File name:

Resource Hacker - CHIP Installer _8aR5p.exe

Full analysis: https://app.any.run/tasks/39e0940f-b80b-4b40-ba5d-ca5a46a8ad7c
Verdict: Malicious activity
Analysis date: July 15, 2024, 13:29:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

F5980F17F44DA870072C5CE396EB01BF

SHA1:

22CE208ACB16875CDD9D42A794557A56068220C2

SHA256:

2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B

SSDEEP:

49152:xhx7dxx15qe01xtgx41J/StY/yuiYWLmgpaRZkDuZdTNACtn:JV1JALgvz4ACtn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • reshacker_setup_527.exe (PID: 6392)
      • reshacker_setup_527.tmp (PID: 6368)
    • Actions looks like stealing of personal data

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Scans artifacts that could help determine the target

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
  • SUSPICIOUS

    • Changes Internet Explorer settings (feature browser emulation)

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Reads security settings of Internet Explorer

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • ResourceHacker.exe (PID: 3724)
    • Searches for installed software

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Reads Microsoft Outlook installation path

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Checks Windows Trust Settings

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Reads Internet Explorer settings

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Executable content was dropped or overwritten

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • reshacker_setup_527.tmp (PID: 6368)
      • reshacker_setup_527.exe (PID: 6392)
    • Reads the Windows owner or organization settings

      • reshacker_setup_527.tmp (PID: 6368)
    • Creates file in the systems drive root

      • ResourceHacker.exe (PID: 3724)
  • INFO

    • Checks supported languages

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • reshacker_setup_527.tmp (PID: 6368)
      • ResourceHacker.exe (PID: 3724)
      • identity_helper.exe (PID: 6296)
      • reshacker_setup_527.exe (PID: 6392)
    • Reads the computer name

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • reshacker_setup_527.tmp (PID: 6368)
      • ResourceHacker.exe (PID: 3724)
      • identity_helper.exe (PID: 6296)
    • Reads the software policy settings

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • slui.exe (PID: 6988)
      • slui.exe (PID: 1332)
    • Checks proxy server information

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • ResourceHacker.exe (PID: 3724)
      • slui.exe (PID: 1332)
    • Create files in a temporary directory

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
      • reshacker_setup_527.tmp (PID: 6368)
      • reshacker_setup_527.exe (PID: 6392)
    • Reads the machine GUID from the registry

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Creates files or folders in the user directory

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Process checks Internet Explorer phishing filters

      • Resource Hacker - CHIP Installer _8aR5p.exe (PID: 6044)
    • Creates a software uninstall entry

      • reshacker_setup_527.tmp (PID: 6368)
    • Creates files in the program directory

      • reshacker_setup_527.tmp (PID: 6368)
    • Reads Environment values

      • ResourceHacker.exe (PID: 3724)
    • Reads Microsoft Office registry keys

      • ResourceHacker.exe (PID: 3724)
      • msedge.exe (PID: 2216)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 6672)
    • Manual execution by a user

      • msedge.exe (PID: 2216)
    • Application launched itself

      • msedge.exe (PID: 2216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (49.6)
.exe | DOS Executable Generic (49.5)
.vxd | VXD Driver (0.7)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:04:16 09:34:08+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 4237824
InitializedDataSize: 1083392
UninitializedDataSize: -
EntryPoint: 0x3f8020
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 1.0.100.6
ProductVersionNumber: 1.0.100.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: CHIP Digital GmbH
FileDescription: CHIP Secured Installer
FileVersion: 1.0.100.6
LegalCopyright: Copyright 2021 CHIP Digital GmbH
ProductName: LgInstall
ProductVersion: 1.0.100.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
63
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start resource hacker - chip installer _8ar5p.exe sppextcomobj.exe no specs slui.exe reshacker_setup_527.exe reshacker_setup_527.tmp resourcehacker.exe no specs slui.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs resource hacker - chip installer _8ar5p.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7172 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
764"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7140 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1060"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ec,0x2f0,0x2f4,0x2e8,0x2fc,0x7ffd9e115fd8,0x7ffd9e115fe4,0x7ffd9e115ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1292"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=3880 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1332C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1924"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7252 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1968"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6012 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3628 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.google.de/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2276"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=6500 --field-trial-handle=2316,i,12123414416359469994,11201344874610396558,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
29 994
Read events
29 708
Write events
264
Delete events
22

