File name:

NordVPNSetup.exe

Full analysis: https://app.any.run/tasks/c3950ecb-3803-4426-af88-2d260693f84d
Verdict: Malicious activity
Analysis date: June 18, 2024, 18:30:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5D6F0577264346D7C28F1853871D89B7

SHA1:

A606FA6E79ED5CA473EED30CC8483901CA67FAE1

SHA256:

391B613C8DB8F21FE6545D6448ADB188DD2B54749F31E7CD7ABEFB6E61F388D2

SSDEEP:

49152:O7HecD4dnbibBlf8+XVUQ+c31Bfw2Jt+Cf1ZLwr9+QC2JiLA1KYPAQEb0bJAl5Hb:W+cD4dncBU482vor9+OE9bQfylxrlHC0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • NordVPNSetup.tmp (PID: 3856)
      • msiexec.exe (PID: 2856)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Creates a writable file in the system directory

      • NordUpdateService.exe (PID: 4028)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Actions looks like stealing of personal data

      • icacls.exe (PID: 2752)
      • icacls.exe (PID: 964)
      • icacls.exe (PID: 3036)
      • icacls.exe (PID: 940)
      • icacls.exe (PID: 3852)
      • icacls.exe (PID: 3416)
      • icacls.exe (PID: 2320)
      • icacls.exe (PID: 2556)
      • icacls.exe (PID: 4056)
      • netcfg.exe (PID: 2740)
      • NordVPNSetup.tmp (PID: 3856)
    • Changes the autorun value in the registry

      • drvinst.exe (PID: 2820)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • rundll32.exe (PID: 2696)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • netcfg.exe (PID: 2740)
      • drvinst.exe (PID: 4044)
    • Reads the Windows owner or organization settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
    • Adds/modifies Windows certificates

      • NordVPNSetup.tmp (PID: 680)
    • Reads the Internet Settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Reads settings of System Certificates

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • tapinstall.exe (PID: 3740)
    • Checks Windows Trust Settings

      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • NordVPNSetup.tmp (PID: 680)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads security settings of Internet Explorer

      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • NordVPNSetup.tmp (PID: 680)
      • tapinstall.exe (PID: 3740)
    • Searches for installed software

      • NordVPNSetup.tmp (PID: 3856)
    • Uses TASKKILL.EXE to kill process

      • NordVPNSetup.tmp (PID: 3856)
    • Process drops legitimate windows executable

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNSetup.tmp (PID: 3856)
    • Uses ICACLS.EXE to modify access control lists

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNSetup.tmp (PID: 3856)
    • Executes as Windows Service

      • NordUpdateService.exe (PID: 4028)
      • VSSVC.exe (PID: 3736)
      • nordvpn-service.exe (PID: 1992)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 1468)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2856)
      • rundll32.exe (PID: 2696)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • NordVPNSetup.tmp (PID: 3856)
      • netcfg.exe (PID: 2740)
      • drvinst.exe (PID: 4044)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Drops 7-zip archiver for unpacking

      • NordVPNSetup.tmp (PID: 3856)
    • The process drops C-runtime libraries

      • NordVPNSetup.tmp (PID: 3856)
  • INFO

    • Create files in a temporary directory

      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 3828)
      • msiexec.exe (PID: 2856)
      • tapinstall.exe (PID: 3740)
      • netcfg.exe (PID: 2740)
    • Checks supported languages

      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.tmp (PID: 3392)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • tapinstall.exe (PID: 2268)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads the computer name

      • NordVPNSetup.tmp (PID: 3392)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • tapinstall.exe (PID: 2268)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads the machine GUID from the registry

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads the software policy settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Creates files or folders in the user directory

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Reads Environment values

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • NordUpdateService.exe (PID: 4028)
      • drvinst.exe (PID: 2820)
    • Disables trace logs

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Creates files in the program directory

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNSetup.tmp (PID: 3856)
    • Creates a software uninstall entry

      • NordUpdaterSetup.tmp (PID: 1180)
      • msiexec.exe (PID: 2856)
      • NordVPNSetup.tmp (PID: 3856)
    • Application launched itself

