General Info

URL

https://filezilla-project.org/download.php?type=client

Full analysis
https://app.any.run/tasks/5a39af33-3e5b-4044-8fe7-6e9f78b1de16
Verdict
Malicious activity
Analysis date
1/10/2019, 22:08:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
adware
installcore
pup
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 3728)
Loads dropped or rewritten executable
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 3728)
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Changes settings of System certificates
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Connects to CnC server
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
INSTALLCORE was detected
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Creates files in the program directory
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Adds / modifies Windows certificates
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Reads the date of Windows installation
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Reads Environment values
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Reads the machine GUID from the registry
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Reads Windows Product ID
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Executable content was dropped or overwritten
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 3728)
  • iexplore.exe (PID: 2948)
  • iexplore.exe (PID: 3096)
Reads internet explorer settings
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Reads CPU info
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 1332)
Application launched itself
  • FileZilla_3.39.0_win32-setup_bundled[1].exe (PID: 3728)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2948)
  • iexplore.exe (PID: 3096)
Changes settings of System certificates
  • iexplore.exe (PID: 2948)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 2948)
Changes internet zones settings
  • iexplore.exe (PID: 2948)
Creates files in the user directory
  • iexplore.exe (PID: 3096)
Reads settings of System Certificates
  • iexplore.exe (PID: 3096)
  • iexplore.exe (PID: 2948)
Reads internet explorer settings
  • iexplore.exe (PID: 3096)
Application launched itself
  • iexplore.exe (PID: 2948)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
37
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

+
drop and start start iexplore.exe iexplore.exe filezilla_3.39.0_win32-setup_bundled[1].exe #INSTALLCORE filezilla_3.39.0_win32-setup_bundled[1].exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2948
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\filezilla_3.39.0_win32-setup_bundled[1].exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\mssprxy.dll

PID
3096
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2948 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\jscript.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll

PID
3728
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Tim Kosse
Description
FileZilla FTP Client
Version
3.39.0
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\filezilla_3.39.0_win32-setup_bundled[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\nsvd1d.tmp\system.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\nsvd1d.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
1332
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe" /UAC:401DE /NCRC
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe
Indicators
Parent process
FileZilla_3.39.0_win32-setup_bundled[1].exe
User
admin
Integrity Level
HIGH
Version:
Company
Tim Kosse
Description
FileZilla FTP Client
Version
3.39.0
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\filezilla_3.39.0_win32-setup_bundled[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\system.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\userinfo.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\inetc.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\nsh1115.tmp\fusion.dll
c:\windows\system32\mpr.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\dhcpcsvc.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\imagehlp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\sxs.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll

Registry activity

Total events
1257
Read events
1161
Write events
92
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2948
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
2948
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
2948
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{DA3B3C6D-151B-11E9-91D7-5254004A04AF}
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307010004000A001500080013000003
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307010004000A001500080013000003
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307010004000A00150008001300BC03
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
11
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307010004000A001500080014000300
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
48
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307010004000A001500080014001C01
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
19
2948
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2948
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307010004000A00150009000100670000000000
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019011020190111
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CachePrefix
:2019011020190111:
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheLimit
8192
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheOptions
11
2948
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheRepair
0
3096
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
3096
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019011020190111
3096
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CachePrefix
:2019011020190111:
3096
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheLimit
8192
3096
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheOptions
11
3096
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheRepair
0
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Name
FileZilla_3.39.0_win32-setup_bundled[1].exe
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
ID
1481493048

