File name:

Shift - Manuals_slg8d.exe

Full analysis: https://app.any.run/tasks/690e671f-d2e9-4383-acf6-0ac8effee47a
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 21, 2024, 15:06:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0191566449AAE1A7FFED02A61D585686

SHA1:

A82CEEFDFD16502FB9BD2DEA8845653E247E62DA

SHA256:

446262C04A0809EFD68A55713CBFBE5D8F78ACF606F2C7F2A27532407681EE93

SSDEEP:

98304:h+cD4dnHwICNdt3uJrGpkbO/uFSJyXsQpZX5vEVpyQn6hHzwOeNO4SPvsm6Puq/s:aaBa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 1744)
      • shift.exe (PID: 5732)
      • shift.exe (PID: 5704)
      • shift.exe (PID: 4668)
      • shift.exe (PID: 5124)
      • shift.exe (PID: 4004)
      • shift.exe (PID: 4772)
      • shift.exe (PID: 6972)
      • shift.exe (PID: 6696)
      • shift.exe (PID: 7500)
      • shift.exe (PID: 7840)
      • shift.exe (PID: 8100)
      • shift.exe (PID: 6436)
      • shift.exe (PID: 5376)
      • shift.exe (PID: 7720)
      • shift.exe (PID: 7688)
      • shift.exe (PID: 7976)
    • Steals credentials from Web Browsers

      • shift.exe (PID: 1436)
    • Changes the autorun value in the registry

      • shift.exe (PID: 1436)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Shift - Manuals_slg8d.exe (PID: 6728)
      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.exe (PID: 6244)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.exe (PID: 6396)
      • Shift Setup_slg8d.tmp (PID: 6484)
    • Reads the Windows owner or organization settings

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
    • Executable content was dropped or overwritten

      • Shift - Manuals_slg8d.exe (PID: 6728)
      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift - Manuals_slg8d.exe (PID: 6244)
      • Shift Setup_slg8d.exe (PID: 6396)
      • Shift Setup_slg8d.tmp (PID: 6484)
    • There is functionality for taking screenshot (YARA)

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
    • Reads security settings of Internet Explorer

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 7688)
    • Reads the date of Windows installation

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
    • Uses TASKKILL.EXE to kill process

      • Shift Setup_slg8d.tmp (PID: 6484)
    • Process drops legitimate windows executable

      • Shift Setup_slg8d.tmp (PID: 6484)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 6744)
    • Application launched itself

      • shift.exe (PID: 1436)
    • Reads Mozilla Firefox installation path

      • shift.exe (PID: 1436)
    • Checks Windows Trust Settings

      • shift.exe (PID: 1436)
      • shift.exe (PID: 7688)
    • Executes application which crashes

      • Shift Setup_slg8d.tmp (PID: 6484)
    • The process checks if it is being run in the virtual environment

      • shift.exe (PID: 1436)
  • INFO

    • Checks supported languages

      • Shift - Manuals_slg8d.exe (PID: 6728)
      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.exe (PID: 6244)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.exe (PID: 6396)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 1744)
      • shift.exe (PID: 5732)
      • shift.exe (PID: 5704)
      • shift.exe (PID: 4668)
      • shift.exe (PID: 5124)
      • shift.exe (PID: 4004)
      • shift.exe (PID: 4772)
      • shift.exe (PID: 6972)
      • shift.exe (PID: 6696)
      • shift.exe (PID: 7500)
      • shift.exe (PID: 7840)
      • shift.exe (PID: 8100)
      • identity_helper.exe (PID: 6384)
      • shift.exe (PID: 6436)
      • shift.exe (PID: 5376)
      • shift.exe (PID: 7720)
      • shift.exe (PID: 7688)
      • shift.exe (PID: 7976)
    • Reads the computer name

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 5732)
      • shift.exe (PID: 5704)
      • shift.exe (PID: 5124)
      • shift.exe (PID: 8100)
      • identity_helper.exe (PID: 6384)
      • shift.exe (PID: 7688)
    • Create files in a temporary directory

      • Shift - Manuals_slg8d.exe (PID: 6728)
      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.exe (PID: 6244)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.exe (PID: 6396)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 5124)
    • Reads Environment values

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • identity_helper.exe (PID: 6384)
      • shift.exe (PID: 7688)
    • Reads the software policy settings

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 5124)
      • WerFault.exe (PID: 7252)
      • WerFault.exe (PID: 8064)
      • shift.exe (PID: 7688)
    • Reads the machine GUID from the registry

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 7688)
    • Checks proxy server information

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • shift.exe (PID: 1436)
      • WerFault.exe (PID: 7252)
      • WerFault.exe (PID: 8064)
    • Process checks computer location settings

