| File name: | zadig-2.9.exe |
| Full analysis: | https://app.any.run/tasks/8290e56d-6b4a-4705-b663-f9ea60461ba1 |
| Verdict: | Malicious activity |
| Analysis date: | June 09, 2025, 22:17:07 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 780C870C02706AA64AB00D3FC0BFEF43 |
| SHA1: | 15FD0655B6E1324CADA7444A0F2F0B8820784BED |
| SHA256: | 4ECAA95DF3DA3621486A043AEF8B3050B8BAFE7C901402871E816229EF82039B |
| SSDEEP: | 98304:SitB4i47IMng9IRETniAG5wAm/H1qrqJGsjcbiyie45629QNR6aJry1QkHGtAlvL:/sQESmBcbL |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:13 12:54:27+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.4 |
| CodeSize: | 5296128 |
| InitializedDataSize: | 32768 |
| UninitializedDataSize: | 2195456 |
| EntryPoint: | 0x724670 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.9.788.0 |
| ProductVersionNumber: | 2.9.788.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Unknown (0009) |
| CharacterSet: | Unicode |
| CompanyName: | akeo.ie |
| FileDescription: | Zadig |
| FileVersion: | 2.9.788 |
| InternalName: | Zadig |
| LegalCopyright: | � 2010-2023 Pete Batard (GPL v3) |
| LegalTrademarks: | https://www.gnu.org/copyleft/gpl.html |
| OriginalFileName: | zadig.exe |
| ProductName: | Zadig |
| ProductVersion: | 2.9.788 |
| Comments: | https://zadig.akeo.ie |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2268 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{ea0ead43-2ac3-b740-b69a-38b40f7f5c59}\USB_Serial_(CDC)_Generic_Device.inf" "9" "4132e3227" "00000000000001D8" "WinSta0\Default" "00000000000001E8" "208" "C:\Users\admin\usb_driver" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5096 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5608 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5968 | "C:\Users\admin\AppData\Local\Temp\zadig-2.9.exe" | C:\Users\admin\AppData\Local\Temp\zadig-2.9.exe | explorer.exe | ||||||||||||
User: admin Company: akeo.ie Integrity Level: HIGH Description: Zadig Exit code: 0 Version: 2.9.788 Modules
| |||||||||||||||
| 6068 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | installer_x64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6268 | "C:\Users\admin\usb_driver\installer_x64.exe" "USB_Serial_(CDC)_Generic_Device.inf" | C:\Users\admin\usb_driver\installer_x64.exe | — | zadig-2.9.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 7428 | "C:\Users\admin\AppData\Local\Temp\zadig-2.9.exe" | C:\Users\admin\AppData\Local\Temp\zadig-2.9.exe | — | explorer.exe | |||||||||||
User: admin Company: akeo.ie Integrity Level: MEDIUM Description: Zadig Exit code: 3221226540 Version: 2.9.788 Modules
| |||||||||||||||
| 7484 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Akeo Consulting\Zadig |
| Operation: | write | Name: | CommCheck |
Value: 1177734 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Akeo Consulting\Zadig |
| Operation: | write | Name: | UpdateCheckInterval |
Value: 86400 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | 042E76C41F0A64889C48059CD26E2BF612544D6D |
