File name:

IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe

Full analysis: https://app.any.run/tasks/9a4a59d6-1ef8-4e48-b37c-d087e20fa1ab
Verdict: Malicious activity
Analysis date: February 08, 2025, 14:00:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

E29570CB35C8A6692D5BCC4EE28E6127

SHA1:

29537962A002D8F02941566AB5F23B7E390EA6AB

SHA256:

49FFAF3F9CDBF9EA5706D23D572D43A9CE726789B345E5220EFAF6D4EA2DCC82

SSDEEP:

98304:mrq3BdwFwGu/tT5opTaUD/Ql6Wjc4nrxGY2BKhwLl04D5sCuzztB4Y2YihUr4:dcMe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • unins000.exe (PID: 4952)
    • Executable content was dropped or overwritten

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Reads the Windows owner or organization settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • _unins.tmp (PID: 1348)
    • Checks Windows Trust Settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Application launched itself

      • unins000.exe (PID: 4952)
    • Starts itself from another location

      • unins000.exe (PID: 6624)
    • Starts application with an unusual extension

      • unins000.exe (PID: 6624)
  • INFO

    • Create files in a temporary directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Checks supported languages

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • unins000.exe (PID: 6624)
      • unins000.exe (PID: 4952)
      • _unins.tmp (PID: 1348)
    • Reads the computer name

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6492)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • _unins.tmp (PID: 6440)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 4244)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • unins000.exe (PID: 4952)
      • unins000.exe (PID: 6624)
      • _unins.tmp (PID: 1348)
    • Process checks computer location settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6264)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 5268)
      • unins000.exe (PID: 4952)
    • Reads the machine GUID from the registry

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • SearchApp.exe (PID: 5064)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Reads the software policy settings

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
      • SearchApp.exe (PID: 5064)
    • Creates a software uninstall entry

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Compiled with Borland Delphi (YARA)

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
    • Checks proxy server information

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Manual execution by a user

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 2632)
      • unins000.exe (PID: 4952)
    • Creates files or folders in the user directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
    • Creates files in the program directory

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 6536)
      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp (PID: 2804)
    • Detects InnoSetup installer (YARA)

      • IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe (PID: 6056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
FileVersion: 1.0.0.0
LegalCopyright: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
OriginalFileName:
ProductName: IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
14
Malicious processes
0
Suspicious processes
8

Behavior graph

Click at the process to see the details
start irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp no specs irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp _unins.tmp irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp no specs irender nxt 70 crack for sketchup   license key 2d3d latest.exe irender nxt 70 crack for sketchup   license key 2d3d latest.tmp rundll32.exe no specs unins000.exe no specs unins000.exe _unins.tmp searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
1348"C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp" /SECONDPHASE="C:\Program Files (x86)\Setup\unins000.exe" /FIRSTPHASEWND=$2024C /INITPROCWND=$A02B4 C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp
unins000.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\iu-14d2n.tmp\_unins.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
2632"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
2804"C:\Users\admin\AppData\Local\Temp\is-9C0NU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$40054,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" /SPAWNWND=$3005A /NOTIFYWND=$40146 C:\Users\admin\AppData\Local\Temp\is-9C0NU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9c0nu.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4244"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" /SPAWNWND=$3005A /NOTIFYWND=$40146 C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4952"C:\Program Files (x86)\Setup\unins000.exe" C:\Program Files (x86)\Setup\unins000.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\program files (x86)\setup\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
5064"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5240C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5268"C:\Users\admin\AppData\Local\Temp\is-PAU7L.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$40146,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\AppData\Local\Temp\is-PAU7L.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpIRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pau7l.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
6056"C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\irender nxt 70 crack for sketchup license key 2d3d latest.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6264"C:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp" /SL5="$50282,935482,845824,C:\Users\admin\Desktop\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe" C:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpIRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a0ptu.tmp\irender nxt 70 crack for sketchup license key 2d3d latest.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
9 186
Read events
9 033
Write events
149
Delete events
4

