File name:

Ultimate Turbo V2.zip

Full analysis: https://app.any.run/tasks/987340b7-59d8-4329-9dbe-99391777b58a
Verdict: Malicious activity
Analysis date: May 28, 2025, 13:52:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

A314F3F717A31330376ECE260555B66D

SHA1:

4080EB1760F8B4AF44FA55283309111772D59DB0

SHA256:

3B6061A96B4E31509C6CC4D15AE099C02C5DEC767532665A85E09CF3DA0FB9E0

SSDEEP:

384:Flz4ZQEU15KbZWaEjhRXB80Fiqns1Sy9S4hpz3j4HK:FpWQp15daEjhRTFiseHVhpgHK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • cmd.exe (PID: 7832)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4868)
    • Starts NET.EXE to display or manage information about active sessions

      • cmd.exe (PID: 7396)
      • net.exe (PID: 7336)
      • net.exe (PID: 1096)
      • cmd.exe (PID: 1128)
      • net.exe (PID: 7756)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4776)
      • net.exe (PID: 8052)
    • Application launched itself

      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 1128)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 8032)
      • cmd.exe (PID: 4776)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 4884)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 1128)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 1128)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 8032)
      • cmd.exe (PID: 6660)
      • forfiles.exe (PID: 4244)
      • forfiles.exe (PID: 1348)
      • forfiles.exe (PID: 8064)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 4776)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 5964)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 5164)
      • cmd.exe (PID: 5956)
    • Windows service management via SC.EXE

      • sc.exe (PID: 8052)
      • sc.exe (PID: 4728)
      • sc.exe (PID: 6760)
      • sc.exe (PID: 6572)
      • sc.exe (PID: 8180)
      • sc.exe (PID: 5156)
      • sc.exe (PID: 5200)
      • sc.exe (PID: 7832)
      • sc.exe (PID: 8136)
      • sc.exe (PID: 7528)
      • sc.exe (PID: 7596)
      • sc.exe (PID: 7556)
      • sc.exe (PID: 7400)
      • sc.exe (PID: 7448)
      • sc.exe (PID: 7312)
      • sc.exe (PID: 7488)
    • Stops a currently running service

      • sc.exe (PID: 8064)
      • sc.exe (PID: 7992)
      • sc.exe (PID: 4652)
      • sc.exe (PID: 7388)
      • sc.exe (PID: 6640)
      • sc.exe (PID: 7544)
      • sc.exe (PID: 7524)
      • sc.exe (PID: 7472)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 1128)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 1128)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4776)
      • cmd.exe (PID: 4868)
    • Hides command output

      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 8032)
      • cmd.exe (PID: 4012)
      • powercfg.exe (PID: 3888)
      • powercfg.exe (PID: 7748)
      • cmd.exe (PID: 5892)
    • Searches and executes a command on selected files

      • forfiles.exe (PID: 4244)
      • forfiles.exe (PID: 8064)
      • forfiles.exe (PID: 1348)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4776)
    • Uses powercfg.exe to modify the power settings

      • cmd.exe (PID: 4012)
      • cmd.exe (PID: 5892)
    • Process uses IPCONFIG to clear DNS cache

      • cmd.exe (PID: 4884)
    • Process uses IPCONFIG to discard the IP address configuration

      • cmd.exe (PID: 4884)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 4884)
    • Process uses IPCONFIG to renew DHCP configuration

      • cmd.exe (PID: 4884)
  • INFO

    • Manual execution by a user

      • regedit.exe (PID: 5244)
      • regedit.exe (PID: 2504)
      • cmd.exe (PID: 7832)
      • regedit.exe (PID: 8176)
      • regedit.exe (PID: 5008)
      • regedit.exe (PID: 4008)
      • regedit.exe (PID: 1660)
      • regedit.exe (PID: 4988)
      • regedit.exe (PID: 3888)
      • regedit.exe (PID: 2148)
      • regedit.exe (PID: 1676)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 1128)
      • notepad.exe (PID: 7612)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4776)
      • cmd.exe (PID: 4868)
    • Checks supported languages

      • chcp.com (PID: 7896)
      • chcp.com (PID: 7344)
    • Changes the display of characters in the console

      • cmd.exe (PID: 7832)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 4884)
      • cmd.exe (PID: 4868)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 6576)
      • WMIC.exe (PID: 3956)
    • Create files in a temporary directory

      • reg.exe (PID: 7612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:05:25 15:19:00
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Ultimate Turbo V2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
712
Monitored processes
567
Malicious processes
4
Suspicious processes
6