Modification events

(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:Resource Hacker - CHIP Installer _8aR5p.exe
Value:
11000
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6044) Resource Hacker - CHIP Installer _8aR5p.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6368) reshacker_setup_527.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E018000075DA500ABBD6DA01
(PID) Process:(6368) reshacker_setup_527.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
6652FE54258FCA088DE3E89FA564E99F8A37C67084434A582121FC8D37471636
Executable files
26
Suspicious files
680
Text files
227
Unknown types
17

Dropped files

PID
Process
Filename
Type
6044Resource Hacker - CHIP Installer _8aR5p.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\PPD_Bit-Driver-Updater_1[1].pngimage
MD5:4FA788C006BA2C165DFB15A20DD408D8
SHA256:AA0A1A9E282167A2A8BA84CED85760DF64311B6A2F60BF44E7BB17AAD3780C95
6044Resource Hacker - CHIP Installer _8aR5p.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\easyprogresscampaign-progress-bitsolucians[1].htmhtml
MD5:9B2AFFEC375CD2607511F8E77AF8923F
SHA256:93FB2064AA42B2FDF959CA019217604C68478AB1A6A03C803F6AFDAB5C7027F6
6044Resource Hacker - CHIP Installer _8aR5p.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E5CE0DC33338C2049C0E8893A179720Ebinary
MD5:9A3F5EB482CD9996C82E198ACA36212D
SHA256:914F20408CC02BC01522905E5A5969FDE42D241502A4064E5EAE362F05332C4E
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\unins000.exeexecutable
MD5:55ABBAA40E0EAEACAABAD31EAF9692A0
SHA256:120CFAFB05CAC4650CB299F05A38422580F0ED6B15BD495D46CF40216C8200F2
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\is-2D2RC.tmpexecutable
MD5:55ABBAA40E0EAEACAABAD31EAF9692A0
SHA256:120CFAFB05CAC4650CB299F05A38422580F0ED6B15BD495D46CF40216C8200F2
6368reshacker_setup_527.tmpC:\Users\admin\AppData\Local\Temp\is-6QB84.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\is-98O32.tmphtml
MD5:54B8AE8D24A96FA2409C79BD0A17BBF9
SHA256:054AFA57B9C062C176C9E652C854A3A22D5AB2A72C787B6E4CACBD675D19104A
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\ResourceHacker.exeexecutable
MD5:263B8A401528B440657BBDFFC64C6487
SHA256:1227E484F32C34F026F311E60F1ABAE065E00F203153DBF0623152DEDF5CAFBD
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\is-PB4NF.tmptext
MD5:538F09449B7FFC050FB12C809431032C
SHA256:F0E3B4D80329CECCC0A86B1A8C4C36410245DDB1DE3D4EF80CD7DB8CF4E59EC8
6368reshacker_setup_527.tmpC:\Program Files (x86)\Resource Hacker\ReadMe.txttext
MD5:538F09449B7FFC050FB12C809431032C
SHA256:F0E3B4D80329CECCC0A86B1A8C4C36410245DDB1DE3D4EF80CD7DB8CF4E59EC8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
204
DNS requests
175
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7128
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7128
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3032
svchost.exe
GET
304
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3716
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6044
Resource Hacker - CHIP Installer _8aR5p.exe
GET
200
2.16.202.114:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgP%2FTrdGuXxbcSOe1t%2B0db79LQ%3D%3D
unknown
whitelisted
4392
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6044
Resource Hacker - CHIP Installer _8aR5p.exe
GET
200
2.16.202.114:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgQ3yyeRD4b7hBj%2FX2Li0MzZMg%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2248
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4656
SearchApp.exe
23.53.43.147:443
www.bing.com
Akamai International B.V.
DE
unknown
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4656
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6044
Resource Hacker - CHIP Installer _8aR5p.exe
83.125.106.237:443
chip-cluster.de
3U TELECOM GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 23.53.43.147
  • 23.53.43.96
  • 23.53.43.106
  • 23.53.43.122
  • 13.107.21.200
  • 204.79.197.200
  • 2.16.110.121
  • 2.16.110.170
  • 2.16.110.171
  • 2.16.110.176
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 95.101.149.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
chip-cluster.de
  • 83.125.106.237
unknown
login.live.com
  • 20.190.159.73
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.23
  • 20.190.159.75
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.23
whitelisted

Threats

PID
Process
Class
Message
6864
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6864
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info