File name:

IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe

Full analysis: https://app.any.run/tasks/9a4a59d6-1ef8-4e48-b37c-d087e20fa1ab
Verdict: Malicious activity
Analysis date: February 08, 2025, 14:00:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

E29570CB35C8A6692D5BCC4EE28E6127

SHA1:

29537962A002D8F02941566AB5F23B7E390EA6AB

SHA256:

49FFAF3F9CDBF9EA5706D23D572D43A9CE726789B345E5220EFAF6D4EA2DCC82

SSDEEP:

98304:mrq3BdwFwGu/tT5opTaUD/Ql6Wjc4nrxGY2BKhwLl04D5sCuzztB4Y2YihUr4:dcMe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Reads security settings of Internet Explorer

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • unins000.exe (PID: 4952)
    • Reads the Windows owner or organization settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • _unins.tmp (PID: 1348)
    • Checks Windows Trust Settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Application launched itself

      • unins000.exe (PID: 4952)
    • Starts itself from another location

      • unins000.exe (PID: 6624)
    • Starts application with an unusual extension

      • unins000.exe (PID: 6624)
  • INFO

    • Checks supported languages

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • unins000.exe (PID: 4952)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Reads the computer name

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • unins000.exe (PID: 4952)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Process checks computer location settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • unins000.exe (PID: 4952)
    • Create files in a temporary directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
    • Compiled with Borland Delphi (YARA)

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
    • Checks proxy server information

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Reads the machine GUID from the registry

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Reads the software policy settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Creates a software uninstall entry

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Creates files or folders in the user directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
    • Creates files in the program directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Manual execution by a user

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • unins000.exe (PID: 4952)
    • Detects InnoSetup installer (YARA)

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
FileVersion: 1.0.0.0
LegalCopyright: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
OriginalFileName:
ProductName: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
14
Malicious processes
0
Suspicious processes
8

Behavior graph

Click at the process to see the details
start irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp no specs irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp _unins.tmp irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp no specs irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp rundll32.exe no specs unins000.exe no specs unins000.exe _unins.tmp searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
1348"C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp" /SECONDPHASE="C:\Program Files (x86)\Setup\unins000.exe" /FIRSTPHASEWND=$2024C /INITPROCWND=$A02B4 C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp
unins000.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\iu-14d2n.tmp\_unins.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
2632"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
2804"C:\Users\admin\AppData\Local\Temp\is-9C0NU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$40054,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" /SPAWNWND=$3005A /NOTIFYWND=$40146 C:\Users\admin\AppData\Local\Temp\is-9C0NU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9c0nu.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4244"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" /SPAWNWND=$3005A /NOTIFYWND=$40146 C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4952"C:\Program Files (x86)\Setup\unins000.exe" C:\Program Files (x86)\Setup\unins000.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\program files (x86)\setup\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
5064"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5240C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5268"C:\Users\admin\AppData\Local\Temp\is-PAU7L.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$40146,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\AppData\Local\Temp\is-PAU7L.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpIRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pau7l.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
6056"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6264"C:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$50282,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpIRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a0ptu.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
9 186
Read events
9 033
Write events
149
Delete events
4

Modification events

(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00330035006200610039003700630061002D0032006400300062002D0034003800610031002D0062003700320064002D003100660064006400640065006100660039003300610038007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LastConstraintIndexBuildCompleted
Value:
2CFAD9E8317ADB010F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{832b68d2-7fe2-4e71-a3ad-26166b656ec6}
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings
Operation:writeName:SafeSearchMode
Value:
1
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:IndexedLanguage
Value:
en-US
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppIndexer
Operation:writeName:LatestCacheFileName
Value:
410070007000430061006300680065003100330033003800330034003900360038003600310036003000340030003200370039002E0074007800740000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppIndexer
Operation:writeName:InstalledWin32AppsRevision
Value:
7B00370045003700380033004100380041002D0033004600440039002D0034004300430036002D0042003900450033002D003100300036004100440042003700330034003600350030007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicText
Value:
Executable files
15
Suspicious files
58
Text files
108
Unknown types
1

Dropped files

PID
Process
Filename
Type
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\Local\Temp\is-IMK46.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}\Apps.ftbinary
MD5:AB5CF5D309581951ACE7978FF8DF0FF0
SHA256:CA45CAA7DE38CB805EC43EDC8B9332E1E95124A27FBB6E5BD3DDD5E8A526AFC7
6056IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exeC:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpexecutable
MD5:F5FAC5E6BDA564FB10BC9203BFE06D53
SHA256:D3A08858052869A6D2D7FBA849F7FE033CA435DE7986A8C18150515899BEE019
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbresbinary
MD5:153A63C0A2897CBA65AF788054AC8B42
SHA256:0841C9E0819D57A0461A020F72C8FC09DC9FC2E6B0AAD3D8A5DE416F6C7CD987
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}\0.2.filtertrie.intermediate.txttext
MD5:C204E9FAAF8565AD333828BEFF2D786E
SHA256:D65B6A3BF11A27A1CED1F7E98082246E40CF01289FD47FE4A5ED46C221F2F73F
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\Local\Temp\is-IMK46.tmp\idp.dllexecutable
MD5:55C310C0319260D798757557AB3BF636
SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED
6492IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exeC:\Users\admin\AppData\Local\Temp\is-KFKBO.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpexecutable
MD5:F5FAC5E6BDA564FB10BC9203BFE06D53
SHA256:D3A08858052869A6D2D7FBA849F7FE033CA435DE7986A8C18150515899BEE019
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:0928AE1923EBDA95D253A62F263EBE9E
SHA256:3F89173358AA6164F69EDA7C5CB4BD4E925F7721E4336528B61B1765F9C4D737
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\67\0SrfjVbd4BJYe5wzcCR3l-BPV6c[1].jss
MD5:93C8EEB694177EFB7AFE347F5C67A9F9
SHA256:736C9B4487EDDD28E6D8695DF77EBC8BA760F3BA0709E9CA7C151856E76D4FBB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
55
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5448
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5448
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6536
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
GET
200
142.250.186.163:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5448
svchost.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5448
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
184.86.251.20:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.99
  • 2.16.164.9
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
www.bing.com
  • 184.86.251.20
  • 184.86.251.4
  • 184.86.251.9
  • 184.86.251.24
  • 184.86.251.14
  • 184.86.251.7
  • 2.21.65.132
  • 2.21.65.154
  • 104.126.37.139
  • 104.126.37.147
  • 104.126.37.153
  • 104.126.37.152
  • 104.126.37.136
  • 104.126.37.146
  • 104.126.37.131
  • 104.126.37.144
  • 104.126.37.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.3
  • 20.190.160.2
  • 20.190.160.22
  • 20.190.160.20
  • 20.190.160.4
  • 20.190.160.130
  • 20.190.160.64
  • 40.126.32.134
whitelisted
go.microsoft.com
  • 2.19.246.123
whitelisted
hotcondition.xyz
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.64.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.16.1
  • 104.21.112.1
unknown
c.pki.goog
  • 142.250.186.163
whitelisted

Threats

No threats detected
No debug info