File name:

Des1ktop.rar

Full analysis: https://app.any.run/tasks/a67d24c5-c762-4e0a-838e-38bb0914f459
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 10, 2024, 22:29:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
antivm
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

981E6CE8E58B76A3F9AFCE17FDABDAC7

SHA1:

4DE620305C76B8C2E64DA7FE05B76B7B7AE0518D

SHA256:

3B01119E69C70BBCF2FE98A9BE075A194EEB0CA7522C9864B30D9182E69B2BFE

SSDEEP:

98304:rjGbZMtPTGyVZfQHXhGxKmVenbxfkn9lfzIywroKyUuriQ/YWa38QXZXNHV548Eo:VzVDTbr4Mdt7+7rp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • UninstallTool_x64.dat (PID: 3068)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6512)
      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool_x64.dat (PID: 3068)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6512)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6512)
      • UninstallTool_x64.dat (PID: 3068)
    • The process creates files with name similar to system file names

      • UninstallToolPortable.exe (PID: 4708)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • UninstallToolPortable.exe (PID: 4708)
    • Executable content was dropped or overwritten

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool_x64.dat (PID: 3068)
    • Reads security settings of Internet Explorer

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool.exe (PID: 6816)
      • UninstallTool_x64.dat (PID: 3068)
    • Reads the date of Windows installation

      • UninstallTool.exe (PID: 6816)
      • UninstallTool_x64.dat (PID: 3068)
    • Application launched itself

      • UninstallTool.exe (PID: 6816)
      • cmd.exe (PID: 6444)
    • Starts application with an unusual extension

      • UninstallTool.exe (PID: 5540)
    • Searches for installed software

      • UninstallTool_x64.dat (PID: 3068)
    • Checks Windows Trust Settings

      • UninstallTool_x64.dat (PID: 3068)
    • Adds/modifies Windows certificates

      • UninstallTool_x64.dat (PID: 3068)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 6444)
      • SkuzyHack.exe (PID: 5052)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 6444)
    • Executing commands from a ".bat" file

      • SkuzyHack.exe (PID: 5052)
    • Accesses product unique identifier via WMI (SCRIPT)

      • WMIC.exe (PID: 6516)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 5072)
    • There is functionality for VM detection (antiVM strings)

      • UninstallTool_x64.dat (PID: 3068)
    • Creates files in the driver directory

      • UninstallTool_x64.dat (PID: 3068)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 5088)
  • INFO

    • Manual execution by a user

      • UninstallToolPortable.exe (PID: 4708)
      • notepad.exe (PID: 5900)
    • Checks supported languages

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool.exe (PID: 6816)
      • UninstallTool.exe (PID: 5540)
      • UninstallTool_x64.dat (PID: 3068)
      • msiexec.exe (PID: 2508)
      • SkuzyHack.exe (PID: 5052)
      • TextInputHost.exe (PID: 2240)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6512)
    • Create files in a temporary directory

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool_x64.dat (PID: 3068)
      • SkuzyHack.exe (PID: 5052)
    • Reads the computer name

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool.exe (PID: 6816)
      • UninstallTool_x64.dat (PID: 3068)
      • msiexec.exe (PID: 2508)
      • TextInputHost.exe (PID: 2240)
    • Creates files or folders in the user directory

      • UninstallToolPortable.exe (PID: 4708)
      • UninstallTool_x64.dat (PID: 3068)
    • Process checks whether UAC notifications are on

      • UninstallTool.exe (PID: 6816)
      • UninstallTool.exe (PID: 5540)
    • Process checks computer location settings

      • UninstallTool.exe (PID: 6816)
      • UninstallTool_x64.dat (PID: 3068)
    • Reads the machine GUID from the registry

      • UninstallTool_x64.dat (PID: 3068)
    • Reads the software policy settings

      • UninstallTool_x64.dat (PID: 3068)
    • Checks proxy server information

      • UninstallTool_x64.dat (PID: 3068)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 1044)
      • WMIC.exe (PID: 6516)
      • notepad.exe (PID: 5900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

MPEG

MPEGAudioVersion: 2
AudioLayer: 3
AudioBitrate: 128 kbps
SampleRate: 22050
ChannelMode: Dual Channel
MSStereo: On
IntensityStereo: Off
CopyrightFlag:
OriginalMedia: -
Emphasis: CCIT J.17