      • Shift - Manuals_slg8d.tmp (PID: 6748)
      • Shift - Manuals_slg8d.tmp (PID: 2388)
      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • shift.exe (PID: 4772)
      • shift.exe (PID: 4004)
      • shift.exe (PID: 6972)
      • shift.exe (PID: 6696)
      • shift.exe (PID: 7840)
      • shift.exe (PID: 7500)
    • Creates files or folders in the user directory

      • Shift Setup_slg8d.tmp (PID: 6484)
      • shift.exe (PID: 1436)
      • WerFault.exe (PID: 7252)
      • WerFault.exe (PID: 8064)
      • shift.exe (PID: 7688)
      • shift.exe (PID: 5704)
    • Creates a software uninstall entry

      • Shift Setup_slg8d.tmp (PID: 6484)
    • Reads Microsoft Office registry keys

      • shift.exe (PID: 1436)
      • msedge.exe (PID: 5112)
    • Application launched itself

      • msedge.exe (PID: 5112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 421888
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 122.11.0.0
ProductVersionNumber: 122.11.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shift
FileDescription: Shift Setup
FileVersion: 122.11.0
LegalCopyright: Copyright Shift. All rights reserved.
OriginalFileName:
ProductName: Shift
ProductVersion: 122.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
68
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start shift - manuals_slg8d.exe THREAT shift - manuals_slg8d.tmp shift - manuals_slg8d.exe THREAT shift - manuals_slg8d.tmp shift setup_slg8d.exe THREAT shift setup_slg8d.tmp taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs shift.exe shift.exe shift.exe shift.exe shift.exe shift.exe msedge.exe shift.exe shift.exe shift.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs shift.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs werfault.exe msedge.exe no specs shift.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shift.exe msedge.exe no specs werfault.exe shift.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shift.exe msedge.exe no specs shift.exe msedge.exe no specs shift.exe msedge.exe no specs shift.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs shift.exe

