File name:

NordVPNSetup.exe

Full analysis: https://app.any.run/tasks/c3950ecb-3803-4426-af88-2d260693f84d
Verdict: Malicious activity
Analysis date: June 18, 2024, 18:30:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5D6F0577264346D7C28F1853871D89B7

SHA1:

A606FA6E79ED5CA473EED30CC8483901CA67FAE1

SHA256:

391B613C8DB8F21FE6545D6448ADB188DD2B54749F31E7CD7ABEFB6E61F388D2

SSDEEP:

49152:O7HecD4dnbibBlf8+XVUQ+c31Bfw2Jt+Cf1ZLwr9+QC2JiLA1KYPAQEb0bJAl5Hb:W+cD4dncBU482vor9+OE9bQfylxrlHC0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Creates a writable file in the system directory

      • NordUpdateService.exe (PID: 4028)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Actions looks like stealing of personal data

      • icacls.exe (PID: 3036)
      • icacls.exe (PID: 964)
      • icacls.exe (PID: 2752)
      • icacls.exe (PID: 3852)
      • icacls.exe (PID: 2556)
      • NordVPNSetup.tmp (PID: 3856)
      • icacls.exe (PID: 4056)
      • icacls.exe (PID: 2320)
      • netcfg.exe (PID: 2740)
      • icacls.exe (PID: 3416)
      • icacls.exe (PID: 940)
    • Changes the autorun value in the registry

      • drvinst.exe (PID: 2820)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • rundll32.exe (PID: 2696)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • tapinstall.exe (PID: 3740)
      • netcfg.exe (PID: 2740)
      • drvinst.exe (PID: 4044)
    • Reads the Windows owner or organization settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
    • Reads settings of System Certificates

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • tapinstall.exe (PID: 3740)
    • Reads the Internet Settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Checks Windows Trust Settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads security settings of Internet Explorer

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • tapinstall.exe (PID: 3740)
    • Searches for installed software

      • NordVPNSetup.tmp (PID: 3856)
    • Uses TASKKILL.EXE to kill process

      • NordVPNSetup.tmp (PID: 3856)
    • Adds/modifies Windows certificates

      • NordVPNSetup.tmp (PID: 680)
    • Process drops legitimate windows executable

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNSetup.tmp (PID: 3856)
    • Uses ICACLS.EXE to modify access control lists

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNSetup.tmp (PID: 3856)
    • Executes as Windows Service

      • NordUpdateService.exe (PID: 4028)
      • VSSVC.exe (PID: 3736)
      • nordvpn-service.exe (PID: 1992)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2856)
      • rundll32.exe (PID: 2696)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 3560)
      • NordVPNSetup.tmp (PID: 3856)
      • drvinst.exe (PID: 2820)
      • netcfg.exe (PID: 2740)
      • drvinst.exe (PID: 4044)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 1468)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 4044)
    • Drops 7-zip archiver for unpacking

      • NordVPNSetup.tmp (PID: 3856)
    • The process drops C-runtime libraries

      • NordVPNSetup.tmp (PID: 3856)
  • INFO

    • Create files in a temporary directory

      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3580)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 3828)
      • msiexec.exe (PID: 2856)
      • tapinstall.exe (PID: 3740)
      • netcfg.exe (PID: 2740)
    • Checks supported languages

      • NordVPNSetup.tmp (PID: 3392)
      • NordVPNSetup.exe (PID: 3192)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.exe (PID: 3268)
      • NordVPNSetup.exe (PID: 3580)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.exe (PID: 4012)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • msiexec.exe (PID: 2856)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • tapinstall.exe (PID: 3740)
      • tapinstall.exe (PID: 2268)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Reads the computer name

      • NordVPNSetup.tmp (PID: 3392)
      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • msiexec.exe (PID: 2856)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • tapinstall.exe (PID: 2268)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 4044)
    • Disables trace logs

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Reads the software policy settings

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 4044)
    • Creates files or folders in the user directory

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
    • Reads Environment values

      • NordVPNSetup.tmp (PID: 680)
      • NordVPNSetup.tmp (PID: 3856)
      • NordVPNTapSetup.exe (PID: 2276)
      • NordUpdateService.exe (PID: 4028)
      • drvinst.exe (PID: 2820)
    • Reads the machine GUID from the registry

