| File name: | Soft whatsapp app.exe |
| Full analysis: | https://app.any.run/tasks/3943614e-467c-4557-8a67-52bac8569788 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | November 08, 2023, 15:32:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F4B514F9D6B74C75524F00FEE764DA02 |
| SHA1: | 90EFB3E1F8FF3557DF65355AA2B9F0CCB938DC64 |
| SHA256: | 3570ED4F3E8CFDEDF63D3FB977B8F19ABFBD075B5A2094F486875535943D5BD6 |
| SSDEEP: | 98304:DXnE8OfISvM7vq4jUfJSn+o3tC1l0bSfHFXbFUKQfTpoYTzv1Ex9kZWBJx0ehDx+:5X1tSAEq5qL1KWYj |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:25 12:04:28+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 102400 |
| InitializedDataSize: | 107008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x199b4 |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 16.12.46.0 |
| ProductVersionNumber: | 16.12.46.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | Install Whatsapp |
| FileVersion: | 16.12.46.0 |
| LegalCopyright: | © Whatsapp. All Copyright. |
| OriginalFileName: | |
| ProductName: | |
| ProductVersion: | 2.9.25 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 600 | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silent --pin-taskbar=y --pin-desktop=n | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe | — | seederexe.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: YandexPin Exit code: 1 Version: 3.7.9.0 Modules
| |||||||||||||||
| 1356 | C:\Users\admin\AppData\Local\Temp\FAD229D6-BFFD-4C94-8B79-20753236DCD5\sender.exe --send "/status.xml?clid=2313438-125&uuid=f378e9d6-9633-4399-AE96-13E12FB2a6d2&vnt=Windows 7x32&file-no=8%0A10%0A11%0A13%0A15%0A17%0A18%0A20%0A21%0A22%0A24%0A25%0A40%0A42%0A45%0A50%0A58%0A61%0A89%0A103%0A111%0A123%0A124%0A129%0A" | C:\Users\admin\AppData\Local\Temp\FAD229D6-BFFD-4C94-8B79-20753236DCD5\sender.exe | seederexe.exe | ||||||||||||
User: admin Company: Yandex Integrity Level: MEDIUM Description: Yandex Statistics Exit code: 0 Version: 0.0.2.14 Modules
| |||||||||||||||
| 1816 | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silent --pin-taskbar=y --pin-desktop=n /website-path="C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\Taskbar\Яндекс Маркет.website" /icon-path="C:\Users\admin\AppData\Local\MICROS~1\INTERN~1\Services\MARKET~1.ICO" /site-id="2AE68B04.8A85F169" | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe | — | seederexe.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: YandexPin Exit code: 0 Version: 3.7.9.0 Modules
| |||||||||||||||
| 1884 | "C:\Users\admin\AppData\Local\Temp\{6E5B255C-6DFE-46EE-9697-C9B4D464F406}.exe" --job-name=yBrowserDownloader-{64A8D2BF-AD8C-438C-9E3B-B39CAA0C663D} --send-statistics --local-path=C:\Users\admin\AppData\Local\Temp\{6E5B255C-6DFE-46EE-9697-C9B4D464F406}.exe --YABROWSER --cumtom-welcome-page=https://browser.yandex.ru/promo/welcome_com/5/ --silent --remote-url=http://downloader.yandex.net/downloadable_soft/browser/pseudoportal-ru/Yandex.exe?clid=2313418-125&ui=f378e9d6-9633-4399-AE96-13E12FB2a6d2 --use-user-default-locale | C:\Users\admin\AppData\Local\Temp\{6E5B255C-6DFE-46EE-9697-C9B4D464F406}.exe | explorer.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: MEDIUM Description: Yandex Exit code: 0 Version: 23.9.4.838 Modules
| |||||||||||||||
| 3428 | "C:\Users\admin\AppData\Local\Temp\Soft whatsapp app.exe" | C:\Users\admin\AppData\Local\Temp\Soft whatsapp app.exe | — | explorer.exe | |||||||||||