Process information

PID
CMD
Path
Indicators
Parent process
448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2204 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1436"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --start-maximizedC:\Users\admin\AppData\Local\Shift\chromium\shift.exe
Shift Setup_slg8d.tmp
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Version:
122.11.0.1151
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\local\shift\chromium\122.11.0.1151\shift_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5128 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1744C:\Users\admin\AppData\Local\Shift\chromium\shift.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Shift\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Shift\User Data\Crashpad" --url=https://o1334372.ingest.sentry.io/api/4506193009180672/minidump/?sentry_key=1c60a0cacdead91f905faa80e9c82d03 --annotation=plat=Win64 --annotation=prod=Shift --annotation=ver=122.11.0.1151 --initial-client-data=0x150,0x154,0x158,0x12c,0x15c,0x7fffd59f5700,0x7fffd59f570c,0x7fffd59f5718C:\Users\admin\AppData\Local\Shift\chromium\shift.exe
shift.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Exit code:
1
Version:
122.11.0.1151
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\122.11.0.1151\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2208"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6896 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2388"C:\Users\admin\AppData\Local\Temp\is-TD8C3.tmp\Shift - Manuals_slg8d.tmp" /SL5="$E035E,1423803,1164800,C:\Users\admin\Desktop\Shift - Manuals_slg8d.exe" /PDATA=eyJnYWRfc291cmNlIjoiNSIsInV0bV9jYW1wYWlnbiI6IjIxMjMzNjM1MzYwIiwidXRtX21lZGl1bSI6IiIsInByb2ZpbGUiOiJzaGlmdC1tYW51YWxzIiwidWEiOiJlZGdlIiwiaW5zdGFsbGVyX2ZpbGVuYW1lIjoic2hpZnQtdjEyMi4xMS4wLXdlYi5leGUiLCJ1dG1fdGVybSI6IiIsImdjbGlkIjoiQ2p3S0NBandfWkMyQmhBUUVpd0FYU2dDbHQzcVVhMkUteFRIc0FMakk5OGxDeDI0M3lFRVNieERaWEEwczFXVDZfeVpnRmx5b1BxdGZSb0NFazRRQXZEX0J3RSIsInRoYW5rc191cmwiOiJodHRwczovL2FwcC5zaGlmdC5jb20vbWFudWFscy90aGFua3MiLCJkaXN0aW5jdF9pZCI6IjNhYWNlMmRjLTg1NjUtNGIzMi04ZmMyLTA1ZGRkMDc2NDZkOCIsImxwX3VybCI6Imh0dHBzOi8vYXBwLnNoaWZ0LmNvbS9tYW51YWxzLzEiLCJ3aGl0ZWxhYmVsIjoibWFudWFscyIsInV0bV9zb3VyY2UiOiJvaC1wbWF4IiwidXRtX2NvbnRlbnQiOiIiLCJpbnN0YWxsX3RpbWUiOjE3MjQyNTI3NzksImRlZmF1bHRfYnJvd3NlciI6Ik1TRWRnZUhUTSIsImluaXRpYWxfdmVyc2lvbiI6IjEyMi4xMS4wLjExNTEiLCJhdHRyaWJ1dGlvbl9rZXkiOiJzbGc4ZCJ9 /SPLITS=eyJzcGxpdCI6ImEiLCJzcGxpdDIiOiJhIiwibm9fc3BsaXQiOmZhbHNlLCJsb2NhbF9zcGxpdF90ZXN0cyI6eyJzcGxpdF9icng1NzBfY2xvc2VfYXBwX2RpYWxvZyI6eyJ2YWx1ZSI6ImNvbnRyb2wifX0sInNlcnZlcl9zaWRlX3NwbGl0X3Rlc3RzIjp7InNwbGl0X3N0MTIzMl9yZW5hbWVfc2hvcnRjdXRzX3NoaWZ0X2Jyb3dzZXIiOnsidmFsdWUiOiJ2YXJpYXRpb24ifSwic3BsaXRfc3RhcnRwYWdlX3NlYXJjaF9mZWVkX2F1Z18xNSI6eyJ2YWx1ZSI6ImNvbnRyb2wiLCJyZXBsYWNlbWVudHMiOnsic2VhcmNoLnNlYXJjaF9lbmdpbmVzLmVuZ2luZV8xLnNlYXJjaF91cmwiOiJodHRwczovL3d3dy5zdGFydHBhZ2UuY29tL2RvL3NlYXJjaD9zZWdtZW50PXN0YXJ0cGFnZS5zaGlmdCZxPXtzZWFyY2hUZXJtc30mY2F0PXdlYiZ0eXBlPSQodHlwZSkkPGVuY29kZWRfc3BsaXRzPl8kW2luc3RhbGxfZGF0ZV0mc3ViaWQ9JFt1dG1fY2FtcGFpZ25dIiwic2VhcmNoX25hbWUiOiJTdGFydFBhZ2UiLCJzZWFyY2guc2VhcmNoX2VuZ2luZXMuZW5naW5lXzEubmFtZSI6IlN0YXJ0UGFnZSIsInNlYXJjaC5zZWFyY2hfZW5naW5lcy5lbmdpbmVfMS5rZXl3b3JkIjoic3RhcnRwYWdlLmNvbSIsInNlYXJjaF91cmwiOiJodHRwczovL3d3dy5zdGFydHBhZ2UuY29tL2RvL3NlYXJjaD9zZWdtZW50PXN0YXJ0cGFnZS5zaGlmdCZxPXtzZWFyY2hUZXJtc30mY2F0PXdlYiZ0eXBlPSQodHlwZSkkPGVuY29kZWRfc3BsaXRzPl8kW2luc3RhbGxfZGF0ZV0mc3ViaWQ9JFt1dG1fY2FtcGFpZ25dIiwic2VhcmNoLnNlYXJjaF9lbmdpbmVzLmVuZ2luZV8xLmZhdmljb25fdXJsIjoiaHR0cHM6Ly93d3cuc3RhcnRwYWdlLmNvbS9zcC9jZG4vZmF2aWNvbnMvZmF2aWNvbi1ncmFkaWVudC5pY28ifX0sInNwbGl0X3N0MTM5MV9kb250X2ltcG9ydF9oaXN0b3J5Ijp7InZhbHVlIjoidmFyaWF0aW9uIn19LCJhdHRyaWJ1dGlvbl9zcGxpdF90ZXN0cyI6e30sImVuY29kZWRfc3BsaXRzIjoiMjU2In0= /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-TD8C3.tmp\Shift - Manuals_slg8d.tmp
Shift - Manuals_slg8d.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-td8c3.tmp\shift - manuals_slg8d.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3384"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3540 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4212 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4036 --field-trial-handle=2016,i,1318481974588374801,2214067498899318280,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
42 574
Read events
42 360
Write events
210
Delete events
4

Modification events

(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
5C1A0000F0A4C4ACDBF3DA01
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3A1542010AB146284912FE269303EA3325CEFAA28325969A2617E76D3BF49C7E
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6748) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2388) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
54090000C6231ECFDBF3DA01
(PID) Process:(2388) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
A0A226AEF92F25CE502B50C9D39CB628D83B539FBFC0C849D2C8410488500CC7
(PID) Process:(2388) Shift - Manuals_slg8d.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
Executable files
53
Suspicious files
402
Text files
308
Unknown types
77

