File name:

file

Full analysis: https://app.any.run/tasks/22d99d5b-914d-4849-90d3-060f74dea21f
Verdict: Malicious activity
Threats:

NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.

Analysis date: October 22, 2023, 19:29:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
netsupport
unwanted
remote
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

646396A1F9B3474AD8533953A3583B4B

SHA1:

9CC3B41381D97196F93D2D551492909D82F58DDE

SHA256:

3407337DEA12501ED2D524ED049D69A8E188BCD585F1A4055B60D4369CFC348B

SSDEEP:

98304:tHMf/6YMy85U5Tf+S+PL3pa89qQu6pGL75ADFACm+KVtNnPdRKtnttvywil3JB7U:2dPwnOOoB83SZICuz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • file.exe (PID: 1392)
      • file.exe (PID: 2268)
      • msiexec.exe (PID: 2664)
      • msiexec.exe (PID: 2712)
      • LZMAdriver.exe (PID: 812)
    • Application was dropped or rewritten from another process

      • ISBEW64.exe (PID: 3052)
      • ISBEW64.exe (PID: 2328)
      • ISBEW64.exe (PID: 2560)
      • ISBEW64.exe (PID: 904)
      • ISBEW64.exe (PID: 2896)
      • ISBEW64.exe (PID: 2064)
      • ISBEW64.exe (PID: 2300)
      • LZMAdriver.exe (PID: 812)
      • ISBEW64.exe (PID: 2416)
      • ISBEW64.exe (PID: 2796)
      • ISBEW64.exe (PID: 1308)
      • CompatProvider.exe (PID: 2888)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 2664)
      • CompatProvider.exe (PID: 2888)
    • NETSUPPORT was detected

      • CompatProvider.exe (PID: 2888)
    • Connects to the CnC server

      • CompatProvider.exe (PID: 2888)
  • SUSPICIOUS

    • Starts itself from another location

      • file.exe (PID: 1392)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2712)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2712)
      • LZMAdriver.exe (PID: 812)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 2712)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 2664)
      • file.exe (PID: 2268)
    • The process drops C-runtime libraries

      • LZMAdriver.exe (PID: 812)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 2976)
    • Reads the Internet Settings

      • CompatProvider.exe (PID: 2888)
    • Connects to the server without a host name

      • CompatProvider.exe (PID: 2888)
    • Connects to unusual port

      • CompatProvider.exe (PID: 2888)
    • The process deletes folder without confirmation

      • file.exe (PID: 2268)
  • INFO

    • Checks supported languages

      • file.exe (PID: 1392)
      • file.exe (PID: 2268)
      • msiexec.exe (PID: 2712)
      • ISBEW64.exe (PID: 3052)
      • ISBEW64.exe (PID: 2560)
      • msiexec.exe (PID: 2664)
      • ISBEW64.exe (PID: 2328)
      • ISBEW64.exe (PID: 2896)
      • ISBEW64.exe (PID: 904)
      • ISBEW64.exe (PID: 2064)
      • ISBEW64.exe (PID: 2300)
      • ISBEW64.exe (PID: 1308)
      • ISBEW64.exe (PID: 2416)
      • ISBEW64.exe (PID: 2796)
      • LZMAdriver.exe (PID: 812)
      • CompatProvider.exe (PID: 2888)
    • Reads the computer name

      • file.exe (PID: 1392)
      • file.exe (PID: 2268)
      • msiexec.exe (PID: 2712)
      • msiexec.exe (PID: 2664)
      • ISBEW64.exe (PID: 3052)
      • ISBEW64.exe (PID: 2560)
      • ISBEW64.exe (PID: 2328)
      • ISBEW64.exe (PID: 2896)
      • ISBEW64.exe (PID: 2300)
      • ISBEW64.exe (PID: 904)
      • ISBEW64.exe (PID: 2064)
      • ISBEW64.exe (PID: 1308)
      • ISBEW64.exe (PID: 2416)
      • ISBEW64.exe (PID: 2796)
      • LZMAdriver.exe (PID: 812)
      • CompatProvider.exe (PID: 2888)
    • Create files in a temporary directory

      • file.exe (PID: 1392)
      • file.exe (PID: 2268)
      • msiexec.exe (PID: 2664)
      • msiexec.exe (PID: 2712)
    • Reads the machine GUID from the registry