User: admin Company: Whatsapp Integrity Level: MEDIUM Description: Install Whatsapp Exit code: 0 Version: 16.12.46.0 Modules
| |||||||||||||||
| 3460 | "C:\Users\admin\AppData\Local\Temp\is-2I9MP.tmp\Soft whatsapp app.tmp" /SL5="$60134,6029596,210432,C:\Users\admin\AppData\Local\Temp\Soft whatsapp app.exe" | C:\Users\admin\AppData\Local\Temp\is-2I9MP.tmp\Soft whatsapp app.tmp | Soft whatsapp app.exe | ||||||||||||
User: admin Company: Whatsapp Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3484 | "C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe" /S | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | — | Soft whatsapp app.tmp | |||||||||||
User: admin Company: Qihoo 360 Technology Co. Ltd. Integrity Level: MEDIUM Description: 360 Total Security Online Installer Exit code: 3221226540 Version: 6, 6, 0, 1054 Modules
| |||||||||||||||
| 3500 | "C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe" /S | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Soft whatsapp app.tmp | ||||||||||||
User: admin Company: Qihoo 360 Technology Co. Ltd. Integrity Level: HIGH Description: 360 Total Security Online Installer Exit code: 0 Version: 6, 6, 0, 1054 Modules
| |||||||||||||||
| 3696 | "C:\Users\admin\AppData\Local\Temp\44D25EEC-32A4-4388-9727-4EC858CFBA56\seederexe.exe" "--yqs=y" "--yhp=y" "--ilight=1" "--oem=" "--nopin=n" "--pin_custom=n" "--pin_desktop=n" "--pin_taskbar=y" "--locale=us" "--browser=y" "--browser_default=" "--loglevel=trace" "--ess=" "--clids=C:\Users\admin\AppData\Local\Temp\clids-yasearch.xml" "--sender=C:\Users\admin\AppData\Local\Temp\FAD229D6-BFFD-4C94-8B79-20753236DCD5\sender.exe" "--is_elevated=no" "--ui_level=2" "--good_token=x" "--no_opera=n" | C:\Users\admin\AppData\Local\Temp\44D25EEC-32A4-4388-9727-4EC858CFBA56\seederexe.exe | msiexec.exe | ||||||||||||
User: admin Company: Yandex Integrity Level: MEDIUM Description: Browser Integration Module Exit code: 0 Version: 3.7.10.0 Modules
| |||||||||||||||
| 3716 | "C:\Users\admin\AppData\Local\Temp\AACA7EEC-83AC-469E-B141-7B64113A9104\lite_installer.exe" --use-user-default-locale --silent --remote-url=http://downloader.yandex.net/downloadable_soft/browser/pseudoportal-ru/Yandex.exe --cumtom-welcome-page=https://browser.yandex.ru/promo/welcome_com/5/ --YABROWSER | C:\Users\admin\AppData\Local\Temp\AACA7EEC-83AC-469E-B141-7B64113A9104\lite_installer.exe | msiexec.exe | ||||||||||||
User: admin Company: Yandex Integrity Level: MEDIUM Description: YandexBrowserDownloader Exit code: 0 Version: 1.0.1.88 Modules
| |||||||||||||||
| (PID) Process: | (3460) Soft whatsapp app.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3460) Soft whatsapp app.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3460) Soft whatsapp app.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3460) Soft whatsapp app.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3500) 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3768 | YandexPackSetup.exe | C:\Users\admin\AppData\Local\Temp\{5B964E0E-B9A3-4276-9ED9-4D5A5720747A}\YandexSearch.msi | — | |
MD5:— | SHA256:— | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\_isetup\_isdecmp.dll | executable | |
MD5:077CB4461A2767383B317EB0C50F5F13 | SHA256:8287D0E287A66EE78537C8D1D98E426562B95C50F569B92CEA9CE36A9FA57E64 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\opera.bmp | image | |