Dropped files

PID
Process
Filename
Type
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\is-EKH9P.tmp
MD5:
SHA256:
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\Shift Setup.exe
MD5:
SHA256:
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup.exe
MD5:
SHA256:
2388Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup_slg8d.exe
MD5:
SHA256:
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\shift.pngimage
MD5:0423D0589E58341B5B64C6099F4123B7
SHA256:A1D2C48437058F24A5EA85C323469473AC4430198770794522A32C28783AADB7
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\Win32Library.dllexecutable
MD5:D82B30898C428A7DBEE81CECEA520F68
SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\min-hover.bmpimage
MD5:C94A77553F2C392D5F1FE2F08E30EFB2
SHA256:8DAA69B6252F6F773CEB6D7090664B933537478731473E1B54CAF67791C2D336
6748Shift - Manuals_slg8d.tmpC:\Users\admin\AppData\Local\Temp\is-JV6VT.tmp\min-pressed.bmpimage
MD5:4B549427F8B753A01272BEC3A658E7BA
SHA256:FE03E30C13229D50685E3387F4F271BEFE57DFA74BE890D09C089FB3688469A1
6728Shift - Manuals_slg8d.exeC:\Users\admin\AppData\Local\Temp\is-NCR2F.tmp\Shift - Manuals_slg8d.tmpexecutable
MD5:9569CD3D574CB04BB31A5D4B8FEDD0A3
SHA256:DBE50ABD58F642ED529313A9CFD99DBA055219DFC2919C7CFA0F53A28C6B0928
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
66
TCP/UDP connections
143
DNS requests
180
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2584
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6976
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6476
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6684
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad6omgufxyuld3hle5dt26kq4fda_2023.7.28.7/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.07_all_ps4en5vvrti3733b4m4dbmuej4.crx3
unknown
whitelisted
6684
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad6omgufxyuld3hle5dt26kq4fda_2023.7.28.7/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.07_all_ps4en5vvrti3733b4m4dbmuej4.crx3
unknown
whitelisted
6684
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad6omgufxyuld3hle5dt26kq4fda_2023.7.28.7/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.07_all_ps4en5vvrti3733b4m4dbmuej4.crx3
unknown
whitelisted
6684
svchost.exe
HEAD
200
23.48.23.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7fc05444-f914-468e-ba6d-4e4860ab2bdc?P1=1724832215&P2=404&P3=2&P4=NCzKlELE%2bbNMXmgS%2fxILgTpUNtnI0BACe647V9mhMzmdkfPGdy8fnOVunLhtjHxvBKZ9ZYoYyY0wUP9iqqzQBw%3d%3d
unknown
whitelisted
6684
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad6omgufxyuld3hle5dt26kq4fda_2023.7.28.7/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.07_all_ps4en5vvrti3733b4m4dbmuej4.crx3
unknown
whitelisted
6684
svchost.exe
GET
206
23.48.23.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7fc05444-f914-468e-ba6d-4e4860ab2bdc?P1=1724832215&P2=404&P3=2&P4=NCzKlELE%2bbNMXmgS%2fxILgTpUNtnI0BACe647V9mhMzmdkfPGdy8fnOVunLhtjHxvBKZ9ZYoYyY0wUP9iqqzQBw%3d%3d
unknown
whitelisted
6684
svchost.exe
GET
206
23.48.23.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7fc05444-f914-468e-ba6d-4e4860ab2bdc?P1=1724832215&P2=404&P3=2&P4=NCzKlELE%2bbNMXmgS%2fxILgTpUNtnI0BACe647V9mhMzmdkfPGdy8fnOVunLhtjHxvBKZ9ZYoYyY0wUP9iqqzQBw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
1360
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6748
Shift - Manuals_slg8d.tmp
3.13.252.231:443
attribution.shiftapis.com
AMAZON-02
US
unknown
6748
Shift - Manuals_slg8d.tmp
3.136.194.100:443
updates.shiftapis.com
AMAZON-02
US
unknown
6748
Shift - Manuals_slg8d.tmp
172.67.4.202:443
downloads.tryshift.com
CLOUDFLARENET
US
unknown
1360
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2584
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 216.58.212.174
whitelisted
attribution.shiftapis.com
  • 3.13.252.231
  • 3.19.148.112
  • 3.131.248.152
  • 18.216.86.13
  • 18.216.33.213
  • 3.131.122.250
unknown
updates.shiftapis.com
  • 3.136.194.100
  • 3.131.66.153
  • 3.129.137.8
unknown
downloads.tryshift.com
  • 172.67.4.202
  • 104.22.77.241
  • 104.22.76.241
unknown
client.wns.windows.com
  • 40.113.103.199
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

PID
Process
Class
Message
5704
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
5704
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
5704
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5704
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Process
Message
shift.exe
[0821/150738.836:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\Shift\User Data\Crashpad: The system cannot find the path specified. (0x3)