Value: | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000042E76C41F0A64889C48059CD26E2BF612544D6D02000000010000004C0000001C0000000000000001000000200000000000000000000000020000006C006900620077006400690020006B0065007900200063006F006E007400610069006E006500720000000000000000000B000000010000000E0000006C006900620077006400690000002000000001000000DB050000308205D7308203BFA0030201020210183551BB897637AF486A6283CC59D841300D06092A864886F70D01010B0500305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3235303630393232313733385A170D3239303130313030303030305A305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100C071475464F8C4B2921CF8112C01304DBF161C50A8341A3F56A8449B9AA33FD8215CC235246A842DBC7FAA20A8FC50F319E40CE4914CF8853285CC2728E7E66C6A64FAA55B5EED6FCA7453A857AF04FA9E0B1F3D183322CA758815BD3837FD537BFBD2430074B47A7E4195FFDE115294ABF84E8FF98D7D2DDF2EE93827EB3F49ACF4F53FCB7F0F5EB413706CF9BC9651468486609356FF93D633A83A3E641E891FABD568E860C3A6D005B02A0453CE33EF39732FDF9189C98F6A9F51BE48779269ABB602BA8548F22F5282D18435BCB1C43D70B1E7D897F9A34D617DEF23F3DBA41E7382653B5AD76023BEA312BDE2361A5CCE5DC6AADA1112ADDB660BA30AE7833E3A1644450298B7F54BA7E45A77E563B5ED9D5015DCE3AFB05982D0D7FF2A4AF01CBD3D69840CBCACD706D64A71E58E9D756BF2156B677DBB45B517CE3BF32CDF8CD8516B767FC7432DE98DF4857E68A264A77294DA49DB620F5917D8DD811AC77716ED653EC1182121BEDCAE2A64F7FDDDFC73A63D499E152FDBFC4699962280A1A95C7A15A0F923BB60523566EB4504F225577B24CC9A4F293588689CB0559960F7C516BFFAE4F478872A1A2F27E7BE21C71C13CD0FE6608E9A77AF79B7C6A3144CDFAB43A9E3D341827E19DC2051C85E80B0F8C7B2D0DE8B108424433BCF9B000A06FD1CE14CFD1FFD2200C9626ECCA1E521A839F222423C68D0061CBD0203010001A3819230818F30160603551D250101FF040C300A06082B0601050507030330340603551D07042D302B812943726561746564206279206C69627764692028687474703A2F2F6C69627764692E616B656F2E696529303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B05000382020100A2994363A3ED70DE6C09577D9A09B4F4550D276D3C74679A8AA23ED6A66B4826C3025255A009CA03A9A90A4144DC73756960CE234590C888DFE367763CC0D64E18282DBC3675B1DC04A7CF93C88339528ED062E0C4B68C7C44C329A02719438C432418C27B2BF1B250DD763A66593433C6D70E8EFF2D62AB0A5528CFE4BE347F5399C66A912BB93275711393269688CD030641FE4900D5796CC2B6C8C675654CFC5D313BD702D1195BC076AEEC4D9AE0879E5C7AA9CF7B87F8FDCD816ECB5CE040CC54FFE366A342705875EF448176BCC38411A516968FE4015C6216EAB6B92F206FD187DFA7056290ED03A5B58F7B68F4AAA2A12B07CD08700AD6B081435423E4EDDE032CFAB1C4D53F70E7B3EE0A551CE3E6856CC4E996F0B5391F95E5BDBEDF78E3C9F4BF527D60DF9363BAC00866E4A76DE849A5B7A844C6CFCB22265515406CC37D3F3F0584E34063C0B49B7FB6A5F2BC2DD3524206B5F28E140B29737E93176D04F0090942BE64900C846A456272C6E1FD7484A07C969FA9FD31CD6D9BFFE499299D6D74AB99F36DCE3CDF42EB4B20CEBF2532DB6CB1649CCF0C5EF70E37B2B0B9EDB393CBC278757F0B05CCDF87754AEED7BB266607A0814612309AEE23AC933548E1BB3E218F28AA7761EAA792A4220CCCDC3C971758A3BE80FA0C0B78B347869FBD3451991E179B69F500B9FC284EF35CFBF6FA9B3C8D912EFF4148 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates |
| Operation: | delete value | Name: | 042E76C41F0A64889C48059CD26E2BF612544D6D |
