File name:

zadig-2.4.exe

Full analysis: https://app.any.run/tasks/6920631c-591a-4c8c-83f9-dab7fe44568d
Verdict: Malicious activity
Analysis date: August 11, 2024, 06:06:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

8364578C40B5A7F379ADBA1BAD2521EC

SHA1:

7E2BAC877385EF86EFD9D54D1B89FF4E9E18243A

SHA256:

4B7C58696B7A809525F6ABCEA9B3E9C1BF91518EBDC0D19AF31E219654074342

SSDEEP:

98304:foiKjvpG51TDyWAYAZkEIVGzUihpHQSUggLFsXmL+uEqZEJh9bkUDRpeQm:f+jvIALYih2SUgpXa+jKEJh9b/9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the Windows auto-update feature

      • installer_x64.exe (PID: 240)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
      • drvinst.exe (PID: 6908)
    • Process drops legitimate windows executable

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
      • drvinst.exe (PID: 6908)
    • Executable content was dropped or overwritten

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
      • drvinst.exe (PID: 6908)
    • Drops a system driver (possible attempt to evade defenses)

      • zadig-2.4.exe (PID: 6464)
    • Adds/modifies Windows certificates

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
    • Reads security settings of Internet Explorer

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
    • Reads the date of Windows installation

      • zadig-2.4.exe (PID: 6464)
    • Checks Windows Trust Settings

      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6424)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 6908)
  • INFO

    • Reads Environment values

      • zadig-2.4.exe (PID: 6464)
    • Checks supported languages

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
      • drvinst.exe (PID: 6908)
    • Create files in a temporary directory

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
    • UPX packer has been detected

      • zadig-2.4.exe (PID: 6464)
    • Reads the computer name

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
      • drvinst.exe (PID: 6908)
    • Reads the software policy settings

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
    • Reads the machine GUID from the registry

      • zadig-2.4.exe (PID: 6464)
      • installer_x64.exe (PID: 240)
      • drvinst.exe (PID: 6424)
    • Creates files in the program directory

      • zadig-2.4.exe (PID: 6464)
    • Process checks computer location settings

      • zadig-2.4.exe (PID: 6464)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:07:27 00:07:30+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.14
CodeSize: 5120000
InitializedDataSize: 32768
UninitializedDataSize: 1609728
EntryPoint: 0x66b040
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.4.721.0
ProductVersionNumber: 2.4.721.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: akeo.ie
FileDescription: Zadig
FileVersion: 2.4.721
InternalName: Zadig
LegalCopyright: © 2010-2018 Pete Batard (GPL v3)
LegalTrademarks: http://www.gnu.org/copyleft/gpl.html
OriginalFileName: zadig.exe
ProductName: Zadig
ProductVersion: 2.4.721
Comments: http://libwdi.akeo.ie
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT zadig-2.4.exe installer_x64.exe conhost.exe no specs drvinst.exe drvinst.exe zadig-2.4.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\usb_driver\installer_x64.exe" "QEMU_USB_Tablet.inf"C:\Users\admin\usb_driver\installer_x64.exe
zadig-2.4.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\usb_driver\installer_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1700\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeinstaller_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6416"C:\Users\admin\AppData\Local\Temp\zadig-2.4.exe" C:\Users\admin\AppData\Local\Temp\zadig-2.4.exeexplorer.exe
User:
admin
Company:
akeo.ie
Integrity Level:
MEDIUM
Description:
Zadig
Exit code:
3221226540
Version:
2.4.721
Modules
Images
c:\users\admin\appdata\local\temp\zadig-2.4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6424DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{11df06ec-0254-474f-a8ff-cfe3b167bd00}\qemu_usb_tablet.inf" "9" "4cc43c933" "00000000000001CC" "WinSta0\Default" "00000000000001BC" "208" "c:\users\admin\usb_driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
6464"C:\Users\admin\AppData\Local\Temp\zadig-2.4.exe" C:\Users\admin\AppData\Local\Temp\zadig-2.4.exe
explorer.exe
User:
admin
Company:
akeo.ie
Integrity Level:
HIGH
Description:
Zadig
Version:
2.4.721
Modules
Images
c:\users\admin\appdata\local\temp\zadig-2.4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6908DrvInst.exe "2" "211" "USB\VID_0627&PID_0001\28754-0000:00:04.7-1" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:a52522ad0c48fa1f:USB_Install:6.1.7600.16385:usb\vid_0627&pid_0001," "4cc43c933" "00000000000001CC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
18 682
Read events
18 568
Write events
69
Delete events
45