Files activity

Executable files
10
Suspicious files
0
Text files
97
Unknown types
2

Dropped files

PID
Process
Filename
Type
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe
executable
MD5: 91b53026267ba8f38c21f8ab856648b4
SHA256: 0d21084ba66020906561367b7fd3fc204065bcfdb56678e1396cb4d32df92b9b
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\nsDialogs.dll
executable
MD5: 42b064366f780c1f298fa3cb3aeae260
SHA256: c13104552b8b553159f50f6e2ca45114493397a6fa4bf2cbb960c4a2bbd349ab
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\UserInfo.dll
executable
MD5: 1b446b36f5b4022d50ffdc0cf567b24a
SHA256: 2862c7bc7f11715cebdea003564a0d70bf42b73451e2b672110e1392ec392922
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\Fusion.dll
executable
MD5: a8b102ddcf25af2c5bdb541b34ef8da6
SHA256: 11446e839464efb0acc862e50dc24ae025811bd2d46f119e32c577e6cebb2c81
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
3728
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsvD1D.tmp\UAC.dll
executable
MD5: adb29e6b186daa765dc750128649b63d
SHA256: 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
3728
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsvD1D.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\FileZilla_3.39.0_win32-setup_bundled[1].exe
executable
MD5: 91b53026267ba8f38c21f8ab856648b4
SHA256: 0d21084ba66020906561367b7fd3fc204065bcfdb56678e1396cb4d32df92b9b
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\UAC.dll
executable
MD5: adb29e6b186daa765dc750128649b63d
SHA256: 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\INetC.dll
executable
MD5: 640bff73a5f8e37b202d911e4749b2e9
SHA256: c1e568e25ec111184deb1b87cfda4bfec529b1abeab39b66539d998012f33502
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\DE.locale
text
MD5: ac99de234c1c7dff173e1be6507d2b50
SHA256: 5f5f05b25b6f44af38ae2fabb99b1bb3f4cc9413e2275b2998b0d3771286737f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\TR.locale
text
MD5: 9456c52aed7848fb1ff6d05de42e8391
SHA256: dd4e1cbeabc982697c1d4227f4c8cd18413351a279962a40041cafe3e427b036
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\UZ.locale
text
MD5: d7bb18debd6ae4b95ca1128a01550970
SHA256: 816b2817affbeb1d634235c0d901bdf45504da18527b5cce6895b4cf8cf8e7ba
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\TE.locale
text
MD5: 4c04155e36f1c718a97bcf3f4ba20697
SHA256: a85fdcd0a5fbc7b09f1401a343f2c7d334caac8d7dfbd0d3bfca20a9fd76d7ec
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\TH.locale
text
MD5: 02b331449294adfdbbafa59074e4984c
SHA256: c53cf743d7169e2d17433d5f123ac45a672d415484fed6af4cbe0f8441b88515
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\TL.locale
text
MD5: 4685406c7549ce5fcb79fae49c013dec
SHA256: 107c995c36d3412886613b05e62bf27c8941b106912c2ed9e9ac54b7240f7524
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\SV.locale
text
MD5: d9fd720403c7b8c786224b693c6331ad
SHA256: f7361ffcba975398338a814f1f061720064d58fd838d2b8879f1b3e6dc5138aa
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\SR.locale
text
MD5: af688f29d4745ac3d641017da91ef575
SHA256: bb47f7a85af70aedbb61c86c7ed7199aafb823350b185722468f7a6d492b2632
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\SK.locale
text
MD5: 405b3c6f0e68d2db60d1585385896623
SHA256: ee1ce5e2bfe867f5600c4a15c47b9d319e23046de25bee4c21b1171bb21a9623
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\SQ.locale
text
MD5: 393bf5a36c36bd97b7f206a13d602827
SHA256: a6b643c1d26d2a9d13c94c147ba35a520b749c40af3e729910fa99eb636fc63b
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\RO.locale
text
MD5: 44652248cbb99cea6dd8f5613b874cfa
SHA256: 57a1b5998c567221f90bfd66f42161273ddd60f52418de1fc939e9c86a51cef9
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\RU.locale
text
MD5: 84c7cb5b39f47ab1cd80ce1f0c25921e
SHA256: 8012719a70324556c482dd3598ba2ed2f959d5dec8a6db44faa421ef672becca
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\SL.locale
text
MD5: 84cc837239842449c8ff335b165c07e6
SHA256: bbe36fcc8d9404395a3e85f76479a6f4f4ec67106e53ad93a3d70747e5157a3d
