File name:

SpyHunter-5.15-6-5285-Installer.exe

Full analysis: https://app.any.run/tasks/99aa6d5a-15fa-443d-899a-54a607681e3d
Verdict: Malicious activity
Analysis date: February 12, 2024, 17:06:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

087FA5C4DDA11DBFF76FC89F7C41407F

SHA1:

2D9274FBF4384E8CFE59141645C881254A8B9157

SHA256:

32C3D2970B3F1D9F944917EBD1F4335D2DA8CB9195A22245967012DD73FD8063

SSDEEP:

98304:+s0GAPsAEqF+nPZcw7UfmxNQt+hq2Ml+x+U66JcZcQyCfZBr4ogdhHy/nT51r9I6:ikjnva/NEi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • ShKernel.exe (PID: 3876)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
    • Actions looks like stealing of personal data

      • SpyHunter5.exe (PID: 120)
    • Steals credentials from Web Browsers

      • SpyHunter5.exe (PID: 120)
    • Creates a writable file in the system directory

      • ShKernel.exe (PID: 3876)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • SpyHunter5.exe (PID: 120)
    • Starts SC.EXE for service management

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
    • Executable content was dropped or overwritten

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • ShKernel.exe (PID: 3876)
    • Reads the Internet Settings

      • rundll32.exe (PID: 1596)
    • The process executes via Task Scheduler

      • rundll32.exe (PID: 1596)
    • Drops 7-zip archiver for unpacking

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
    • Executes as Windows Service

      • ShMonitor.exe (PID: 3656)
      • ShKernel.exe (PID: 3876)
    • Reads the Windows owner or organization settings

      • ShKernel.exe (PID: 3876)
      • SpyHunter5.exe (PID: 120)
    • Creates files in the driver directory

      • ShKernel.exe (PID: 3876)
    • Drops a system driver (possible attempt to evade defenses)

      • ShKernel.exe (PID: 3876)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2952)
    • Creates a software uninstall entry

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
  • INFO

    • Reads the computer name

      • ShKernel.exe (PID: 3876)
      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • ShMonitor.exe (PID: 3656)
      • SpyHunter5.exe (PID: 120)
    • Checks supported languages

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • ShMonitor.exe (PID: 3656)
      • SpyHunter5.exe (PID: 120)
      • ShKernel.exe (PID: 3876)
    • Create files in a temporary directory

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
    • Application launched itself

      • msedge.exe (PID: 2128)
      • msedge.exe (PID: 2344)
    • Creates files in the program directory

      • SpyHunter-5.15-6-5285-Installer.exe (PID: 2852)
      • ShKernel.exe (PID: 3876)
      • ShMonitor.exe (PID: 3656)
      • SpyHunter5.exe (PID: 120)
    • Manual execution by a user

      • msedge.exe (PID: 2344)
    • Reads Windows Product ID

      • ShKernel.exe (PID: 3876)
      • SpyHunter5.exe (PID: 120)
    • Reads CPU info

      • ShKernel.exe (PID: 3876)
      • SpyHunter5.exe (PID: 120)
    • Process checks whether UAC notifications are on

      • ShKernel.exe (PID: 3876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:08 14:36:09+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4766720
InitializedDataSize: 2403328
UninitializedDataSize: -
EntryPoint: 0x2a8097
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.853.5482
ProductVersionNumber: 3.0.853.5482
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: EnigmaSoft Limited
FileDescription: EnigmaSoft Installer
FileVersion: 3.0.853.5482
InternalName: Installer.exe
LegalCopyright: Copyright 2016-2023. EnigmaSoft Limited. All rights reserved.
OriginalFileName: Installer.exe
ProductName: Installer
ProductVersion: 3.0.853.5482
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
85
Monitored processes
34
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spyhunter-5.15-6-5285-installer.exe sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs sc.exe no specs msedge.exe no specs msedge.exe no specs sc.exe no specs regsvr32.exe no specs sc.exe no specs shkernel.exe sc.exe no specs shmonitor.exe no specs msedge.exe no specs spyhunter5.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs spyhunter-5.15-6-5285-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe" /hideC:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe
ShKernel.exe
User:
admin
Company:
EnigmaSoft Limited
Integrity Level:
MEDIUM
Description:
SpyHunter product.
Exit code:
0
Version:
5.16.6.327
Modules
Images
c:\program files\enigmasoft\spyhunter\spyhunter5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2208 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
568C:\Windows\System32\sc.exe create ShMonitor start= demand binPath= "\"C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe\"" DisplayName= "SpyHunter 5 Kernel Monitor"C:\Windows\System32\sc.exeSpyHunter-5.15-6-5285-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
572"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
584"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1600 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1092"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1472 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1288"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2216 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler https://www.enigmasoftware.com/congratulations-spyhunter-installed/?hwx=be61cceca008f70f83a14f29cff82655&lang=EN&purl=https%3A%2F%2Fpurchase%2Eenigmasoftware%2Ecom%2Fshwin&sid=shcC:\Windows\System32\rundll32.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6ba9f598,0x6ba9f5a8,0x6ba9f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1748"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3560 --field-trial-handle=1228,i,13482127639022967285,14601147021155624290,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
89 929
Read events
89 836
Write events
82
Delete events
11

Modification events

(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:LanguageType
Value:
EN
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ITime
Value:
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardEnabled
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardUnknownExecution
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardUnknownPromptOnlySuspicious
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:CloudAnalysis
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ShowArmW10Warning
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ICfg
Value:
e72d8cb294cee996ff651da25d101b5aad690c18f315b567a154a745ce4cde89b4b75113893fda6cdde508dc9c7de3002ac8d02a84ce50a341176b2bad9d90ef
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:AdFlags
Value:
1
(PID) Process:(2852) SpyHunter-5.15-6-5285-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:Language
Value:
English.lng
Executable files
14
Suspicious files
44
Text files
32
Unknown types
105