Modification events

(PID) Process:(6464) zadig-2.4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Akeo Consulting\Zadig
Operation:writeName:CommCheck
Value:
937062
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Akeo Consulting\Zadig
Operation:writeName:UpdateCheckInterval
Value:
86400
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Value:
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:writeName:Blob
Value:
030000000100000014000000A767D57D1E5E49A31CF51EEF03D6C8AECF666D7302000000010000004C0000001C0000000000000001000000200000000000000000000000020000006C006900620077006400690020006B0065007900200063006F006E007400610069006E006500720000000000000000000B000000010000000E0000006C006900620077006400690000002000000001000000D1050000308205CD308203B5A003020102021014CD3DA5DE7F2DBB48A509D9BBC7B6E9300D06092A864886F70D01010B050030633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3234303831313036303633305A170D3239303130313030303030305A30633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100BA925609901AF1C373BBEF51A153871372686BAA1E1ED11F8BCDFC2658197B4696D8201471F4D5ABE509225707325C08DA9CAFA4242CFE98E3DF9D001B51C11AD98D2B6E065AFE5238C4C2B75B19C51BA1D0E485D3A85FB297E8ECE84CCF6176DF35D292F2350FEA712C339691CE4A09E87E95BDD52A54590AC356699B112937E78D8E3B4F0DA2873F4F3834DE42A0D4ECAD726FEBD24BEB36C89716267140713CF36491C5356EB307D9D44DA7704335ECBE61DEB324D16A967067941878EEC94000BEE69A587AA45A2BC38A7072D97A6660C727EDE9D2E56792F55B0F2A29A2575BFF881088CBB1EDCA473304EAC8A3C215046136711D07653D131EF2EF4083A47643B635203D9C5A2E1605E793192C15CEF396457522F954529411DE90A02AC748CC05F2F12ACB5AEE52091D3B45BE44B84A8569DF95BFB5ECFD857DFA45B487D47834EC5ECA16B119088B600EEC795CEC41044F353C1D33863616A1BDB64F0FBEBBA704AB0FF2012D1C85D5D3CE5F47E25BF47E62FD5E15AACB3F4C2328900288ED914F2A5D9E3B0B940339411F686B16373893AED4304CC2D391DC703A6624404972BFF0856981C3B5CE0EACDE6B58FB25EB1DD698F4AAFC04C816616CDB08DE515ED8763B2B9A230E91596B8D4C484B1491D7A9DBC3D74D64FBF091E1E36A82787D87FE69481136DF05F8A2FF5254C098C2C3C3E5322BB8AB9341B839090203010001A37D307B30160603551D250101FF040C300A06082B0601050507030330200603551D07041930178615687474703A2F2F6C69627764692E616B656F2E6965303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B0500038202010084635244A2DEB9D4BCA9986F8291EF6754864FAB3795267D2581344AA7965BF52CCF9499C12B5BD174C9E2A95D3875C69D5811B9C6CB69F74B254C6E86D6C7C654A32FF1CBD6F85267EAB3485A9D0BB2BA079377DE74CC74BE6AD7D7D8AAC391D31EC6DA8105504CED9B3C15631670CF3D8ABE0D737627EE4707246582FFD7507C183C1EB534D1CE0096BC7E1714D5B88FBB7045EB11D047FE05CC3270ED66A19EC3B79329F51496C78D3DE5F406EFE082826CE8485956BA8ABD1001C96940DF2CD055334B5E43ED333BC53F27601FFD299750F8DF76EAC120255F1CF4B1360F094FD6F64DF27DAB565EEB4CD8EC993F1CD83C50C31B9FA83523A24E91901D201C727B5C28B4BA9FC8359D7342F880FE01E8CB003776561D764CE6F8D179020F99224C5E403BC2055B44A5DC3943E635ED678A73E921A4A9E2F3101612AF33C19F24AC67CB76F6ADEF517265EF673965D84D043E2924657E0A4A29B577E877DE6C4E305BEF3790D373BD81AF0CC30305FCC2BD94370A5985A155BBAC2DB1307D45DBB612F586EDB6E40F098088759A4A8BF17291BA95D6670A03AF426376B3F0030B4CB5AA86585AAB3B90479C958C1CFD15557BBEC8642EDCABF8566B6CBE6CB511E131A7EF9879F90BC23CDDB6D7EFC02F37F634B858D2534643F1EFB475EEECD6DAAFA7EE6159FFF997242F6A858A2A99B462512CEFCB4ADD5AD9EB921DE1