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\PT.locale
text
MD5: 49b6cd7b7b3df73b1de5bb76c4f22e2f
SHA256: bdb75d81031c2e2c588d4be0ad4c303141259dd88e19b3ae9d77580224037998
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\MS.locale
text
MD5: e333713949b150ee82345f922e0040ec
SHA256: 44d77861ff9fc61c13bc1408e2e8d43c32673844c7f0b04e17f075232e4ba7de
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\NL.locale
text
MD5: ade4560acaaf360f9dc5e590419abe83
SHA256: 23d3afc51acc6f786f6fcb46aeb0cf74af9f430a0aa539916f68c6be8a7add48
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ML.locale
text
MD5: 119243b7f2c19e278e4684d266de18e6
SHA256: 5db2b398c16f0c95f1caa5d268be5b6fa2da37072bf3522b9d911a7cbe7e19d8
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\NE.locale
text
MD5: 5d79e5cec4f95a3ca6a202970ced6d6e
SHA256: 54f1ddd4b34f705ee10714210e71f59ee51b8931a07b190920bbba2e03950c09
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\PA.locale
text
MD5: ab30b346b4c737c4a9c3ba9b49f2ba83
SHA256: f57cb5d5f9225c52dce26ef9ba742a36b5958f927eec5cd6c898f4f7ea3c3b9c
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\PL.locale
text
MD5: fb48165b230ae752119d6f89bd7699ee
SHA256: 6c83b789070f2f9f193aaac52e6f610e6766007352bebb7ee9f6113439ccae48
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\MK.locale
text
MD5: 9766f19ce1168c26a4ba2ab95e177759
SHA256: a4968d3d8bed8e9ea59f980fc5b31b27bf81911036d70f9305956ede2d92f28f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\NO.locale
text
MD5: 2febd73097d15772b1c90a4e12278018
SHA256: 8585251a7a33f40b2cebb310f57ac0f80dff863bffec69874eb20923eb98adbf
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\MR.locale
text
MD5: bbaf39e1500f3851ad4ea9a0f8d8e3fd
SHA256: 988c7d261cab45a65b09cb485405da216f34c75d228c7e934c309999d3fbf8dd
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\PS.locale
text
MD5: 06efce2d687d52bcb57a48e8b0b726b4
SHA256: 45a64d28eb92e02855f2ba2c1999cb217ff84f4bc9abc89e49c974cfc884a847
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\KK.locale
text
MD5: 27cadfd9aa0fe98538ea44e91c149070
SHA256: f4ba3b56a35e18371e059ba3b9e9711c3cd99d04295ba51ae826767c12aa38e9
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\KA.locale
text
MD5: 1a4abc33ce6e481942ecc7de68ca8d9c
SHA256: 70a39de6f6c425e362bafb70401e762fd724be0aa208748378d199ac4aab3072
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\LT.locale
text
MD5: ed29292834140f8500e4548bf3dffbf2
SHA256: 278889852149473c3f2795593f25a1e544e367a07297573f01e712dde175fee8
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\LO.locale
text
MD5: 08a83d5e6c8683249c5c3b195a33a007
SHA256: 7dd5d3b863ae1c4fce0a3342646639cc8dac2423b2addcc14bcc585a7b8dd83f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\KU.locale
text
MD5: 1b0984c7b45d39fb72f200c72c1d00bd
SHA256: 6ee56f9f35e3c11102221ea9fd6bb083e75826c9dad46fc9fd5705363b191e40
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\KO.locale
text
MD5: dbf7f7864e99ee24bee3a2acdb534766
SHA256: 9039e23765337dcfff2cf9eefbb33a6394c5fe402843209298ef0f31db3cb494
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\LV.locale
text
MD5: 5db26fee22efa33110cdc356002e82ae
SHA256: a925bc583d473136f561fbc2893685ad0112cd578d7fec9ced53cab8a8bf4681
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\IT.locale
text
MD5: 5beb8094b02db5fe5acb113ea615b428
SHA256: 046a44dbd7f96007576ae6e193d308b16dd409f24b3434b2f97bc9e32d03ebec
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\JA.locale
text
MD5: 6bc9980050aed56c2eab3b378bd2ca7c
SHA256: 330e2fcef32fdf2acc2e0ca307436926ffb03532af10bea54ea6c1d66ef9e32f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\IS.locale
text
MD5: e43741977970f32159950e862a2e51ca
SHA256: f6706486f6928bc7f56e5ba9269cb57780a1a3db1cf08ccbf477418579e2b421
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HU.locale
text
MD5: 7cce69e942d9e14a1cf10280499a2667
SHA256: 83001fce7998f3de063073587f905a13c7649f45ffd3139e8f589978e8fdaf7f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HR.locale
text
MD5: 0df1fbe32d5c0037c39d94981f56e186