      • file.exe (PID: 2268)
      • msiexec.exe (PID: 2712)
      • msiexec.exe (PID: 2664)
      • ISBEW64.exe (PID: 3052)
      • ISBEW64.exe (PID: 2328)
      • ISBEW64.exe (PID: 2896)
      • ISBEW64.exe (PID: 904)
      • ISBEW64.exe (PID: 2064)
      • ISBEW64.exe (PID: 2560)
      • ISBEW64.exe (PID: 2796)
      • ISBEW64.exe (PID: 2300)
      • ISBEW64.exe (PID: 1308)
      • ISBEW64.exe (PID: 2416)
      • CompatProvider.exe (PID: 2888)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2712)
      • CompatProvider.exe (PID: 2888)
    • Checks proxy server information

      • CompatProvider.exe (PID: 2888)
    • Creates files in the program directory

      • LZMAdriver.exe (PID: 812)
    • Drop NetSupport executable file

      • LZMAdriver.exe (PID: 812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:05:11 19:03:16+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 481280
InitializedDataSize: 612864
UninitializedDataSize: -
EntryPoint: 0x45d0a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.90.2000.0
ProductVersionNumber: 7.90.2000.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Unties Backout LLC
FileDescription: Setup Launcher Unicode
FileVersion: 7.90.2000
InternalName: Setup
LegalCopyright: Copyright (c) 2020 Flexera. All Rights Reserved.
OriginalFileName: setup.exe
ProductName: Unpluralized Antifrost
ProductVersion: 7.90.2000
InternalBuildNumber: 198300
ISInternalVersion: 26.0.546
ISInternalDescription: Setup Launcher Unicode
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
21
Malicious processes
11
Suspicious processes
6

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start file.exe no specs file.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs cmd.exe no specs lzmadriver.exe no specs cmd.exe no specs reg.exe no specs #NETSUPPORT compatprovider.exe cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
812LZMAdriver.exe x dism.7z -oC:\ProgramData -pJWWF92HAadWoSJXCC:\ProgramData\LZMAdriver.execmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
22.01
Modules
Images
c:\programdata\lzmadriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
904C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8B2E0B91-08F5-4C73-A76E-B2CB75EC0127}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1308C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{076AD3F7-01D8-49C0-B369-475953A6F3A3}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
1392"C:\Users\admin\AppData\Local\Temp\file.exe" C:\Users\admin\AppData\Local\Temp\file.exeexplorer.exe
User:
admin
Company:
Unties Backout LLC
Integrity Level:
MEDIUM
Description:
Setup Launcher Unicode
Exit code:
1603
Version:
7.90.2000
Modules
Images
c:\users\admin\appdata\local\temp\file.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
2064C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C95AC587-DFDA-4E34-B36A-0FEFF3FBB63F}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2268C:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\file.exe /q"C:\Users\admin\AppData\Local\Temp\file.exe" /tempdisk1folder"C:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}" /IS_tempC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\file.exefile.exe
User:
admin
Company:
Unties Backout LLC
Integrity Level:
MEDIUM
Description:
Setup Launcher Unicode
Exit code:
1603
Version:
7.90.2000
Modules
Images
c:\users\admin\appdata\local\temp\{14418024-95d0-4d91-8b4a-b555cb8ac0e6}\file.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
2300C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{99998B32-1A79-4D81-B714-283A99C2B450}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2328C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{85A101B0-B6BA-452D-BAC6-155D3072AF7C}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2416C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{EA0E5F55-F56B-4140-A0B7-13B09DBAB366}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2560C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6989D4D3-878A-4EF7-8EE4-D5FBF878AA2B}C:\Users\admin\AppData\Local\Temp\{27995FDB-07E2-4116-9D7F-99547143874B}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
MEDIUM
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.546
Modules
Images
c:\users\admin\appdata\local\temp\{27995fdb-07e2-4116-9d7f-99547143874b}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
Total events
2 600
Read events
2 577
Write events
12
Delete events
11