Value: | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000042E76C41F0A64889C48059CD26E2BF612544D6D02000000010000004C0000001C0000000000000001000000200000000000000000000000020000006C006900620077006400690020006B0065007900200063006F006E007400610069006E006500720000000000000000000B000000010000000E0000006C006900620077006400690000002000000001000000DB050000308205D7308203BFA0030201020210183551BB897637AF486A6283CC59D841300D06092A864886F70D01010B0500305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3235303630393232313733385A170D3239303130313030303030305A305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100C071475464F8C4B2921CF8112C01304DBF161C50A8341A3F56A8449B9AA33FD8215CC235246A842DBC7FAA20A8FC50F319E40CE4914CF8853285CC2728E7E66C6A64FAA55B5EED6FCA7453A857AF04FA9E0B1F3D183322CA758815BD3837FD537BFBD2430074B47A7E4195FFDE115294ABF84E8FF98D7D2DDF2EE93827EB3F49ACF4F53FCB7F0F5EB413706CF9BC9651468486609356FF93D633A83A3E641E891FABD568E860C3A6D005B02A0453CE33EF39732FDF9189C98F6A9F51BE48779269ABB602BA8548F22F5282D18435BCB1C43D70B1E7D897F9A34D617DEF23F3DBA41E7382653B5AD76023BEA312BDE2361A5CCE5DC6AADA1112ADDB660BA30AE7833E3A1644450298B7F54BA7E45A77E563B5ED9D5015DCE3AFB05982D0D7FF2A4AF01CBD3D69840CBCACD706D64A71E58E9D756BF2156B677DBB45B517CE3BF32CDF8CD8516B767FC7432DE98DF4857E68A264A77294DA49DB620F5917D8DD811AC77716ED653EC1182121BEDCAE2A64F7FDDDFC73A63D499E152FDBFC4699962280A1A95C7A15A0F923BB60523566EB4504F225577B24CC9A4F293588689CB0559960F7C516BFFAE4F478872A1A2F27E7BE21C71C13CD0FE6608E9A77AF79B7C6A3144CDFAB43A9E3D341827E19DC2051C85E80B0F8C7B2D0DE8B108424433BCF9B000A06FD1CE14CFD1FFD2200C9626ECCA1E521A839F222423C68D0061CBD0203010001A3819230818F30160603551D250101FF040C300A06082B0601050507030330340603551D07042D302B812943726561746564206279206C69627764692028687474703A2F2F6C69627764692E616B656F2E696529303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B05000382020100A2994363A3ED70DE6C09577D9A09B4F4550D276D3C74679A8AA23ED6A66B4826C3025255A009CA03A9A90A4144DC73756960CE234590C888DFE367763CC0D64E18282DBC3675B1DC04A7CF93C88339528ED062E0C4B68C7C44C329A02719438C432418C27B2BF1B250DD763A66593433C6D70E8EFF2D62AB0A5528CFE4BE347F5399C66A912BB93275711393269688CD030641FE4900D5796CC2B6C8C675654CFC5D313BD702D1195BC076AEEC4D9AE0879E5C7AA9CF7B87F8FDCD816ECB5CE040CC54FFE366A342705875EF448176BCC38411A516968FE4015C6216EAB6B92F206FD187DFA7056290ED03A5B58F7B68F4AAA2A12B07CD08700AD6B081435423E4EDDE032CFAB1C4D53F70E7B3EE0A551CE3E6856CC4E996F0B5391F95E5BDBEDF78E3C9F4BF527D60DF9363BAC00866E4A76DE849A5B7A844C6CFCB22265515406CC37D3F3F0584E34063C0B49B7FB6A5F2BC2DD3524206B5F28E140B29737E93176D04F0090942BE64900C846A456272C6E1FD7484A07C969FA9FD31CD6D9BFFE499299D6D74AB99F36DCE3CDF42EB4B20CEBF2532DB6CB1649CCF0C5EF70E37B2B0B9EDB393CBC278757F0B05CCDF87754AEED7BB266607A0814612309AEE23AC933548E1BB3E218F28AA7761EAA792A4220CCCDC3C971758A3BE80FA0C0B78B347869FBD3451991E179B69F500B9FC284EF35CFBF6FA9B3C8D912EFF4148 