      • msiexec.exe (PID: 2856)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2856)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2696)
      • netcfg.exe (PID: 2740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 123392
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.11.0
ProductVersionNumber: 0.0.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: NordVPN
FileDescription: NordVPN Web Installer
FileVersion: 0.0.11.0
LegalCopyright:
OriginalFileName:
ProductName: NordVPN
ProductVersion: 0.0.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
106
Monitored processes
40
Malicious processes
24
Suspicious processes
1

Behavior graph

Click at the process to see the details
start nordvpnsetup.exe nordvpnsetup.tmp no specs nordvpnsetup.exe nordvpnsetup.tmp nordvpnsetup.exe nordvpnsetup.tmp taskkill.exe no specs nordupdatersetup.exe nordupdatersetup.tmp icacls.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs nordupdateservice.exe nordvpntapsetup.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe tapinstall.exe no specs tapinstall.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs drvinst.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe netcfg.exe drvinst.exe rundll32.exe no specs nordvpn-service.exe no specs nordvpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Users\admin\AppData\Local\Temp\is-PI3NK.tmp\NordVPNSetup.tmp" /SL5="$6010A,890444,866304,C:\Users\admin\AppData\Local\Temp\NordVPNSetup.exe" /SPAWNWND=$F0168 /NOTIFYWND=$6015A C:\Users\admin\AppData\Local\Temp\is-PI3NK.tmp\NordVPNSetup.tmp
NordVPNSetup.exe
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pi3nk.tmp\nordvpnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
940"C:\Windows\system32\icacls.exe" "C:\Program Files\NordVPN" /inheritance:rC:\Windows\System32\icacls.exe
NordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
964"C:\Windows\system32\icacls.exe" C:\ProgramData\NordVPN /remove Users /TC:\Windows\System32\icacls.exe
NordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1180"C:\Users\admin\AppData\Local\Temp\is-HLHA6.tmp\NordUpdaterSetup.tmp" /SL5="$601BE,2008538,909824,C:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordUpdaterSetup.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTART /RESTARTEXITCODE=3010 /CLOSEAPPLICATIONSC:\Users\admin\AppData\Local\Temp\is-HLHA6.tmp\NordUpdaterSetup.tmp
NordUpdaterSetup.exe
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hlha6.tmp\nordupdatersetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1468C:\Windows\system32\MsiExec.exe -Embedding 33DC865FD04052E89FF574BB1156535CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1524"C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /grant *S-1-5-18:(OI)(CI)(F)C:\Windows\System32\icacls.exeNordUpdaterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1820C:\Windows\system32\MsiExec.exe -Embedding A1A4F1B7635E31F88103341A42E971D9 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1992"C:\Program Files\NordVPN\nordvpn-service.exe"C:\Program Files\NordVPN\nordvpn-service.exeservices.exe
User:
SYSTEM
Company:
TEFINCOM S.A.
Integrity Level:
SYSTEM
Description:
NordVPN
Version:
1.0.2.26
2268"C:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exe" hwids tapnordvpnC:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exerundll32.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\nordvpn network tap\bin\i386\tapinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2276"C:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordVPNTapSetup.exe" /qn /norestartC:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordVPNTapSetup.exe
NordVPNSetup.tmp
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
NordVPN network TAP Installer
Exit code:
0
Version:
1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\is-0rbmu.tmp\nordvpntapsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
58 282
Read events
57 371
Write events
822
Delete events
89

Modification events

(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A8020000AEC35191ADC1DA01
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8CF68F4511B4B00A6BB8976489E3558DF103542A8BE4A1D446D3A993140D67DA
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Value:
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
0400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE7F0000000100000016000000301406082B0601050507030306082B06010505070309090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703080F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF10300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD11D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A06200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF690B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D00200052003600000053000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD7A000000010000000C000000300A06082B060105050703097E00000001000000080000000080C82B6886D701200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
5C0000000100000004000000001000007E00000001000000080000000080C82B6886D7017A000000010000000C000000300A06082B06010505070309190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD53000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200360000006200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF69140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A01D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF0300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD10F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF1090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703087F0000000100000016000000301406082B0601050507030306082B060105050703090400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:D69B561148F01C77C54578C10926DF5B856976AD
Value:
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Operation:writeName:Blob
Value:
040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB028090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA9531400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C02000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Operation:writeName:Blob
Value:
5C000000010000000400000000080000530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD0F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B06010505070308040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0282000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
Executable files
635
Suspicious files
155
Text files
91
Unknown types
23

