File name:

Shift - Templates_6cxn7.exe

Full analysis: https://app.any.run/tasks/2622cae5-12fc-4341-9d28-2445267f8288
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 15, 2025, 08:34:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

1485201C064EB0BF3B0717BA0417C39F

SHA1:

D1B2CA2C56ECB75FC6A22E90010013E132FF2C5D

SHA256:

3FFE81A059621B8F1224C563245AD40A049718CF902338452A8674350F1B4760

SSDEEP:

98304:J+cD4dnHwICNdt3umWs5h77G64PwJOfp7XsQpZX5vEVpyQn6hHzwOeNO4SPvsm6u:6aBu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • shift.exe (PID: 2736)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Executable content was dropped or overwritten

      • Shift - Templates_6cxn7.exe (PID: 6288)
      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.exe (PID: 3772)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.exe (PID: 4544)
      • Shift Setup_6cxn7.tmp (PID: 3812)
    • There is functionality for taking screenshot (YARA)

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Uses TASKKILL.EXE to kill process

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Process drops legitimate windows executable

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Uses ICACLS.EXE to modify access control lists

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 4640)
    • Application launched itself

      • shift.exe (PID: 6704)
      • shift.exe (PID: 6416)
    • Reads security settings of Internet Explorer

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Executes application which crashes

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • The process checks if it is being run in the virtual environment

      • shift.exe (PID: 6416)
  • INFO

    • Checks supported languages

      • Shift - Templates_6cxn7.exe (PID: 6288)
      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.exe (PID: 3772)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
      • shift.exe (PID: 6416)
      • shift.exe (PID: 6704)
      • shift.exe (PID: 6572)
      • shift.exe (PID: 6932)
      • shift.exe (PID: 6800)
      • shift.exe (PID: 6968)
      • shift.exe (PID: 3576)
      • shift.exe (PID: 6216)
      • shift.exe (PID: 1488)
      • shift.exe (PID: 6396)
      • shift.exe (PID: 1080)
      • shift.exe (PID: 3696)
      • shift.exe (PID: 3080)
      • shift.exe (PID: 3724)
      • shift.exe (PID: 4136)
      • shift.exe (PID: 3816)
      • shift.exe (PID: 1304)
      • shift.exe (PID: 4596)
      • shift.exe (PID: 3664)
      • shift.exe (PID: 5208)
      • shift.exe (PID: 6524)
      • shift.exe (PID: 2632)
      • shift.exe (PID: 3124)
      • shift.exe (PID: 6156)
      • shift.exe (PID: 1480)
      • shift.exe (PID: 6696)
      • shift.exe (PID: 4548)
      • shift.exe (PID: 7124)
      • shift.exe (PID: 3436)
      • shift.exe (PID: 936)
      • shift.exe (PID: 7284)
      • shift.exe (PID: 7344)
      • shift.exe (PID: 7292)
      • shift.exe (PID: 7728)
      • shift.exe (PID: 7744)
      • shift.exe (PID: 5604)
      • shift.exe (PID: 4036)
      • shift.exe (PID: 7524)
      • shift.exe (PID: 7720)
      • shift.exe (PID: 7964)
      • shift.exe (PID: 7972)
      • shift.exe (PID: 7980)
      • shift.exe (PID: 7996)
      • shift.exe (PID: 6176)
      • shift.exe (PID: 7344)
      • shift.exe (PID: 768)
      • shift.exe (PID: 7752)
      • shift.exe (PID: 7736)
      • shift.exe (PID: 5604)
      • shift.exe (PID: 7436)
      • shift.exe (PID: 3936)
      • shift.exe (PID: 6352)
      • shift.exe (PID: 7348)
      • shift.exe (PID: 7212)
    • Create files in a temporary directory

      • Shift - Templates_6cxn7.exe (PID: 6288)
      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.exe (PID: 3772)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
      • shift.exe (PID: 2736)
      • shift.exe (PID: 6416)
      • Shift Setup_6cxn7.exe (PID: 4544)
    • Reads the computer name

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift Setup_6cxn7.tmp (PID: 3812)
      • shift.exe (PID: 6416)
      • shift.exe (PID: 6704)
      • shift.exe (PID: 6932)
      • shift.exe (PID: 2736)
      • shift.exe (PID: 3696)
    • Reads the machine GUID from the registry