Modification events

(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\156\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\156
Operation:delete keyName:(default)
Value:
(PID) Process:(2712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete valueName:C:\Config.Msi\18cb0e.rbs
Value:
31065374
(PID) Process:(2712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete valueName:C:\Config.Msi\18cb0e.rbsLow
Value:
798581296
(PID) Process:(2712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete keyName:(default)
Value:
(PID) Process:(2712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
Operation:delete keyName:(default)
Value:
(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
24BFA93668BC7F3BA1A902E858A1337F3994AA0864F965E50A8F10172659EC0E
(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
980A0000B202592F1E05DA01
(PID) Process:(2712) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
26
Suspicious files
11
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
2268file.exeC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\Unpluralized Antifrost.msi
MD5:
SHA256:
2712msiexec.exeC:\Windows\Installer\18cb0b.msi
MD5:
SHA256:
1392file.exeC:\Users\admin\AppData\Local\Temp\~B64B.tmptext
MD5:236E86A73AA13283F042A8E0E37D817B
SHA256:F4F66390A1BB0C30A78DF0CAF277BDD0111FECB9F53099663F56DEF6038CB1BF
1392file.exeC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\_ISMSIDEL.INItext
MD5:9142F4B312AC514AFA2D417AB7AD121A
SHA256:6621081ED5C00A483D1C0092E34CE3B457E14D4E725629FCCC16C4A3628F3F31
2268file.exeC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\0x0409.initext
MD5:A108F0030A2CDA00405281014F897241
SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
1392file.exeC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\file.exeexecutable
MD5:646396A1F9B3474AD8533953A3583B4B
SHA256:3407337DEA12501ED2D524ED049D69A8E188BCD585F1A4055B60D4369CFC348B
2712msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFCEF94C942D926DB9.TMPbinary
MD5:2205612950136F59F8BC9E2B5BCF6335
SHA256:1DFDAB9589BAFF9504F73C372AA4CCDB591EB1574959A0493E6E801849CC60C9
2268file.exeC:\Users\admin\AppData\Local\Temp\{14418024-95D0-4D91-8B4A-B555CB8AC0E6}\Setup.INItext
MD5:236E86A73AA13283F042A8E0E37D817B
SHA256:F4F66390A1BB0C30A78DF0CAF277BDD0111FECB9F53099663F56DEF6038CB1BF
2268file.exeC:\Users\admin\AppData\Local\Temp\~B69A.tmptext
MD5:236E86A73AA13283F042A8E0E37D817B
SHA256:F4F66390A1BB0C30A78DF0CAF277BDD0111FECB9F53099663F56DEF6038CB1BF
1392file.exeC:\Users\admin\AppData\Local\Temp\~B64C.tmptext
MD5:236E86A73AA13283F042A8E0E37D817B
SHA256:F4F66390A1BB0C30A78DF0CAF277BDD0111FECB9F53099663F56DEF6038CB1BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
8
DNS requests
2
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2888
CompatProvider.exe
GET
200
51.142.119.24:80
http://geo.netsupportsoftware.com/location/loca.asp
unknown
text
15 b
unknown
2888
CompatProvider.exe
POST
200
185.225.17.47:136
http://185.225.17.47/fakeurl.htm
unknown
binary
152 b
unknown
2888
CompatProvider.exe
POST
185.225.17.47:136
http://185.225.17.47/fakeurl.htm
unknown
unknown
2888
CompatProvider.exe
POST
185.225.17.47:136
http://185.225.17.47/fakeurl.htm
unknown
unknown
2888
CompatProvider.exe
POST
185.225.17.47:136
http://185.225.17.47/fakeurl.htm
unknown
unknown
2888
CompatProvider.exe
POST
200
185.225.17.47:136
http://185.225.17.47/fakeurl.htm
unknown
binary
61 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2888
CompatProvider.exe
51.142.119.24:80
geo.netsupportsoftware.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
2888
CompatProvider.exe
185.225.17.47:136
glaciecrw.cfd
MivoCloud SRL
RO
unknown

DNS requests

Domain
IP
Reputation
geo.netsupportsoftware.com
  • 51.142.119.24
  • 62.172.138.67
  • 62.172.138.8
unknown
glaciecrw.cfd
  • 185.225.17.47
unknown

Threats

PID
Process
Class
Message
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Checkin
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Response
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Checkin
2888
CompatProvider.exe
Potential Corporate Privacy Violation
ET POLICY NetSupport GeoLocation Lookup Request
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Response
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Checkin
2888
CompatProvider.exe
Misc activity
ET INFO NetSupport Remote Admin Checkin
4 ETPRO signatures available at the full report
No debug info