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
Operation:delete valueName:A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Value:
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:writeName:Blob
Value:
030000000100000014000000A767D57D1E5E49A31CF51EEF03D6C8AECF666D7302000000010000004C0000001C0000000000000001000000200000000000000000000000020000006C006900620077006400690020006B0065007900200063006F006E007400610069006E006500720000000000000000000B000000010000000E0000006C006900620077006400690000002000000001000000D1050000308205CD308203B5A003020102021014CD3DA5DE7F2DBB48A509D9BBC7B6E9300D06092A864886F70D01010B050030633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3234303831313036303633305A170D3239303130313030303030305A30633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100BA925609901AF1C373BBEF51A153871372686BAA1E1ED11F8BCDFC2658197B4696D8201471F4D5ABE509225707325C08DA9CAFA4242CFE98E3DF9D001B51C11AD98D2B6E065AFE5238C4C2B75B19C51BA1D0E485D3A85FB297E8ECE84CCF6176DF35D292F2350FEA712C339691CE4A09E87E95BDD52A54590AC356699B112937E78D8E3B4F0DA2873F4F3834DE42A0D4ECAD726FEBD24BEB36C89716267140713CF36491C5356EB307D9D44DA7704335ECBE61DEB324D16A967067941878EEC94000BEE69A587AA45A2BC38A7072D97A6660C727EDE9D2E56792F55B0F2A29A2575BFF881088CBB1EDCA473304EAC8A3C215046136711D07653D131EF2EF4083A47643B635203D9C5A2E1605E793192C15CEF396457522F954529411DE90A02AC748CC05F2F12ACB5AEE52091D3B45BE44B84A8569DF95BFB5ECFD857DFA45B487D47834EC5ECA16B119088B600EEC795CEC41044F353C1D33863616A1BDB64F0FBEBBA704AB0FF2012D1C85D5D3CE5F47E25BF47E62FD5E15AACB3F4C2328900288ED914F2A5D9E3B0B940339411F686B16373893AED4304CC2D391DC703A6624404972BFF0856981C3B5CE0EACDE6B58FB25EB1DD698F4AAFC04C816616CDB08DE515ED8763B2B9A230E91596B8D4C484B1491D7A9DBC3D74D64FBF091E1E36A82787D87FE69481136DF05F8A2FF5254C098C2C3C3E5322BB8AB9341B839090203010001A37D307B30160603551D250101FF040C300A06082B0601050507030330200603551D07041930178615687474703A2F2F6C69627764692E616B656F2E6965303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B0500038202010084635244A2DEB9D4BCA9986F8291EF6754864FAB3795267D2581344AA7965BF52CCF9499C12B5BD174C9E2A95D3875C69D5811B9C6CB69F74B254C6E86D6C7C654A32FF1CBD6F85267EAB3485A9D0BB2BA079377DE74CC74BE6AD7D7D8AAC391D31EC6DA8105504CED9B3C15631670CF3D8ABE0D737627EE4707246582FFD7507C183C1EB534D1CE0096BC7E1714D5B88FBB7045EB11D047FE05CC3270ED66A19EC3B79329F51496C78D3DE5F406EFE082826CE8485956BA8ABD1001C96940DF2CD055334B5E43ED333BC53F27601FFD299750F8DF76EAC120255F1CF4B1360F094FD6F64DF27DAB565EEB4CD8EC993F1CD83C50C31B9FA83523A24E91901D201C727B5C28B4BA9FC8359D7342F880FE01E8CB003776561D764CE6F8D179020F99224C5E403BC2055B44A5DC3943E635ED678A73E921A4A9E2F3101612AF33C19F24AC67CB76F6ADEF517265EF673965D84D043E2924657E0A4A29B577E877DE6C4E305BEF3790D373BD81AF0CC30305FCC2BD94370A5985A155BBAC2DB1307D45DBB612F586EDB6E40F098088759A4A8BF17291BA95D6670A03AF426376B3F0030B4CB5AA86585AAB3B90479C958C1CFD15557BBEC8642EDCABF8566B6CBE6CB511E131A7EF9879F90BC23CDDB6D7EFC02F37F634B858D2534643F1EFB475EEECD6DAAFA7EE6159FFF997242F6A858A2A99B462512CEFCB4ADD5AD9EB921DE1