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • shift.exe (PID: 3696)
    • The process uses the downloaded file

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Checks proxy server information

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • shift.exe (PID: 6416)
      • WerFault.exe (PID: 5308)
    • Process checks computer location settings

      • Shift - Templates_6cxn7.tmp (PID: 6312)
      • Shift - Templates_6cxn7.tmp (PID: 4504)
      • Shift Setup_6cxn7.tmp (PID: 3812)
      • shift.exe (PID: 6416)
      • shift.exe (PID: 6216)
      • shift.exe (PID: 3576)
      • shift.exe (PID: 1488)
      • shift.exe (PID: 3816)
      • shift.exe (PID: 4136)
      • shift.exe (PID: 6524)
      • shift.exe (PID: 2632)
      • shift.exe (PID: 3124)
      • shift.exe (PID: 4548)
      • shift.exe (PID: 6156)
      • shift.exe (PID: 6696)
      • shift.exe (PID: 7124)
      • shift.exe (PID: 4036)
      • shift.exe (PID: 5604)
      • shift.exe (PID: 7524)
      • shift.exe (PID: 936)
      • shift.exe (PID: 7752)
      • shift.exe (PID: 7972)
      • shift.exe (PID: 7344)
      • shift.exe (PID: 7720)
      • shift.exe (PID: 6396)
      • shift.exe (PID: 7436)
      • shift.exe (PID: 7212)
      • shift.exe (PID: 5604)
    • Creates files or folders in the user directory

      • Shift Setup_6cxn7.tmp (PID: 3812)
      • shift.exe (PID: 6416)
      • shift.exe (PID: 6800)
      • WerFault.exe (PID: 5308)
    • The sample compiled with english language support

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Reads the software policy settings

      • Shift Setup_6cxn7.tmp (PID: 3812)
      • WerFault.exe (PID: 5308)
      • WerFault.exe (PID: 6160)
    • Creates a software uninstall entry

      • Shift Setup_6cxn7.tmp (PID: 3812)
    • Sends debugging messages

      • shift.exe (PID: 6704)
      • shift.exe (PID: 6572)
    • Reads Environment values

      • shift.exe (PID: 6416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 421888
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 130.0.0.0
ProductVersionNumber: 130.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shift
FileDescription: Shift Setup
FileVersion: 130.0.0
LegalCopyright: Copyright Shift. All rights reserved.
OriginalFileName:
ProductName: Shift
ProductVersion: 130.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
221
Monitored processes
84
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start shift - templates_6cxn7.exe shift - templates_6cxn7.tmp shift - templates_6cxn7.exe shift - templates_6cxn7.tmp shift setup_6cxn7.exe shift setup_6cxn7.tmp taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs shift.exe shift.exe shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe no specs shift.exe no specs werfault.exe shift.exe no specs shift.exe no specs werfault.exe shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=57 --field-trial-handle=11400,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=11472 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Exit code:
0
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
900"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=27 --field-trial-handle=7772,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=7464 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
936"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=36 --field-trial-handle=8232,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=9196 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1076"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=6124,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=6148 /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Exit code:
0
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1080"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=3876,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=6160 /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Exit code:
0
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1304"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --string-annotations=is-enterprise-managed=no --field-trial-handle=6712,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=6616 /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1480"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --field-trial-handle=7968,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=8152 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1488"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=5652,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=5632 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1792\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=6544,i,10645069456132694887,1624300428972059775,262144 --variations-seed-version --mojo-platform-channel-handle=6696 /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
130.0.0.1768
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\130.0.0.1768\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
13 676
Read events
13 585
Write events
90
Delete events
1

Modification events

(PID) Process:(4504) Shift - Templates_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
9811000019E06F5F2867DB01
(PID) Process:(4504) Shift - Templates_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
F415C35FD08F22209ABBCABF41BC929DBB4B8FD71BAA276D5A74B722990D9409
(PID) Process:(4504) Shift - Templates_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:pv
Value:
130.0.0.1768
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:EnterpriseProduct<{95fcf903-63b1-44bd-ab77-358a5bd30aae}_is1>
Value:
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CLASSES_ROOT\CLSID\{E797BF82-EFC0-4B94-A059-AA797B10D29C}\LocalServer32
Operation:writeName:ServerExecutable
Value:
C:\Users\admin\AppData\Local\Shift\chromium\130.0.0.1768\notification_helper.exe
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationDescription
Value:
Shift Browser
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationName
Value:
Shift Browser
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.htm
Value:
ShiftHTML
(PID) Process:(3812) Shift Setup_6cxn7.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.html
Value:
ShiftHTML
Executable files
49
Suspicious files
605
Text files
294
Unknown types
76