Dropped files

PID
Process
Filename
Type
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-AND9S.tmp\is-NRIBS.tmp
MD5:
SHA256:
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-AND9S.tmp\NordVPNSetup.exe
MD5:
SHA256:
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-AND9S.tmp\Nord.Setup.dllexecutable
MD5:D9D4E2634AF0B4E81D473E5A76DF357F
SHA256:E897C29355A0E81E55FD9F8C74B52810A065E9E8C37A4C2ED813EFB846C9E89F
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\CabE82A.tmpcompressed
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
3268NordVPNSetup.exeC:\Users\admin\AppData\Local\Temp\is-BR4FA.tmp\NordVPNSetup.tmpexecutable
MD5:6693DDACA0479CDEEA33386155E9CACF
SHA256:384DAB757AF95F6D6D4A80351507F6F455C0FCE58F2AA32FF1C1E8CEEB3ADE82
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\439F613B3D55693954E1B080DE3085B4_C4927E03400A4F6EDB9D613E6354F864der
MD5:4089DAC9BBFA0897E1482828B678667C
SHA256:C8FB62C72E9CEB646FC2C2AC99E663D26BF148EDA8216E715D381FA4AFC83FC2
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_D21903E2722B551F252C717985D24037der
MD5:EF92D6AEB37F700CBB5291A3118EF4C3
SHA256:53BF4D87B8C08B354AC1496D22C8E01B72210DE88EFAF7DD3F80968927801371
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\439F613B3D55693954E1B080DE3085B4_C4927E03400A4F6EDB9D613E6354F864binary
MD5:9D41734A181EB795E19204C4D51950BB
SHA256:6EDBF198D070AFF68CD0C794B131016EB0D91AB2250783D89E676B08129984C9
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\357F04AD41BCF5FE18FCB69F60C6680F_59F1658D90E38DA89AB56C23C0E7D055binary
MD5:39916F9B77BCEB74E1686F4EFD1E1E23
SHA256:AEA161949A4700279C6CE5671C4740E118139A1FF496783FA7E7AF29AFB33EA4
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\48B35517638A85CA46010B026C2B955A_EA1CE828C73D50A657100E303A2437C4binary
MD5:B33544B200E10D9AD340BED253C994B5
SHA256:1A2542C1132415914C3E6F6A608C534B5AA8E6D51BB7A4A83ED033EAD510620C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
53
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1060
svchost.exe
GET
304
23.216.77.72:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5445ebff82c5850f
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDF2zq5W4nUrgkGCLSg%3D%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr6/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBRi%2B7TJbHYn9EmJ9W03lecB7P%2BG7QQUrmwFo5MT4qLn4tcc1sfwf8hnU6ACDQHsHJJA3v0uQF18R3Q%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/ca/gstsacasha384g4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS2enBWzCNkWKN%2FFhoLZmlPnDczoAQU6hbGaefjy1dFOTOk8EC%2B0MO9ZZYCEAEZdXRxyZLXRN%2Blluu5cBU%3D
unknown
unknown
1372
svchost.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
680
NordVPNSetup.tmp
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
unknown
4028
NordUpdateService.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
680
NordVPNSetup.tmp
104.18.20.226:80
secure.globalsign.com
CLOUDFLARENET
shared
680
NordVPNSetup.tmp
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
680
NordVPNSetup.tmp
104.19.159.190:443
api.nordvpn.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.156.111:443
downloads.nordcdn.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.168.111:443
applytics.zwyr157wwiu6eior.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.167.111:443
applytics.zwyr157wwiu6eior.com
CLOUDFLARENET
unknown
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
secure.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.69
  • 23.216.77.80
  • 23.216.77.72
  • 23.216.77.44
whitelisted
api.nordvpn.com
  • 104.19.159.190
  • 104.16.208.203
unknown
applytics.zwyr157wwiu6eior.com
  • 104.16.167.111
  • 104.16.168.111
unknown
downloads.nordcdn.com
  • 104.16.156.111
  • 104.16.155.111
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted

Threats

No threats detected
No debug info