      • NordVPNSetup.tmp (PID: 3856)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNTapSetup.exe (PID: 2276)
      • msiexec.exe (PID: 2856)
      • msiexec.exe (PID: 1820)
      • msiexec.exe (PID: 1468)
      • NordVPNSetup.tmp (PID: 680)
      • tapinstall.exe (PID: 3740)
      • drvinst.exe (PID: 2820)
      • drvinst.exe (PID: 3560)
      • drvinst.exe (PID: 4044)
    • Creates files in the program directory

      • NordUpdaterSetup.tmp (PID: 1180)
      • NordUpdateService.exe (PID: 4028)
      • NordVPNSetup.tmp (PID: 3856)
    • Creates a software uninstall entry

      • NordUpdaterSetup.tmp (PID: 1180)
      • msiexec.exe (PID: 2856)
      • NordVPNSetup.tmp (PID: 3856)
    • Application launched itself

      • msiexec.exe (PID: 2856)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2856)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2696)
      • netcfg.exe (PID: 2740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 123392
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.11.0
ProductVersionNumber: 0.0.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: NordVPN
FileDescription: NordVPN Web Installer
FileVersion: 0.0.11.0
LegalCopyright:
OriginalFileName:
ProductName: NordVPN
ProductVersion: 0.0.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
106
Monitored processes
40
Malicious processes
24
Suspicious processes
1

Behavior graph

Click at the process to see the details
start nordvpnsetup.exe nordvpnsetup.tmp no specs nordvpnsetup.exe nordvpnsetup.tmp nordvpnsetup.exe nordvpnsetup.tmp taskkill.exe no specs nordupdatersetup.exe nordupdatersetup.tmp icacls.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs nordupdateservice.exe nordvpntapsetup.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe tapinstall.exe no specs tapinstall.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs drvinst.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe icacls.exe netcfg.exe drvinst.exe rundll32.exe no specs nordvpn-service.exe no specs nordvpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Users\admin\AppData\Local\Temp\is-PI3NK.tmp\NordVPNSetup.tmp" /SL5="$6010A,890444,866304,C:\Users\admin\AppData\Local\Temp\NordVPNSetup.exe" /SPAWNWND=$F0168 /NOTIFYWND=$6015A C:\Users\admin\AppData\Local\Temp\is-PI3NK.tmp\NordVPNSetup.tmp
NordVPNSetup.exe
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pi3nk.tmp\nordvpnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
940"C:\Windows\system32\icacls.exe" "C:\Program Files\NordVPN" /inheritance:rC:\Windows\System32\icacls.exe
NordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
964"C:\Windows\system32\icacls.exe" C:\ProgramData\NordVPN /remove Users /TC:\Windows\System32\icacls.exe
NordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1180"C:\Users\admin\AppData\Local\Temp\is-HLHA6.tmp\NordUpdaterSetup.tmp" /SL5="$601BE,2008538,909824,C:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordUpdaterSetup.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTART /RESTARTEXITCODE=3010 /CLOSEAPPLICATIONSC:\Users\admin\AppData\Local\Temp\is-HLHA6.tmp\NordUpdaterSetup.tmp
NordUpdaterSetup.exe
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hlha6.tmp\nordupdatersetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1468C:\Windows\system32\MsiExec.exe -Embedding 33DC865FD04052E89FF574BB1156535CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1524"C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /grant *S-1-5-18:(OI)(CI)(F)C:\Windows\System32\icacls.exeNordUpdaterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1820C:\Windows\system32\MsiExec.exe -Embedding A1A4F1B7635E31F88103341A42E971D9 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1992"C:\Program Files\NordVPN\nordvpn-service.exe"C:\Program Files\NordVPN\nordvpn-service.exeservices.exe
User:
SYSTEM
Company:
TEFINCOM S.A.
Integrity Level:
SYSTEM
Description:
NordVPN
Version:
1.0.2.26
2268"C:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exe" hwids tapnordvpnC:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exerundll32.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\nordvpn network tap\bin\i386\tapinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2276"C:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordVPNTapSetup.exe" /qn /norestartC:\Users\admin\AppData\Local\Temp\is-0RBMU.tmp\NordVPNTapSetup.exe
NordVPNSetup.tmp
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
NordVPN network TAP Installer
Exit code:
0
Version:
1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\is-0rbmu.tmp\nordvpntapsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
58 282
Read events
57 371
Write events
822
Delete events
89