SHA256: 9078de8455c43a85408108abe2181be496897dc0bcbf533b15098fcddd4ebce1
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HY.locale
text
MD5: ab8b9b0e16b5ef75e0357a8b3f490e05
SHA256: 480570dada38e88b723aa39ac7d79eac7915eb72550b96157022ee0324406804
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HT.locale
text
MD5: 642c180660f79cd3cc7d841614b57365
SHA256: 045aa565e48add4ccbeab74bf38248733e0c4d8becaefab19a6746213ba17762
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ID.locale
text
MD5: e871501287a24ef0d6802d62cd27b46c
SHA256: 0f2899ee236e8d53022ab9f18202114e1567e6c8c93a3fdd128f38bb80355931
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HI.locale
text
MD5: 791e420383be8d190644640fe7a10ab6
SHA256: 38c96d6da4f0b00a61cfc0f3734b80a37cf79d92cb583428e23e8381746081ca
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\HE.locale
text
MD5: d1aea6c331c1db405a2a991346533477
SHA256: f71341df3639a6017693333d8bcce3131ca51f428adea6e940e21d2475342b79
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\FI.locale
text
MD5: aa02a7f1269174618543687ea202f385
SHA256: b891b31e69071351a1669b93f35c434f094973931572dfe36b3c24e648a0d12b
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\GU.locale
text
MD5: d58f240e4f4d700b8523cd8ecb3a83e2
SHA256: 25f31b56585cc3a34b59b9e72e8eff6a654d911fe1c7fb18feeb8dc62d4e0331
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\FR.locale
text
MD5: 227c91a86f898c3b565180646141d680
SHA256: 5109297aaf2b41406b4b210c1da7cfe462c195af1b2bf1b60225477903919bc2
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\FA.locale
text
MD5: 9dbb5724b5a1526b1bfad362d67854f2
SHA256: b154cb9b33a3f2d3390b201025a027c0dee848f98118d601a5710988e95e33b3
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\EU.locale
text
MD5: 49c617241f6bfd93bc5b4b0573bd8b26
SHA256: 6c7241993651cb8414a78afc817b4a40dbbe3a359e7a8ce1f5e31ac1c6f78171
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ET.locale
text
MD5: 31adb5d5e61e0a2e7fa200340df57102
SHA256: de026d2a590398259e6f34200aceb16ffca75c7b8479930b9c2d5524869cce15
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ES.locale
text
MD5: 53755996be49144a3a83890c026b4049
SHA256: d8cd03140dc31d4d08b2c7cb8067a77ca46ad3c58347988e6625cf15c6c8a4e2
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico
––
MD5:  ––
SHA256:  ––
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\EL.locale
text
MD5: 71035ad0232f4d8dc0e837d5865e8834
SHA256: 3aea8bcfd2855028b3c77db0b53627e8884cd9c1d9481a8d83731a9d2b1e5d9f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\EN.locale
text
MD5: 4459c311642a67b43941afcf798d7791
SHA256: d27e381c436210ac3d8c5ba9a2954cc050619b353c99c5978bb775759cd5f3b0
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\DA.locale
text
MD5: 7b1312c0dea89488087e56d35651e472
SHA256: e2f6b6a141164fd442aeaa79a261f2e9799a0c7700c928df701702468b902a8c
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\BE.locale
text
MD5: 411748400cd72340bcf29e34f539340a
SHA256: 2c9e5a82c1edabe537c04c330a87332faa1188a4ba3394084e756e9ab2f0066a
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\AZ.locale
text
MD5: 90a482ef6f51d900b5f3fbbfdeeedd8b
SHA256: 254679039a064418809eb8c9187c0d6588a0f2e44c671b77f79c82806c900750
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\CA.locale
text
MD5: 18dd92b6bfcf4b2d04ec752f2bbed37e
SHA256: acd3d339fc4c4978bd6942e95f451da49d10e8861d8d89022c9edc62748039f3
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\AF.locale
text
MD5: 85683d68fac960fd7887669059b18113
SHA256: 6578baf8fab1dce694229303df0bac1be2bca437d05f3391d9939d9610028fe1
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\images\progress-bg2.png
image
MD5: b582d9a67bfe77d523ba825fd0b9dae3
SHA256: ab4eeb3ea1eef4e84cb61eccb0ba0998b32108d70b3902df3619f4d9393f74c3
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\BS.locale
text
MD5: ff9188bbc0c3a5c14658db0627b28585
SHA256: add647d223c183f6d56a1aa9a22d2b0436f18c9f972da7bc8705cccf867d74dd
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\images\Loader.gif
image
MD5: 57ca1a2085d82f0574e3ef740b9a5ead