MD5:9468DBFD6AE9045F5D6EBCBE67FF3E5F | SHA256:F125108D143D50EFA163AF030D5B68FE103169F7F997A59990041579CB455C24 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360ts.bmp | image | |
MD5:2DB08849B512035057611D30FA2E2573 | SHA256:59B4F968F8B70BFF5F9A6EEA612F37ECB9AA86D8CD6D9965635E487DBA071438 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\yandex.bmp | image | |
MD5:8CBFA701F863933D99EA14305277DE4A | SHA256:255D7326FEB416EFF18294799C01EA47960CA91DF2039835C83D987E3275EBF9 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\yaconf.txt | xml | |
MD5:1624F4A1E637E4A958CA214764AD4D02 | SHA256:69E56887CAF622CDA9BA6380BFC46BC08BA2E80361D9B087B79BF12D40B07F75 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | executable | |
MD5:1B2A7FC17F031879561BC73141C6EBEE | SHA256:E05412EC3BB86AAE3E71218C08D53FFD19F09FC1C5D971CFE08695C09668C01E | |||
| 3752 | msiexec.exe | C:\Windows\Installer\16fa14.msi | — | |
MD5:— | SHA256:— | |||
| 3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | C:\Users\admin\AppData\Local\Temp\{2FF2EAFF-E20C-4b9f-A10A-3118F3B749A6}.tmp | compressed | |
MD5:7D883E7A121DD2A690E3A04BB196DA6F | SHA256:9A54E77EDD072495D1A9C0BBA781F14C63F344EAAFA4F466D3DE770979691410 | |||
| 3460 | Soft whatsapp app.tmp | C:\Users\admin\AppData\Local\Temp\is-3IEG7.tmp\is-3174R.tmp | xml | |
MD5:1624F4A1E637E4A958CA214764AD4D02 | SHA256:69E56887CAF622CDA9BA6380BFC46BC08BA2E80361D9B087B79BF12D40B07F75 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3460 | Soft whatsapp app.tmp | GET | 302 | 5.45.205.243:80 | http://download.yandex.ru/yandex-pack/downloader/info.rss | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | 200 | 54.254.196.234:80 | http://s.360safe.com/360ts/mini_inst.htm?ver=6.6.0.1054&pid=RU.Omgm.CPI202204&os=6.1&mid=b8c075ec50c0ffb37ec9c97cc27794fb&state=153 | unknown | — | — | unknown |
3460 | Soft whatsapp app.tmp | GET | 302 | 5.45.205.241:80 | http://downloader.yandex.net/yandex-pack/7053/YandexPackSetup.exe | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | 200 | 54.254.196.234:80 | http://s.360safe.com/safei18n/query_env.htm?v611=DgY0MAEIfWmLLgABAABPECKefWzxVz%2F0v%2F94FVCJxQ5Yl7MpEbUzGzIPokeMfq4ubQXvrERDLcg6h67q9QIzckpfYqxK8eBryDYZu5BroHKIkFyCjwSb%2FtwBPmRBFfx8fY4N2nZrIiyXyBTyTPVQlYVxbrAHqQ43xG7kN40G2r%2FHREgUyXxf6eg4qqK%2FaPYCaKOtAG9jaPjQwjdj3%2BEN4%2FbEUAfEpyv%2FFYEme%2FAKtrrrcp7UWND0TUewcrGe%2B3wssnT8hZviNKhrS8%2FhG1qHsMhN2AmZ%2BLyqRFCO7D1ZjDV8kVbS2h6Ye%2BNkRtxk2zjk7uFJPAD%2FL1CgkQuZfh1OVNRD7VWWLs6A7KZsvVn7c6MmwDvBupuoVVFA7uSJCnDCDhEthNvutR%2FrZ7VHn6Bwwg4RLYTb7rUf62e1R5%2BgkG%2BXCfqNvhu4qWoCEc1%2Bn5Azs9sG3fcF9E30hs%2FrYvfZ5jhD6z4ShEveRxkV7wq6ihVoktjRNq4u6wiAhyklXg%3D%3D | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | 200 | 54.254.196.234:80 | http://s.360safe.com/safei18n/dimana.htm?lr=1&mid=b8c075ec50c0ffb37ec9c97cc27794fb&mod=360Installer.exe&ph=02a8342074eb25c8adb2d135e2bab7e5&p2p=1&t_id=360TS_Setup_For_Mini.cab&tads=655&tdl=655&tds=655&terr=0&tes=Status|1,ErrorCode|0,DnCount|5,HttpNum|1,DnFailCount|5,FStatus|1,P2SS|655,P2PS|0,PDMode|2&tfl=655&tp=t&tst=1&ttdl=655&ttm=1000&ttup=120&vh=1.3.0.1361&vp=1.3.0.1320&softname=360TS | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | — | 104.192.108.20:80 | http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1048.exe | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | — | 104.192.108.21:80 | http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1048.exe | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | — | 104.192.108.21:80 | http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1048.exe | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | — | 104.192.108.17:80 | http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1048.exe | unknown | — | — | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | GET | — | 104.192.108.17:80 | http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1048.