Modification events

(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A8020000AEC35191ADC1DA01
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8CF68F4511B4B00A6BB8976489E3558DF103542A8BE4A1D446D3A993140D67DA
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Value:
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
0400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE7F0000000100000016000000301406082B0601050507030306082B06010505070309090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703080F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF10300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD11D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A06200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF690B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D00200052003600000053000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD7A000000010000000C000000300A06082B060105050703097E00000001000000080000000080C82B6886D701200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
5C0000000100000004000000001000007E00000001000000080000000080C82B6886D7017A000000010000000C000000300A06082B06010505070309190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD53000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200360000006200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF69140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A01D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF0300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD10F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF1090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703087F0000000100000016000000301406082B0601050507030306082B060105050703090400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:D69B561148F01C77C54578C10926DF5B856976AD
Value:
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Operation:writeName:Blob
Value:
040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB028090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA9531400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C02000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
(PID) Process:(680) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Operation:writeName:Blob
Value:
5C000000010000000400000000080000530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD0F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B06010505070308040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0282000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
Executable files
635
Suspicious files
155
Text files
91
Unknown types
23

Dropped files

PID
Process
Filename
Type
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-AND9S.tmp\is-NRIBS.tmp
MD5:
SHA256:
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-AND9S.tmp\NordVPNSetup.exe
MD5:
SHA256:
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\TarE82B.tmpbinary
MD5:4EA6026CF93EC6338144661BF1202CD1
SHA256:8EFBC21559EF8B1BCF526800D8070BAAD42474CE7198E26FA771DBB41A76B1D8
3268NordVPNSetup.exeC:\Users\admin\AppData\Local\Temp\is-BR4FA.tmp\NordVPNSetup.tmpexecutable
MD5:6693DDACA0479CDEEA33386155E9CACF
SHA256:384DAB757AF95F6D6D4A80351507F6F455C0FCE58F2AA32FF1C1E8CEEB3ADE82
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5C8CC0A7FE31816B4641D0465402560binary
MD5:9163156545CF185BAE15224B2D074D78
SHA256:50C7D766C384D777FDD4F9A9719F88920BDA81CF134F5E8ED61CB2CFF9B7C6F7
3192NordVPNSetup.exeC:\Users\admin\AppData\Local\Temp\is-PI3NK.tmp\NordVPNSetup.tmpexecutable
MD5:6693DDACA0479CDEEA33386155E9CACF
SHA256:384DAB757AF95F6D6D4A80351507F6F455C0FCE58F2AA32FF1C1E8CEEB3ADE82
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C8CC0A7FE31816B4641D0465402560binary
MD5:E94FB54871208C00DF70F708AC47085B
SHA256:7B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF86
680NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\CabE82A.tmpcompressed
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
680NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_59F1658D90E38DA89AB56C23C0E7D055binary
MD5:10E97C3CF5325222F60AA39521D8B82B
SHA256:334DD3A1593D5DF2525B1D53B654AE46A4E956039F1D5F8DB581348BBB917CB8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
53
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://secure.globalsign.com/cacert/codesigningrootr45.crt
unknown
unknown
680
NordVPNSetup.tmp
GET
200
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?674ab44182650220
unknown
unknown
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1060
svchost.exe
GET
304
23.216.77.72:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5445ebff82c5850f
unknown
unknown
1372
svchost.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr6/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBRi%2B7TJbHYn9EmJ9W03lecB7P%2BG7QQUrmwFo5MT4qLn4tcc1sfwf8hnU6ACDQHsHJJA3v0uQF18R3Q%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDF2zq5W4nUrgkGCLSg%3D%3D
unknown
unknown
680
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/ca/gstsacasha384g4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS2enBWzCNkWKN%2FFhoLZmlPnDczoAQU6hbGaefjy1dFOTOk8EC%2B0MO9ZZYCEAEZdXRxyZLXRN%2Blluu5cBU%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
680
NordVPNSetup.tmp
104.18.20.226:80
secure.globalsign.com
CLOUDFLARENET
shared
680
NordVPNSetup.tmp
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
680
NordVPNSetup.tmp
104.19.159.190:443
api.nordvpn.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.156.111:443
downloads.nordcdn.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.168.111:443
applytics.zwyr157wwiu6eior.com
CLOUDFLARENET
unknown
680
NordVPNSetup.tmp
104.16.167.111:443
applytics.zwyr157wwiu6eior.com
CLOUDFLARENET
unknown
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
secure.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.69
  • 23.216.77.80
  • 23.216.77.72
  • 23.216.77.44
whitelisted
api.nordvpn.com
  • 104.19.159.190
  • 104.16.208.203
unknown
applytics.zwyr157wwiu6eior.com
  • 104.16.167.111
  • 104.16.168.111
unknown
downloads.nordcdn.com
  • 104.16.156.111
  • 104.16.155.111
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted

Threats

No threats detected
No debug info