SHA256: 476a7b1085cc64de1c0eb74a6776fa8385d57eb18774f199df83fc4d7bbcc24e
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\BG.locale
text
MD5: c77a1f22bc00991db483daad060c21b9
SHA256: f3cfc4b300d6ac056cd21934c9a4cefbfde6531905323f08bf1985f9f3867da9
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\CS.locale
text
MD5: 0af631d42063eef22d6bfcf3b1780254
SHA256: 8290556e9ad37befee2ccff5b65aab1dd44ac7f45292220a33ab30282e6b9d3a
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\ie6_main.css
text
MD5: 74f08d5a243ae79f1de64dffdaf846cb
SHA256: 15590060bfd227f656e569031113a080e0d45621a5c944dfc352f869eadafef2
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\csshover3.htc
html
MD5: 52fa0da50bf4b27ee625c80d36c67941
SHA256: e37e99ddfc73ac7ba774e23736b2ef429d9a0cb8c906453c75b14c029bdd5493
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\browse.css
text
MD5: 6009d6e864f60aea980a9df94c1f7e1c
SHA256: 5ef48a8c8c3771b4f233314d50dd3b5afdcd99dd4b74a9745c8fe7b22207056d
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\button.css
text
MD5: 37e1ff96e084ec201f0d95feef4d5e94
SHA256: 8e806f5b94fc294e918503c8053ef1284e4f4b1e02c7da4f4635e33ec33e0534
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\progress-bar.css
text
MD5: 5335f1c12201b5f7cf5f8b4f5692e3d1
SHA256: 974cd89e64bdaa85bf36ed2a50af266d245d781a8139f5b45d7c55a0b0841dda
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\checkbox.css
text
MD5: 64773c6b0e3413c81aebc46cce8c9318
SHA256: b09504c1bf0486d3ec46500592b178a3a6c39284672af8815c3687cc3d29560d
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\images\progress-bg.png
image
MD5: e9f12f92a9eeb8ebe911080721446687
SHA256: c1cf449536bc2778e27348e45f0f53d04c284109199fb7a9af7a61016b91f8bc
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\images\button-bg.png
image
MD5: 98b1de48dfa64dc2aa1e52facfbee3b0
SHA256: 2693930c474fe640e2fe8d6ef98abe2ecd303d2392c3d8b2e006e8942ba8f534
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\main.css
text
MD5: 9b27e2a266fe15a3aabfe635c29e8923
SHA256: 166aa42bc5216c5791388847ae114ec0671a0d97b9952d14f29419b8be3fb23f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\css\sdk-ui\images\progress-bg-corner.png
image
MD5: 608f1f20cd6ca9936eaa7e8c14f366be
SHA256: 86b6e6826bcde2955d64d4600a4e01693522c1fddf156ce31c4ba45b3653a7bd
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\002525D3.log
––
MD5:  ––
SHA256:  ––
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\bg_fus_TB[1].png
image
MD5: 2d82b2d5461208e8b6d6bb3fa907ab50
SHA256: 8d0dbcc4d2f9607316b7aaa17332420cb98568320ca23ea9fd4ce4f44bf0a4bd
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\bootstrap_43971.html
––
MD5:  ––
SHA256:  ––
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\002526FC.log
––
MD5:  ––
SHA256:  ––
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsh1115.tmp\modern-wizard.bmp
image
MD5: cbe40fd2b1ec96daedc65da172d90022
SHA256: 3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ZH.locale
text
MD5: f87a44df4ee66271fcb7cb8909be2c2e
SHA256: f212cbeb0355b860a19969bf9a685b6aae5e8cd1b50ca97ec59880bdbaac24ad
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\ZU.locale
text
MD5: e0fe6b07557ceadb3cdee5cd6bf1553c
SHA256: 9a5f171619d63344771d0af667662cc3672222166fc7d5368724b818d4508b24
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\YO.locale
text
MD5: 28cadcc5482ef94c3dd399966efce474
SHA256: 18350d0b95fea022fe7f65b2c21748423ad96ac9f4a87e833395873d45130dad
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\VI.locale
text
MD5: 1c68a0b054e91821a6ee5fcc95a8f370
SHA256: 949be3edb5994b200e83ca062b6badcffdac4c177ce1a77b2976ede622797399
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\TA.locale
text
MD5: 0357e9121095334fb270b19d2e847368
SHA256: 009f1c6bfbb1f39d8a59e9a8fc589f4dc8a978b4150c283fb2f3f1dfca7a4b87
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019011020190111\index.dat
dat
MD5: 37531739dd4675fbdcb9d9192a840fbc
SHA256: 76c73e64789f1a58eb3d4d84209649e83cb5b760a9f81d346b013d854c58d019