Modification events

(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00330035006200610039003700630061002D0032006400300062002D0034003800610031002D0062003700320064002D003100660064006400640065006100660039003300610038007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LastConstraintIndexBuildCompleted
Value:
2CFAD9E8317ADB010F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{832b68d2-7fe2-4e71-a3ad-26166b656ec6}
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings
Operation:writeName:SafeSearchMode
Value:
1
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:IndexedLanguage
Value:
en-US
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppIndexer
Operation:writeName:LatestCacheFileName
Value:
410070007000430061006300680065003100330033003800330034003900360038003600310036003000340030003200370039002E0074007800740000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppIndexer
Operation:writeName:InstalledWin32AppsRevision
Value:
7B00370045003700380033004100380041002D0033004600440039002D0034004300430036002D0042003900450033002D003100300036004100440042003700330034003600350030007D0000000F48D9E8317ADB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicText
Value:
Executable files
15
Suspicious files
58
Text files
108
Unknown types
1

Dropped files

PID
Process
Filename
Type
6492IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exeC:\Users\admin\AppData\Local\Temp\is-KFKBO.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpexecutable
MD5:F5FAC5E6BDA564FB10BC9203BFE06D53
SHA256:D3A08858052869A6D2D7FBA849F7FE033CA435DE7986A8C18150515899BEE019
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}\0.1.filtertrie.intermediate.txttext
MD5:34BD1DFB9F72CF4F86E6DF6DA0A9E49A
SHA256:8E1E6A3D56796A245D0C7B0849548932FEE803BBDB03F6E289495830E017F14C
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:971C514F84BBA0785F80AA1C23EDFD79
SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895
6056IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.exeC:\Users\admin\AppData\Local\Temp\is-A0PTU.tmp\IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpexecutable
MD5:F5FAC5E6BDA564FB10BC9203BFE06D53
SHA256:D3A08858052869A6D2D7FBA849F7FE033CA435DE7986A8C18150515899BEE019
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Program Files (x86)\Setup\is-8GM0R.tmpexecutable
MD5:A82B55A542B6A659D2C5080B5ED77241
SHA256:B3B0D15FA57E8733F8BE59A4D7C90CAA33A99E2ABB273EB5E5BF91132B30B182
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{35ba97ca-2d0b-48a1-b72d-1fdddeaf93a8}\Apps.ftbinary
MD5:AB5CF5D309581951ACE7978FF8DF0FF0
SHA256:CA45CAA7DE38CB805EC43EDC8B9332E1E95124A27FBB6E5BD3DDD5E8A526AFC7
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:A7CD99522B95D7403D88835511BFEED9
SHA256:A80EE8393906C544992DD3BAE1AA696BB199E867F27605DEACBD622813C2FB55
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Program Files (x86)\Setup\unins000.datbinary
MD5:38896E2C6EDED4FDFBDC4C098F11179B
SHA256:923966B5D787C483C318736FC43BAAE0A9D9EAC99538D3AF0EE5F2AAC74C4DBE
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbresbinary
MD5:153A63C0A2897CBA65AF788054AC8B42
SHA256:0841C9E0819D57A0461A020F72C8FC09DC9FC2E6B0AAD3D8A5DE416F6C7CD987
6536IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmpC:\Program Files (x86)\Setup\unins000.exeexecutable
MD5:A82B55A542B6A659D2C5080B5ED77241
SHA256:B3B0D15FA57E8733F8BE59A4D7C90CAA33A99E2ABB273EB5E5BF91132B30B182
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
55
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5448
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
QA
binary
973 b
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
QA
binary
973 b
whitelisted
5448
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
QA
binary
973 b
whitelisted
5880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
312 b
whitelisted
6536
IRender nXt 70 Crack For Sketchup License Key 2D3D Latest.tmp
GET
200
142.250.186.163:80
http://c.pki.goog/r/r4.crl
US
binary
436 b
whitelisted
5880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5448
svchost.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5448
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
184.86.251.20:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.99
  • 2.16.164.9
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
www.bing.com
  • 184.86.251.20
  • 184.86.251.4
  • 184.86.251.9
  • 184.86.251.24
  • 184.86.251.14
  • 184.86.251.7
  • 2.21.65.132
  • 2.21.65.154
  • 104.126.37.139
  • 104.126.37.147
  • 104.126.37.153
  • 104.126.37.152
  • 104.126.37.136
  • 104.126.37.146
  • 104.126.37.131
  • 104.126.37.144
  • 104.126.37.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.3
  • 20.190.160.2
  • 20.190.160.22
  • 20.190.160.20
  • 20.190.160.4
  • 20.190.160.130
  • 20.190.160.64
  • 40.126.32.134
whitelisted
go.microsoft.com
  • 2.19.246.123
whitelisted
hotcondition.xyz
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.64.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.16.1
  • 104.21.112.1
unknown
c.pki.goog
  • 142.250.186.163
whitelisted

Threats

No threats detected
No debug info