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:writeName:Blob
Value:
0F0000000100000020000000B906652427BAE76AA8EF00C4FA76078288B3E48DF845883F47517CB01DD79CC20B000000010000000E0000006C0069006200770064006900000002000000010000004C0000001C0000000000000001000000200000000000000000000000020000006C006900620077006400690020006B0065007900200063006F006E007400610069006E00650072000000000000000000030000000100000014000000A767D57D1E5E49A31CF51EEF03D6C8AECF666D732000000001000000D1050000308205CD308203B5A003020102021014CD3DA5DE7F2DBB48A509D9BBC7B6E9300D06092A864886F70D01010B050030633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3234303831313036303633305A170D3239303130313030303030305A30633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100BA925609901AF1C373BBEF51A153871372686BAA1E1ED11F8BCDFC2658197B4696D8201471F4D5ABE509225707325C08DA9CAFA4242CFE98E3DF9D001B51C11AD98D2B6E065AFE5238C4C2B75B19C51BA1D0E485D3A85FB297E8ECE84CCF6176DF35D292F2350FEA712C339691CE4A09E87E95BDD52A54590AC356699B112937E78D8E3B4F0DA2873F4F3834DE42A0D4ECAD726FEBD24BEB36C89716267140713CF36491C5356EB307D9D44DA7704335ECBE61DEB324D16A967067941878EEC94000BEE69A587AA45A2BC38A7072D97A6660C727EDE9D2E56792F55B0F2A29A2575BFF881088CBB1EDCA473304EAC8A3C215046136711D07653D131EF2EF4083A47643B635203D9C5A2E1605E793192C15CEF396457522F954529411DE90A02AC748CC05F2F12ACB5AEE52091D3B45BE44B84A8569DF95BFB5ECFD857DFA45B487D47834EC5ECA16B119088B600EEC795CEC41044F353C1D33863616A1BDB64F0FBEBBA704AB0FF2012D1C85D5D3CE5F47E25BF47E62FD5E15AACB3F4C2328900288ED914F2A5D9E3B0B940339411F686B16373893AED4304CC2D391DC703A6624404972BFF0856981C3B5CE0EACDE6B58FB25EB1DD698F4AAFC04C816616CDB08DE515ED8763B2B9A230E91596B8D4C484B1491D7A9DBC3D74D64FBF091E1E36A82787D87FE69481136DF05F8A2FF5254C098C2C3C3E5322BB8AB9341B839090203010001A37D307B30160603551D250101FF040C300A06082B0601050507030330200603551D07041930178615687474703A2F2F6C69627764692E616B656F2E6965303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B0500038202010084635244A2DEB9D4BCA9986F8291EF6754864FAB3795267D2581344AA7965BF52CCF9499C12B5BD174C9E2A95D3875C69D5811B9C6CB69F74B254C6E86D6C7C654A32FF1CBD6F85267EAB3485A9D0BB2BA079377DE74CC74BE6AD7D7D8AAC391D31EC6DA8105504CED9B3C15631670CF3D8ABE0D737627EE4707246582FFD7507C183C1EB534D1CE0096BC7E1714D5B88FBB7045EB11D047FE05CC3270ED66A19EC3B79329F51496C78D3DE5F406EFE082826CE8485956BA8ABD1001C96940DF2CD055334B5E43ED333BC53F27601FFD299750F8DF76EAC120255F1CF4B1360F094FD6F64DF27DAB565EEB4CD8EC993F1CD83C50C31B9FA83523A24E91901D201C727B5C28B4BA9FC8359D7342F880FE01E8CB003776561D764CE6F8D179020F99224C5E403BC2055B44A5DC3943E635ED678A73E921A4A9E2F3101612AF33C19F24AC67CB76F6ADEF517265EF673965D84D043E2924657E0A4A29B577E877DE6C4E305BEF3790D373BD81AF0CC30305FCC2BD94370A5985A155BBAC2DB1307D45DBB612F586EDB6E40F098088759A4A8BF17291BA95D6670A03AF426376B3F0030B4CB5AA86585AAB3B90479C958C1CFD15557BBEC8642EDCABF8566B6CBE6CB511E131A7EF9879F90BC23CDDB6D7EFC02F37F634B858D2534643F1EFB475EEECD6DAAFA7EE6159FFF997242F6A858A2A99B462512CEFCB4ADD5AD9EB921DE1