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019011020190111\index.dat
dat
MD5: 421a507ff6f2090845057edd6f7eeb77
SHA256: ddc552d4d94e29508b9bc664e3d69a437c05248cff5ed5aed9fd905a7b87a713
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\FileZilla_3.39.0_win32-setup_bundled[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FileZilla_3.39.0_win32-setup_bundled[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\UR.locale
text
MD5: f98806a6c51ad09ab464191f95320bba
SHA256: 5e7131784e1de61479c8dc8bfcf8de40ed07f4d0ffdd4a29c42be6f298ad169f
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Users\admin\AppData\Local\Temp\nsd243451561498\locale\UK.locale
text
MD5: 805b4a7d627d697d81889e90b5dc26f1
SHA256: 63148079e733a889e2531b21e0234c1ba7f1c981f9c1d025e539a5a3b420e065
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\favicon[1].ico
image
MD5: 559c607660096f3736b623a832c53cfd
SHA256: 1598e03e269a543e2043de559893bf3c6f360704a376beeb9ee9ae3ff189217e
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\s_common[1].png
image
MD5: ba08ea224b15c854b328619b6b064eb3
SHA256: f480c10cfdf762b0ddc3cc6d6c8773720ce8ce24f589f0f39c3ee31cd2438331
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\s_header_bottom[1].png
image
MD5: 166dc36b2da17df05ac57c5a42300b26
SHA256: 4f4e37e945f331b3e28717bdc1d2eccce47c9aeb0d8f327013f6a41f01599896
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\h3[1].png
image
MD5: 81ccc377ab5202c9954092f128056f90
SHA256: 96e572bc4aad95203ebfdf4cf55c40502447842d4ab3bc074a0635d5a6d34907
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\arrow[1].png
image
MD5: f797ea5384d38744f407dc14984e8238
SHA256: a51603a54d45262921203536dca57d491b1b65065054f9a405ea618729d0f3cd
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\button_green[1].png
image
MD5: bf7c31087d40729ee0bba1950d453256
SHA256: b451855bd42d4e6a67663437e492873f7b2c86e532d855b7ee420461a7fa955c
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\fz3_win_main-small[1].png
image
MD5: 01e8a38e051fc3a45abe69846e24a31b
SHA256: 953154cb391e4f959b43ff6c5ecd02579dd3182adf90e2aab3da914a47e88ba2
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\logo-linux[1].png
image
MD5: 3670d3e087b8cc195850cd5190db6e56
SHA256: c2c30e4508f4a6fa3a92ae9509d116f288c40050ed20e7a49dc832f83f13217f
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\style[1].css
text
MD5: b71ea06c1b475f2b04eedee9e1f0046c
SHA256: 81d6dd38f7b33342694291981d64bec85df7716c032431f36ef6d3e529092d0b
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\logo-windows64[1].png
image
MD5: f07c52e8d9d1fbcb99eaec88a51ef641
SHA256: 5753af2993b6e3e426a46ef188825d7fcff73d3f33125ddf51d5b63da81e1843
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\dealslands[1].png
image
MD5: 276522a62241e7d3c1ff75af16ce91d1
SHA256: 4abce09f5890d487c1ba742235248acc85ca0cd6ec85b18651a374008d202817
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\logo-osx[1].png
image
MD5: 5a7ba8d6b63665f51335107005f9fbce
SHA256: c49921ef5dd10d28a2ec32532c893529d427fb9eab59c39d1d3fdddaf73a9203
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\ndchost[1].png
image
MD5: 221ec6a6597039fad752724367c7a4ff
SHA256: 187bc44634267870fa86b753de185277a98a57ea78052827af95b5f0ca561bdc
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\logo-windows32[1].png
image
MD5: 32d6005feab834f0182941cbd060b38d
SHA256: 597619fc8a3dd4c2b954aecaf63b227d577762f66eb17152c80d59df2de0ccd1
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\download[1].htm
html
MD5: 86b3aeb46b87d362007a46db56afed76
SHA256: ad9a9cbea74bb6563f4114208468456c95008ade5987997dc0a8b48662d00119
3096
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\download[1].php
––
MD5:  ––
SHA256:  ––
2948
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[2].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
2948
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
1332
FileZilla_3.39.0_win32-setup_bundled[1].exe
C:\Program Files\00252854.log
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
6
TCP/UDP connections
13
DNS requests
7
Threats
8