Dropped files

PID
Process
Filename
Type
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-8TIJ5.tmp\is-218BD.tmp
MD5:
SHA256:
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-8TIJ5.tmp\Shift Setup.exe
MD5:
SHA256:
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup.exe
MD5:
SHA256:
4504Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup_6cxn7.exe
MD5:
SHA256:
6288Shift - Templates_6cxn7.exeC:\Users\admin\AppData\Local\Temp\is-3HAAQ.tmp\Shift - Templates_6cxn7.tmpexecutable
MD5:028771A0BE92A587863E54EC6B5042FF
SHA256:AEAA9E03A194F504A2F3DA3BC4EE93EE945FC75655BA56F621F74CF7311B66EC
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-8TIJ5.tmp\shift.pngimage
MD5:0423D0589E58341B5B64C6099F4123B7
SHA256:A1D2C48437058F24A5EA85C323469473AC4430198770794522A32C28783AADB7
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-8TIJ5.tmp\Win32Library.dllexecutable
MD5:D82B30898C428A7DBEE81CECEA520F68
SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198
6312Shift - Templates_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-8TIJ5.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
3812Shift Setup_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-COTSM.tmp\exit-hover.bmpimage
MD5:D33F497718C0BF3C5705941BA5666A5A
SHA256:C61FB1333511D8E78C4606DD2A800F1CF9D94307B26C01862128FF11C0B5E333
3812Shift Setup_6cxn7.tmpC:\Users\admin\AppData\Local\Temp\is-COTSM.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
585
DNS requests
779
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3696
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1556
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aczvdmlgeewonrf3yvpxvvp6ofnq_2025.1.10.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.10.00_all_nzej7xkm6iolqes6ixulzwov5a.crx3
unknown
whitelisted
1556
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aczvdmlgeewonrf3yvpxvvp6ofnq_2025.1.10.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.10.00_all_nzej7xkm6iolqes6ixulzwov5a.crx3
unknown
whitelisted
1556
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aczvdmlgeewonrf3yvpxvvp6ofnq_2025.1.10.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.10.00_all_nzej7xkm6iolqes6ixulzwov5a.crx3
unknown
whitelisted
1556
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaldksiunzh56452py2db5mnbpa_120.0.6050.0/jamhcnnkihinmdlkakkaopbjbbcngflc_120.0.6050.0_all_dgzfpknn7v3zslsbhrwu6bt44e.crx3
unknown
whitelisted
1556
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aczvdmlgeewonrf3yvpxvvp6ofnq_2025.1.10.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.10.00_all_nzej7xkm6iolqes6ixulzwov5a.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
488
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
92.123.104.49:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
www.bing.com
  • 92.123.104.49
  • 92.123.104.62
  • 92.123.104.61
  • 92.123.104.59
  • 92.123.104.47
  • 92.123.104.58
  • 92.123.104.54
  • 92.123.104.53
  • 92.123.104.46
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.134
  • 40.126.32.72
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.136
whitelisted
attribution.shiftapis.com
  • 13.59.219.169
  • 3.143.130.209
  • 3.132.109.129
unknown
updates.shiftapis.com
  • 3.22.156.115
  • 3.14.160.143
  • 3.129.74.119
unknown
go.microsoft.com
  • 23.213.166.81
whitelisted

Threats

PID
Process
Class
Message
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6800
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6800
shift.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6800
shift.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
Process
Message
shift.exe
[0115/083531.049:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\Shift\User Data\Crashpad: The system cannot find the path specified. (0x3)
shift.exe
[0115/083531.094:ERROR:registration_protocol_win.cc(136)] TransactNamedPipe: The pipe has been ended. (0x6D)
shift.exe
[0115/083531.094:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\Shift\User Data\Crashpad: The system cannot find the path specified. (0x3)