Behavior graph

Click at the process to see the details
start winrar.exe no specs sppextcomobj.exe no specs slui.exe rundll32.exe no specs cmd.exe conhost.exe no specs chcp.com no specs regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe cmd.exe conhost.exe no specs chcp.com no specs net.exe no specs net1.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs findstr.exe no specs timeout.exe no specs cmd.exe conhost.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs wmic.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs slui.exe reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs sc.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs notepad.exe no specs cmd.exe conhost.exe no specs chcp.com no specs net.exe no specs net1.exe no specs cmd.exe no specs wmic.exe no specs bcdedit.exe no specs bcdedit.exe no specs findstr.exe no specs bcdedit.exe no specs bcdedit.exe no specs bcdedit.exe no specs findstr.exe no specs bcdedit.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs forfiles.exe no specs find.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs forfiles.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs forfiles.exe no specs cmd.exe no specs ipconfig.exe no specs ipconfig.exe no specs ipconfig.exe no specs ipconfig.exe no specs reg.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe conhost.exe no specs cmd.exe no specs wmic.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs powercfg.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs cmd.exe no specs powercfg.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs reg.exe no specs cmd.exe conhost.exe no specs chcp.com no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132/c del /q /f "C:\WINDOWS\Prefetch\SIHOST.EXE-2C4C53BA.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
208/c echo "SETUP.EXE-02E2ADB1.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
232/c echo "RUNDLL32.EXE-D818865A.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
236/c echo "AgGlFaultHistory.db"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
236/c del /q /f "C:\WINDOWS\Prefetch\CHROME.EXE-5A1054B1.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
236/c del /q /f "C:\WINDOWS\Prefetch\SKYPE.EXE-72459440.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
300/c echo "SVCHOST.EXE-62975899.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
444/c del /q /f "C:\WINDOWS\Prefetch\CHROME.EXE-5A1054B0.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
456/c echo "DLLHOST.EXE-041F1888.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
496/c echo "RUNTIMEBROKER.EXE-D128F7A3.pf"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 934
Read events
16 809
Write events
89
Delete events
36

Modification events

(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ultimate Turbo V2.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
0
Suspicious files
0
Text files
59
Unknown types
0

Dropped files

PID
Process
Filename
Type
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\1-Tutorial pt-br.txttext
MD5:35C957DAE2C32C5FFE0B57CCC8ED03C2
SHA256:B36EEEA26F0F03B474FF4AAAD5BED9952F9A224D44F0A593778F7A41B0233DF1
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\Backup-Point.battext
MD5:24C6E42357AA75F8F0F798ED02FB5E61
SHA256:0DC7387B5E3B38EAF171281D076334ABCCF98CCF2A82805E83404006349156DC
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\1-Bat Optimizations\1-Windows-Settings.battext
MD5:1A774CE6DE5135B0F0F9954DAC3D2794
SHA256:94C45602E0D6C540B9AC73F11898E8FA3AD2C2C73C23B5B308D1DA09B434B258
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\remove-ini-programs.battext
MD5:45C4E1D98773182A5C3E74F2F5B29197
SHA256:CC073D2F6E507F82AEA27C67449538BC3211CBF3A372AF894CC96B89AC17196B
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\Program-Uninstall.battext
MD5:9956650A570EF6F238FFD78D1DB48A80
SHA256:FE7C8A4C3120291B779DA7A320DCFC58A7A9BAA7E274EC583B7AD511B14119C9
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\0-Dont touch here.txttext
MD5:8272FA2AC4EF66ECB211AE04506D21E0
SHA256:10BAC4E093DF4BD0B19CE0BA6DA8D3CEF23E04B8433444494F4CAE158E063F83
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\0-Startup\0-Não mexa nessa pasta.txttext
MD5:3ABE77D01D03FB2EA0B20CACB2F542E1
SHA256:40C4560C41A2B37355EC20C3E1C7FB96FEF0FCC455FA1A721AF549C101481206
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\3-Bonus fix\Bonus Tweaks en.txttext
MD5:25A9C3C023B4A4FE702E7557E985BA9E
SHA256:3EB9CFA4B6861307CA4A0837F1750EFA39795FBBA1D3C73CD7F6F10AB9913C0D
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\2-Reg fixes\No menu delay.regtext
MD5:44752BA851D19C28045DD7E7EC2CC63A
SHA256:232855481FEDC57D323738DFB4C7CC657D1CCB2C4E4FA07434C5CE8901A267D0
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.14482\Ultimate Turbo V2\2-Reg fixes\HPET Disabler.regtext
MD5:F0AE487555D9751A20561517967E8B58
SHA256:9027BA9D24888974388E407468EECBC818D0446F5D3FBB2A08D9030914911ABE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8028
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8028
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2616
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.14
  • 40.126.32.140
  • 20.190.160.17
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info