Dropped files

PID
Process
Filename
Type
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\purl.datbinary
MD5:B4EDDF5E35BC5F6913A246530705A151
SHA256:AE2DDA813C46DC3FA74D1B5E671E1D0A77BE156899B21E69A185BA5B6BECC0E4
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Bulgarian.lngbinary
MD5:8B4608FABC2237BE17D72888BFF37753
SHA256:FFE944D30606FDE1A4CC245C6D94A444B78AA5360B17AA009D3AD6B1169F368D
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Danish.lngbinary
MD5:118FC18FBAB4A3626085F584CA4F863E
SHA256:4B788D88A9317F7181582C6855FF230F5BD953F2CDACFAB029D346C765128E9A
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Native.exeexecutable
MD5:A65B45590375B59B2D4267CDBFF65FD4
SHA256:13030203E1CFD38547413CC678A8D49C38B839C545B022AE1354949B0B144EC4
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exeexecutable
MD5:83883B09B751698ECC98DEED0B2E5329
SHA256:934DF74001EA2178E2F2E4A510FC56AC7375893905425BA1DD1A9CA6BED072FB
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exeexecutable
MD5:68D86A870B82219690FA7A35CDA5FCF6
SHA256:66A0F350EFF22447D9BD7FD138EC55F84CC98AFECB24E300B0D3E049D3B8545E
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Chinese (Traditional).lngbinary
MD5:07DEC84D431731B369134CFDA95FAF3D
SHA256:A64DE97F0E9E90E02C3B1E3EDF3F4734BF3158767240CAC5FB13DC6EC5413726
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\French.lngbinary
MD5:6E44854D478C87A9B194A6BE7213DC0A
SHA256:9C8A8F3A7068B2DD5B9954EC53A7628A98D7D1633C10D80BFD357FF6AB65A7D2
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\German.lngbinary
MD5:33B9D808AF35B0EF749C03FF14F59E93
SHA256:90099785F4DE7B99AE60578BD9831439F63134856928F2151DDFEBC9D64F97EF
2852SpyHunter-5.15-6-5285-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Czech.lngbinary
MD5:78EDA8C7B531040C646D7D0E8BCCF5F0
SHA256:93FC6A23D6872ACF1EF8F400BBBB6E7F90915A8A67A3CF24CABF2004BC069CF8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
123
DNS requests
85
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2852
SpyHunter-5.15-6-5285-Installer.exe
HEAD
302
142.250.185.164:80
http://www.google.com/
unknown
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
HEAD
405
142.250.185.164:80
http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgQtWGF5GKqgqa4GIjCRvGvGdAvGKQCuXzaqcuua79Ed4LRZTK3BNrRsMk8h8dYJdC3woO8SdvjxDMOGoTUyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
unknown
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
GET
301
169.150.247.37:80
http://installer.enigmasoftware.com/log_collect.cfg
unknown
html
162 b
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
GET
301
169.150.247.38:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_initrd.gz.ecf
unknown
html
162 b
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
GET
301
169.150.247.38:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_shldr.mbr.ecf
unknown
html
162 b
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
GET
301
169.150.247.38:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_vmlinuz.ecf
unknown
html
162 b
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
GET
301
169.150.247.38:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_shldr.ecf
unknown
html
162 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2852
SpyHunter-5.15-6-5285-Installer.exe
18.239.18.49:443
geo-ip.enigmasoft.net
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
142.250.185.110:443
www.google-analytics.com
GOOGLE
US
whitelisted
2852
SpyHunter-5.15-6-5285-Installer.exe
142.250.185.164:80
www.google.com
GOOGLE
US
whitelisted
2852
SpyHunter-5.15-6-5285-Installer.exe
169.150.247.37:80
installer.enigmasoftware.com
GB
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
169.150.247.37:443
installer.enigmasoftware.com
GB
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
169.150.247.39:443
installer.enigmasoftware.com
GB
unknown
2852
SpyHunter-5.15-6-5285-Installer.exe
52.222.149.60:443
dl.enigmasoftware.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
geo-ip.enigmasoft.net
  • 18.239.18.49
  • 18.239.18.38
  • 18.239.18.126
  • 18.239.18.65
unknown
www.google-analytics.com
  • 142.250.185.110
  • 216.239.36.178
  • 216.239.38.178
  • 216.239.34.178
  • 216.239.32.178
whitelisted
www.google.com
  • 142.250.185.164
  • 172.217.16.132
whitelisted
installer.enigmasoftware.com
  • 169.150.247.37
  • 169.150.247.39
  • 169.150.247.38
shared
dl.enigmasoftware.com
  • 52.222.149.60
  • 52.222.149.98
  • 52.222.149.126
  • 52.222.149.122
whitelisted
instcfg.enigmasoftware.com
  • 18.65.39.99
  • 18.65.39.10
  • 18.65.39.63
  • 18.65.39.74
unknown
config.edge.skype.com
  • 13.107.43.16
whitelisted
www.enigmasoftware.com
  • 18.66.122.46
  • 18.66.122.99
  • 18.66.122.54
  • 18.66.122.121
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
tt.web.enigmasoftware.com
  • 54.195.217.160
  • 52.17.7.239
unknown

Threats

No threats detected
Process
Message
ShKernel.exe
Main. Enter. Initializing logger...