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:delete keyName:(default)
Value:
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:writeName:Blob
Value:
030000000100000014000000A767D57D1E5E49A31CF51EEF03D6C8AECF666D732000000001000000D1050000308205CD308203B5A003020102021014CD3DA5DE7F2DBB48A509D9BBC7B6E9300D06092A864886F70D01010B050030633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3234303831313036303633305A170D3239303130313030303030305A30633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100BA925609901AF1C373BBEF51A153871372686BAA1E1ED11F8BCDFC2658197B4696D8201471F4D5ABE509225707325C08DA9CAFA4242CFE98E3DF9D001B51C11AD98D2B6E065AFE5238C4C2B75B19C51BA1D0E485D3A85FB297E8ECE84CCF6176DF35D292F2350FEA712C339691CE4A09E87E95BDD52A54590AC356699B112937E78D8E3B4F0DA2873F4F3834DE42A0D4ECAD726FEBD24BEB36C89716267140713CF36491C5356EB307D9D44DA7704335ECBE61DEB324D16A967067941878EEC94000BEE69A587AA45A2BC38A7072D97A6660C727EDE9D2E56792F55B0F2A29A2575BFF881088CBB1EDCA473304EAC8A3C215046136711D07653D131EF2EF4083A47643B635203D9C5A2E1605E793192C15CEF396457522F954529411DE90A02AC748CC05F2F12ACB5AEE52091D3B45BE44B84A8569DF95BFB5ECFD857DFA45B487D47834EC5ECA16B119088B600EEC795CEC41044F353C1D33863616A1BDB64F0FBEBBA704AB0FF2012D1C85D5D3CE5F47E25BF47E62FD5E15AACB3F4C2328900288ED914F2A5D9E3B0B940339411F686B16373893AED4304CC2D391DC703A6624404972BFF0856981C3B5CE0EACDE6B58FB25EB1DD698F4AAFC04C816616CDB08DE515ED8763B2B9A230E91596B8D4C484B1491D7A9DBC3D74D64FBF091E1E36A82787D87FE69481136DF05F8A2FF5254C098C2C3C3E5322BB8AB9341B839090203010001A37D307B30160603551D250101FF040C300A06082B0601050507030330200603551D07041930178615687474703A2F2F6C69627764692E616B656F2E6965303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B0500038202010084635244A2DEB9D4BCA9986F8291EF6754864FAB3795267D2581344AA7965BF52CCF9499C12B5BD174C9E2A95D3875C69D5811B9C6CB69F74B254C6E86D6C7C654A32FF1CBD6F85267EAB3485A9D0BB2BA079377DE74CC74BE6AD7D7D8AAC391D31EC6DA8105504CED9B3C15631670CF3D8ABE0D737627EE4707246582FFD7507C183C1EB534D1CE0096BC7E1714D5B88FBB7045EB11D047FE05CC3270ED66A19EC3B79329F51496C78D3DE5F406EFE082826CE8485956BA8ABD1001C96940DF2CD055334B5E43ED333BC53F27601FFD299750F8DF76EAC120255F1CF4B1360F094FD6F64DF27DAB565EEB4CD8EC993F1CD83C50C31B9FA83523A24E91901D201C727B5C28B4BA9FC8359D7342F880FE01E8CB003776561D764CE6F8D179020F99224C5E403BC2055B44A5DC3943E635ED678A73E921A4A9E2F3101612AF33C19F24AC67CB76F6ADEF517265EF673965D84D043E2924657E0A4A29B577E877DE6C4E305BEF3790D373BD81AF0CC30305FCC2BD94370A5985A155BBAC2DB1307D45DBB612F586EDB6E40F098088759A4A8BF17291BA95D6670A03AF426376B3F0030B4CB5AA86585AAB3B90479C958C1CFD15557BBEC8642EDCABF8566B6CBE6CB511E131A7EF9879F90BC23CDDB6D7EFC02F37F634B858D2534643F1EFB475EEECD6DAAFA7EE6159FFF997242F6A858A2A99B462512CEFCB4ADD5AD9EB921DE1