Composite

Duration: 0:06:49 (approx)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
28
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs uninstalltoolportable.exe uninstalltool.exe no specs uninstalltool.exe THREAT uninstalltool_x64.dat uninstalltoolhelper.exe no specs msiexec.exe no specs skuzyhack.exe no specs conhost.exe no specs cmd.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs textinputhost.exe no specs timeout.exe no specs openwith.exe no specs timeout.exe no specs cmd.exe no specs wmic.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs notepad.exe no specs schtasks.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\Desktop\UninstallToolPortable\App\Uninstall Tool\UninstallToolHelper.exe" /pid:3068C:\Users\admin\Desktop\UninstallToolPortable\App\Uninstall Tool\UninstallToolHelper.exeUninstallTool_x64.dat
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool Helper Process
Exit code:
0
Version:
1, 1, 17, 5
Modules
Images
c:\users\admin\desktop\uninstalltoolportable\app\uninstall tool\uninstalltoolhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1044C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1116timeout /t 3 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1680timeout /t 3 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1716timeout /t 2 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1792timeout /t 3 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2240"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2508C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3068"C:\Users\admin\Desktop\UninstallToolPortable\App\Uninstall Tool\UninstallTool_x64.dat"C:\Users\admin\Desktop\UninstallToolPortable\App\Uninstall Tool\UninstallTool_x64.dat
UninstallTool.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool
Exit code:
0
Version:
3.7.4.5725
Modules
Images
c:\users\admin\desktop\uninstalltoolportable\app\uninstall tool\uninstalltool_x64.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4088\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSkuzyHack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
28 184
Read events
28 014
Write events
148
Delete events
22

Modification events

(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Des1ktop.rar
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF330100005E000000F304000047020000
(PID) Process:(6512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
23
Suspicious files
11
Text files
54
Unknown types
0

Dropped files

PID
Process
Filename
Type
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Portable by TryRooM.txttext
MD5:5D9257139AEB819F9406B8128E0AA9F0
SHA256:864540E32B8E80FE98B38FD9547DFEEC97205A1C298E1FA28EC0294C92653396
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Belarusian.xmlxml
MD5:F45BD67669A87633385F196722756EF6
SHA256:8758D0CBCFA35F0BE9FE8D6ED724129DBC9EB0EAA211248D84AF3DA943B8EBB1
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Czech.xmlxml
MD5:060F73E2AC79CB9098830194FB24FF56
SHA256:5CD2562FC92E38240B0B4D4605BF6E818C6F4E70E184CE24E4DA5A9405706B51
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Chinese_Traditional.xmlxml
MD5:1A906251E766E5C7008C59E447A5AAD9
SHA256:BB302E8D618B49A7F158FDDD70020AE7057E9646D7352D3C4E25000DE2A054F1
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Danish.xmlxml
MD5:1140B3A8EAC03B8EB044174FE3DBD936
SHA256:949863F8F81ED4463ED9D4D035360408CDFDFD591A31FF3EE368D4D849AAB1BB
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Greek.xmlxml
MD5:B166E5B75086030EABD739D1A6ED2BF0
SHA256:5704980557EEDE8F1A911A069F6E9CDB1D466555F5BEDCCFDC8C7EDE73FCF3AF
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Estonian.xmlxml
MD5:9445056A7668007A7316F9F924DFEA2B
SHA256:B1216398DB076C306D4A59117CEAE889D031D4D1CA4371413A3F6D5823377E34
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Dutch.xmlxml
MD5:05E04A1604C4A3DC35743FAE19154E65
SHA256:5A7082C2E8E709DECD7E08AEDBBC956B6187F07E40D770785335C46A4E686989
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\Hindi.xmlxml
MD5:9065D8B59D19EA5AF0736950D80FBB2E
SHA256:20D9293113326C83A731592BEE0FBE711466F7F272D11D3E03905AA6B07D692F
6512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6512.32019\UninstallToolPortable\App\Uninstall Tool\languages\French.xmlxml
MD5:DBA0671B22C1D6A9557D0E7250F63905
SHA256:73ED44CA5E37D2078006DFEB060421BE8F7781A4DF85D2E1CA5F7D33FC33D559
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
46
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6924
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6980
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3068
UninstallTool_x64.dat
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
3068
UninstallTool_x64.dat
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
3068
UninstallTool_x64.dat
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDfD%2FoApQz6Tjifa39Nky1P
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2572
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3268
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
3268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3812
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.23.209.182
  • 2.23.209.150
  • 2.23.209.189
  • 2.23.209.176
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.133
  • 2.23.209.185
  • 2.23.209.193
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.76
  • 40.126.32.68
  • 20.190.160.17
  • 20.190.160.14
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
th.bing.com
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.182
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.140
  • 2.23.209.189
  • 2.23.209.149
  • 2.23.209.133
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info