files (x86)\IObit\Driver Booster\11.6.0\Manta.exe
DriverBooster.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Manta
Exit code:
0
Version:
11.2.0.11
Modules
Images
c:\program files (x86)\iobit\driver booster\11.6.0\manta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
780"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\TaskbarPin\ICONPIN64.exe" pin "C:\Program Files (x86)\IObit\Driver Booster\11.6.0\DriverBooster.exe"C:\Program Files (x86)\IObit\Driver Booster\11.6.0\TaskbarPin\ICONPIN64.exe
driver_booster_setup_trial.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Icon Pin
Exit code:
0
Version:
1.0.0.22
Modules
Images
c:\program files (x86)\iobit\driver booster\11.6.0\taskbarpin\iconpin64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
46 576
Read events
46 200
Write events
342
Delete events
34

Modification events

(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000013039A
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(6744) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(6988) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6988) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6988) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
Executable files
174
Suspicious files
682
Text files
614
Unknown types
21

Dropped files

PID
Process
Filename
Type
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF12a1a7.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF12a1b6.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF12a1b6.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF12a1f5.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF12a1e5.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF12a1e5.TMP
MD5:
SHA256:
6988msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
123
TCP/UDP connections
242
DNS requests
168
Threats
62

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2108
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6012
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2636
svchost.exe
HEAD
200
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3f7756bd-b1cc-4d5e-96d8-fd938a5c5bb6?P1=1725978298&P2=404&P3=2&P4=OsQqPoE9Su2okUE94dLdU2k5c%2fMuzK7731GfElmPsG%2brgcrAbraOQHrVVHgufu3QcCvAl7fiwCOHySn0%2faGUfw%3d%3d
unknown
whitelisted
6456
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6456
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2636
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3f7756bd-b1cc-4d5e-96d8-fd938a5c5bb6?P1=1725978298&P2=404&P3=2&P4=OsQqPoE9Su2okUE94dLdU2k5c%2fMuzK7731GfElmPsG%2brgcrAbraOQHrVVHgufu3QcCvAl7fiwCOHySn0%2faGUfw%3d%3d
unknown
whitelisted
2636
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3f7756bd-b1cc-4d5e-96d8-fd938a5c5bb6?P1=1725978298&P2=404&P3=2&P4=OsQqPoE9Su2okUE94dLdU2k5c%2fMuzK7731GfElmPsG%2brgcrAbraOQHrVVHgufu3QcCvAl7fiwCOHySn0%2faGUfw%3d%3d
unknown
whitelisted
2636
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3f7756bd-b1cc-4d5e-96d8-fd938a5c5bb6?P1=1725978298&P2=404&P3=2&P4=OsQqPoE9Su2okUE94dLdU2k5c%2fMuzK7731GfElmPsG%2brgcrAbraOQHrVVHgufu3QcCvAl7fiwCOHySn0%2faGUfw%3d%3d
unknown
whitelisted
6988
msedge.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
6988
msedge.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
568
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6012
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4644
msedge.exe
13.107.246.42:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6988
msedge.exe
239.255.255.250:1900
whitelisted
4644
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4644
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4644
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4644
msedge.exe
94.245.104.56:443
api.edgeoffer.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.42
whitelisted
api.edgeoffer.microsoft.com
  • 94.245.104.56
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
fonts.googleapis.com
  • 172.217.23.106
whitelisted
bzib.nelreports.net
  • 2.19.126.145
  • 2.19.126.152
  • 23.48.23.51
  • 23.48.23.26
whitelisted
fonts.gstatic.com
  • 216.58.206.35
  • 172.217.18.3
whitelisted
www.googletagmanager.com
  • 142.250.184.200
whitelisted

Threats

PID
Process
Class
Message
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6020
setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
4976
InstStat.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6924
AutoUpdate.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6924
AutoUpdate.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6924
AutoUpdate.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
Process
Message
setup.exe
[DBInstaller] : + FormCreate
setup.exe
time1
setup.exe
doFinshedEvent_Freeware 0
setup.exe
time3
setup.exe
Order: itop
setup.exe
ProductVersion: 11.6.0.128
setup.exe
Chk_ver_min
setup.exe
Chk_ver_max
setup.exe
CheckSameVerList
setup.exe
CheckLicense