(PID) Process:(6464) zadig-2.4.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A767D57D1E5E49A31CF51EEF03D6C8AECF666D73
Operation:writeName:Blob
Value:
0B000000010000000E0000006C00690062007700640069000000030000000100000014000000A767D57D1E5E49A31CF51EEF03D6C8AECF666D732000000001000000D1050000308205CD308203B5A003020102021014CD3DA5DE7F2DBB48A509D9BBC7B6E9300D06092A864886F70D01010B050030633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3234303831313036303633305A170D3239303130313030303030305A30633161305F06035504031E58005500530042005C005600490044005F00300036003200370026005000490044005F003000300030003100200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100BA925609901AF1C373BBEF51A153871372686BAA1E1ED11F8BCDFC2658197B4696D8201471F4D5ABE509225707325C08DA9CAFA4242CFE98E3DF9D001B51C11AD98D2B6E065AFE5238C4C2B75B19C51BA1D0E485D3A85FB297E8ECE84CCF6176DF35D292F2350FEA712C339691CE4A09E87E95BDD52A54590AC356699B112937E78D8E3B4F0DA2873F4F3834DE42A0D4ECAD726FEBD24BEB36C89716267140713CF36491C5356EB307D9D44DA7704335ECBE61DEB324D16A967067941878EEC94000BEE69A587AA45A2BC38A7072D97A6660C727EDE9D2E56792F55B0F2A29A2575BFF881088CBB1EDCA473304EAC8A3C215046136711D07653D131EF2EF4083A47643B635203D9C5A2E1605E793192C15CEF396457522F954529411DE90A02AC748CC05F2F12ACB5AEE52091D3B45BE44B84A8569DF95BFB5ECFD857DFA45B487D47834EC5ECA16B119088B600EEC795CEC41044F353C1D33863616A1BDB64F0FBEBBA704AB0FF2012D1C85D5D3CE5F47E25BF47E62FD5E15AACB3F4C2328900288ED914F2A5D9E3B0B940339411F686B16373893AED4304CC2D391DC703A6624404972BFF0856981C3B5CE0EACDE6B58FB25EB1DD698F4AAFC04C816616CDB08DE515ED8763B2B9A230E91596B8D4C484B1491D7A9DBC3D74D64FBF091E1E36A82787D87FE69481136DF05F8A2FF5254C098C2C3C3E5322BB8AB9341B839090203010001A37D307B30160603551D250101FF040C300A06082B0601050507030330200603551D07041930178615687474703A2F2F6C69627764692E616B656F2E6965303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B0500038202010084635244A2DEB9D4BCA9986F8291EF6754864FAB3795267D2581344AA7965BF52CCF9499C12B5BD174C9E2A95D3875C69D5811B9C6CB69F74B254C6E86D6C7C654A32FF1CBD6F85267EAB3485A9D0BB2BA079377DE74CC74BE6AD7D7D8AAC391D31EC6DA8105504CED9B3C15631670CF3D8ABE0D737627EE4707246582FFD7507C183C1EB534D1CE0096BC7E1714D5B88FBB7045EB11D047FE05CC3270ED66A19EC3B79329F51496C78D3DE5F406EFE082826CE8485956BA8ABD1001C96940DF2CD055334B5E43ED333BC53F27601FFD299750F8DF76EAC120255F1CF4B1360F094FD6F64DF27DAB565EEB4CD8EC993F1CD83C50C31B9FA83523A24E91901D201C727B5C28B4BA9FC8359D7342F880FE01E8CB003776561D764CE6F8D179020F99224C5E403BC2055B44A5DC3943E635ED678A73E921A4A9E2F3101612AF33C19F24AC67CB76F6ADEF517265EF673965D84D043E2924657E0A4A29B577E877DE6C4E305BEF3790D373BD81AF0CC30305FCC2BD94370A5985A155BBAC2DB1307D45DBB612F586EDB6E40F098088759A4A8BF17291BA95D6670A03AF426376B3F0030B4CB5AA86585AAB3B90479C958C1CFD15557BBEC8642EDCABF8566B6CBE6CB511E131A7EF9879F90BC23CDDB6D7EFC02F37F634B858D2534643F1EFB475EEECD6DAAFA7EE6159FFF997242F6A858A2A99B462512CEFCB4ADD5AD9EB921DE1
Executable files
33
Suspicious files
11
Text files
3
Unknown types
2