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3460 | Soft whatsapp app.tmp | 5.45.205.243:80 | download.yandex.ru | YANDEX LLC | RU | whitelisted |
3460 | Soft whatsapp app.tmp | 185.70.202.14:80 | ext-cachev2-itt02.cdn.yandex.net | TELECOM ITALIA SPARKLE S.p.A. | IT | unknown |
3460 | Soft whatsapp app.tmp | 5.45.205.241:80 | download.yandex.ru | YANDEX LLC | RU | whitelisted |
3460 | Soft whatsapp app.tmp | 149.5.241.43:80 | ext-cachev2-cogent03.cdn.yandex.net | COGENT-174 | FR | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | 54.254.196.234:80 | s.360safe.com | AMAZON-02 | SG | unknown |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | 151.236.118.173:80 | iup.360safe.com | CDNetworks LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
download.yandex.ru |
| whitelisted |
ext-cachev2-itt02.cdn.yandex.net |
| whitelisted |
downloader.yandex.net |
| whitelisted |
ext-cachev2-cogent03.cdn.yandex.net |
| whitelisted |
st.p.360safe.com |
| unknown |
s.360safe.com |
| unknown |
iup.360safe.com |
| unknown |
tr.p.360safe.com |
| unknown |
int.down.360safe.com |
| unknown |
sd.p.360safe.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3460 | Soft whatsapp app.tmp | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
3460 | Soft whatsapp app.tmp | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
3460 | Soft whatsapp app.tmp | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
3460 | Soft whatsapp app.tmp | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3460 | Soft whatsapp app.tmp | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Generic Protocol Command Decode | ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag true) |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Generic Protocol Command Decode | ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag false) |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Generic Protocol Command Decode | ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag true change port flag false) |
3500 | 360TS_Setup_Mini_RU_Omgm_CPI202204_6.6.0.1054.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3716 | lite_installer.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
YandexPackSetup.exe | IsAlreadyRun() In
|
YandexPackSetup.exe | IsMSISrvFree() : OpenMutex() err ret = 2
|
YandexPackSetup.exe | GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1302019708-1500728564-335382590-1000
|
YandexPackSetup.exe | GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = USER-PC, dwSessionId = 1
|
YandexPackSetup.exe | IsMSISrvFree() In |
YandexPackSetup.exe | GetSidFromEnumSess(): LsaGetLogonSessionData(0) err = 5
|
YandexPackSetup.exe | IsMSISrvFree() Out ret = 1
|
YandexPackSetup.exe | IsAlreadyRun() Out : ret (BOOL) = 0
|
YandexPackSetup.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
YandexPackSetup.exe | GetSidFromEnumSess(): LsaGetLogonSessionData(0) err = 5
|