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2948 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe POST 200 52.210.70.79:80 http://os.tourtodaylaboratory.com/FusionFileZilla/ IE
binary
binary
malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe GET 200 199.201.110.78:80 http://img.tourtodaylaboratory.com/img/Rowabobeso/bg_fus_TB.png US
image
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2948 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
3096 iexplore.exe 136.243.154.86:443 Hetzner Online GmbH DE unknown
2948 iexplore.exe 136.243.154.86:443 Hetzner Online GmbH DE unknown
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe 136.243.154.86:443 Hetzner Online GmbH DE unknown
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe 52.214.73.247:80 Amazon.com, Inc. IE malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe 52.210.70.79:80 Amazon.com, Inc. IE malicious
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe 199.201.110.78:80 Namecheap, Inc. US suspicious

DNS requests

Domain IP Reputation
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
filezilla-project.org 136.243.154.86
whitelisted
download.filezilla-project.org 136.243.154.86
whitelisted
offers.filezilla-project.org 136.243.154.86
whitelisted
rp.tourtodaylaboratory.com 52.214.73.247
54.194.149.175
malicious
os.tourtodaylaboratory.com 52.210.70.79
52.209.41.250
malicious
img.tourtodaylaboratory.com 199.201.110.78
malicious

Threats

PID Process Class Message
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3
1332 FileZilla_3.39.0_win32-setup_bundled[1].exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4

4 ETPRO signatures available at the full report

Debug output strings

No debug info.