Dropped files

PID
Process
Filename
Type
6464zadig-2.4.exeC:\Users\admin\usb_driver\x86\winusbcoinstaller2.dllexecutable
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B
SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C
6464zadig-2.4.exeC:\Users\admin\AppData\Local\Temp\winusbcoinstaller2.dllexecutable
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B
SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C
6464zadig-2.4.exeC:\Users\admin\usb_driver\x86\install-filter.exeexecutable
MD5:1A534450750ECA1F3D951DEF8D9965BF
SHA256:5E84D13636FBCE7869CDDC8B20C7D83FA0063E98C319E8E5AB751EDC9EE1DA76
6464zadig-2.4.exeC:\Users\admin\usb_driver\x86\WdfCoInstaller01011.dllexecutable
MD5:3D2A2D921135801835073451F002480F
SHA256:C7649879A10C9332FC0F9744C7E3224647AEE9E7E62C7E21CF9E987462E3DD06
6464zadig-2.4.exeC:\Users\admin\usb_driver\amd64\winusbcoinstaller2.dllexecutable
MD5:246900CE6474718730ECD4F873234CF5
SHA256:981A17EFFDDBC20377512DDAEC9F22C2B7067E17A3E2A8CCF82BB7BB7B2420B6
6464zadig-2.4.exeC:\Users\admin\usb_driver\x86\libusb0.sysexecutable
MD5:C8C9800179AF00C90629514E30873D80
SHA256:AA7D75A4D01B405AAB7C848674BBED392B64C6E374E20FD72ADC3C96294E2F00
6464zadig-2.4.exeC:\Users\admin\usb_driver\amd64\install-filter.exeexecutable
MD5:A16F041C87529221C86E16124C7E9ADD
SHA256:DF2ABF387893332F28C4DF68B10A6B176DC9706142055DCCCCF447F5A9CEDE2D
6464zadig-2.4.exeC:\Users\admin\usb_driver\amd64\libusb0.sysexecutable
MD5:16E18CED459B1824234890386EE66CD5
SHA256:8058F2AFE6EF96A7D2DED432997FD8655970C9EA75A938EE4557D6A2CB4CC989
6464zadig-2.4.exeC:\Users\admin\usb_driver\x86\libusb0.dllexecutable
MD5:1A534450750ECA1F3D951DEF8D9965BF
SHA256:5E84D13636FBCE7869CDDC8B20C7D83FA0063E98C319E8E5AB751EDC9EE1DA76
6464zadig-2.4.exeC:\Users\admin\usb_driver\license\libusb0\installer_license.txttext
MD5:3F886CCCE73C834D0BA9A07B89A5ADAD
SHA256:49A8AF4FC09A41B51744B936C9E7700001020F3C5AC4476D87767C6FC3CA2A1C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
47
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
300
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6820
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6856
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
5044
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1536
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5044
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
unknown
300
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.170
  • 104.126.37.171
  • 104.126.37.145
  • 104.126.37.178
  • 104.126.37.155
  • 104.126.37.153
  • 104.126.37.162
  • 104.126.37.163
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.71
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 184.86.251.9
  • 184.86.251.19
  • 184.86.251.22
  • 184.86.251.21
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.24.121.134
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted

Threats

No threats detected
Process
Message
zadig-2.4.exe
Windows 10 64-bit (Build 19045)
zadig-2.4.exe
ini file 'zadig.ini' not found - default parameters will be used
zadig-2.4.exe
Zadig 2.4.721
zadig-2.4.exe
default driver set to 'WinUSB'
zadig-2.4.exe
0 devices found.
zadig-2.4.exe
libwdi:debug [wdi_create_list] Hardware ID: USB\VID_0627&PID_0001&REV_0000
zadig-2.4.exe
libwdi:debug [wdi_create_list] Compatible ID: USB\Class_03&SubClass_00&Prot_00
zadig-2.4.exe
1 device found.
zadig-2.4.exe
libwdi:debug [wdi_create_list] Driver version: 10.0.19041.3636
zadig-2.4.exe
libwdi:debug [wdi_create_list] HidUsb USB device (0): USB\VID_0627&PID_0001\28754-0000:00:04.7-1