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000042E76C41F0A64889C48059CD26E2BF612544D6D2000000001000000DB050000308205D7308203BFA0030201020210183551BB897637AF486A6283CC59D841300D06092A864886F70D01010B0500305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3235303630393232313733385A170D3239303130313030303030305A305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100C071475464F8C4B2921CF8112C01304DBF161C50A8341A3F56A8449B9AA33FD8215CC235246A842DBC7FAA20A8FC50F319E40CE4914CF8853285CC2728E7E66C6A64FAA55B5EED6FCA7453A857AF04FA9E0B1F3D183322CA758815BD3837FD537BFBD2430074B47A7E4195FFDE115294ABF84E8FF98D7D2DDF2EE93827EB3F49ACF4F53FCB7F0F5EB413706CF9BC9651468486609356FF93D633A83A3E641E891FABD568E860C3A6D005B02A0453CE33EF39732FDF9189C98F6A9F51BE48779269ABB602BA8548F22F5282D18435BCB1C43D70B1E7D897F9A34D617DEF23F3DBA41E7382653B5AD76023BEA312BDE2361A5CCE5DC6AADA1112ADDB660BA30AE7833E3A1644450298B7F54BA7E45A77E563B5ED9D5015DCE3AFB05982D0D7FF2A4AF01CBD3D69840CBCACD706D64A71E58E9D756BF2156B677DBB45B517CE3BF32CDF8CD8516B767FC7432DE98DF4857E68A264A77294DA49DB620F5917D8DD811AC77716ED653EC1182121BEDCAE2A64F7FDDDFC73A63D499E152FDBFC4699962280A1A95C7A15A0F923BB60523566EB4504F225577B24CC9A4F293588689CB0559960F7C516BFFAE4F478872A1A2F27E7BE21C71C13CD0FE6608E9A77AF79B7C6A3144CDFAB43A9E3D341827E19DC2051C85E80B0F8C7B2D0DE8B108424433BCF9B000A06FD1CE14CFD1FFD2200C9626ECCA1E521A839F222423C68D0061CBD0203010001A3819230818F30160603551D250101FF040C300A06082B0601050507030330340603551D07042D302B812943726561746564206279206C69627764692028687474703A2F2F6C69627764692E616B656F2E696529303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B05000382020100A2994363A3ED70DE6C09577D9A09B4F4550D276D3C74679A8AA23ED6A66B4826C3025255A009CA03A9A90A4144DC73756960CE234590C888DFE367763CC0D64E18282DBC3675B1DC04A7CF93C88339528ED062E0C4B68C7C44C329A02719438C432418C27B2BF1B250DD763A66593433C6D70E8EFF2D62AB0A5528CFE4BE347F5399C66A912BB93275711393269688CD030641FE4900D5796CC2B6C8C675654CFC5D313BD702D1195BC076AEEC4D9AE0879E5C7AA9CF7B87F8FDCD816ECB5CE040CC54FFE366A342705875EF448176BCC38411A516968FE4015C6216EAB6B92F206FD187DFA7056290ED03A5B58F7B68F4AAA2A12B07CD08700AD6B081435423E4EDDE032CFAB1C4D53F70E7B3EE0A551CE3E6856CC4E996F0B5391F95E5BDBEDF78E3C9F4BF527D60DF9363BAC00866E4A76DE849A5B7A844C6CFCB22265515406CC37D3F3F0584E34063C0B49B7FB6A5F2BC2DD3524206B5F28E140B29737E93176D04F0090942BE64900C846A456272C6E1FD7484A07C969FA9FD31CD6D9BFFE499299D6D74AB99F36DCE3CDF42EB4B20CEBF2532DB6CB1649CCF0C5EF70E37B2B0B9EDB393CBC278757F0B05CCDF87754AEED7BB266607A0814612309AEE23AC933548E1BB3E218F28AA7761EAA792A4220CCCDC3C971758A3BE80FA0C0B78B347869FBD3451991E179B69F500B9FC284EF35CFBF6FA9B3C8D912EFF4148 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | write | Name: | Blob |
Value: 0B000000010000000E0000006C00690062007700640069000000030000000100000014000000042E76C41F0A64889C48059CD26E2BF612544D6D2000000001000000DB050000308205D7308203BFA0030201020210183551BB897637AF486A6283CC59D841300D06092A864886F70D01010B0500305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E0065007200610074006500640029301E170D3235303630393232313733385A170D3239303130313030303030305A305D315B305906035504031E52005500530042005C004D0053005F0043004F004D0050005F00550053004200530045005200200028006C006900620077006400690020006100750074006F00670065006E006500720061007400650064002930820222300D06092A864886F70D01010105000382020F003082020A0282020100C071475464F8C4B2921CF8112C01304DBF161C50A8341A3F56A8449B9AA33FD8215CC235246A842DBC7FAA20A8FC50F319E40CE4914CF8853285CC2728E7E66C6A64FAA55B5EED6FCA7453A857AF04FA9E0B1F3D183322CA758815BD3837FD537BFBD2430074B47A7E4195FFDE115294ABF84E8FF98D7D2DDF2EE93827EB3F49ACF4F53FCB7F0F5EB413706CF9BC9651468486609356FF93D633A83A3E641E891FABD568E860C3A6D005B02A0453CE33EF39732FDF9189C98F6A9F51BE48779269ABB602BA8548F22F5282D18435BCB1C43D70B1E7D897F9A34D617DEF23F3DBA41E7382653B5AD76023BEA312BDE2361A5CCE5DC6AADA1112ADDB660BA30AE7833E3A1644450298B7F54BA7E45A77E563B5ED9D5015DCE3AFB05982D0D7FF2A4AF01CBD3D69840CBCACD706D64A71E58E9D756BF2156B677DBB45B517CE3BF32CDF8CD8516B767FC7432DE98DF4857E68A264A77294DA49DB620F5917D8DD811AC77716ED653EC1182121BEDCAE2A64F7FDDDFC73A63D499E152FDBFC4699962280A1A95C7A15A0F923BB60523566EB4504F225577B24CC9A4F293588689CB0559960F7C516BFFAE4F478872A1A2F27E7BE21C71C13CD0FE6608E9A77AF79B7C6A3144CDFAB43A9E3D341827E19DC2051C85E80B0F8C7B2D0DE8B108424433BCF9B000A06FD1CE14CFD1FFD2200C9626ECCA1E521A839F222423C68D0061CBD0203010001A3819230818F30160603551D250101FF040C300A06082B0601050507030330340603551D07042D302B812943726561746564206279206C69627764692028687474703A2F2F6C69627764692E616B656F2E696529303F0603551D2004383036303406082B060105050702013028302606082B06010505070201161A687474703A2F2F6C69627764692D6370732E616B656F2E696500300D06092A864886F70D01010B05000382020100A2994363A3ED70DE6C09577D9A09B4F4550D276D3C74679A8AA23ED6A66B4826C3025255A009CA03A9A90A4144DC73756960CE234590C888DFE367763CC0D64E18282DBC3675B1DC04A7CF93C88339528ED062E0C4B68C7C44C329A02719438C432418C27B2BF1B250DD763A66593433C6D70E8EFF2D62AB0A5528CFE4BE347F5399C66A912BB93275711393269688CD030641FE4900D5796CC2B6C8C675654CFC5D313BD702D1195BC076AEEC4D9AE0879E5C7AA9CF7B87F8FDCD816ECB5CE040CC54FFE366A342705875EF448176BCC38411A516968FE4015C6216EAB6B92F206FD187DFA7056290ED03A5B58F7B68F4AAA2A12B07CD08700AD6B081435423E4EDDE032CFAB1C4D53F70E7B3EE0A551CE3E6856CC4E996F0B5391F95E5BDBEDF78E3C9F4BF527D60DF9363BAC00866E4A76DE849A5B7A844C6CFCB22265515406CC37D3F3F0584E34063C0B49B7FB6A5F2BC2DD3524206B5F28E140B29737E93176D04F0090942BE64900C846A456272C6E1FD7484A07C969FA9FD31CD6D9BFFE499299D6D74AB99F36DCE3CDF42EB4B20CEBF2532DB6CB1649CCF0C5EF70E37B2B0B9EDB393CBC278757F0B05CCDF87754AEED7BB266607A0814612309AEE23AC933548E1BB3E218F28AA7761EAA792A4220CCCDC3C971758A3BE80FA0C0B78B347869FBD3451991E179B69F500B9FC284EF35CFBF6FA9B3C8D912EFF4148 | |||
| (PID) Process: | (5968) zadig-2.9.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\042E76C41F0A64889C48059CD26E2BF612544D6D |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5968 | zadig-2.9.exe | C:\Users\admin\AppData\Local\Temp\winusbcoinstaller2.dll | executable | |
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B | SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\AppData\Local\Temp\libusb0.dll | executable | |
MD5:7ACB3296C10A1C16C8F655E422DF653B | SHA256:D3D4DA84D99809FB0FA37C00704AC820D72B6EA5ED6279D9ADFB27E8DE1E785D | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\x86\winusbcoinstaller2.dll | executable | |
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B | SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\amd64\WdfCoInstaller01011.dll | executable | |
MD5:D10864C1730172780C2D4BE633B9220A | SHA256:F6FB39A8578F19616570D5A3DC7212C84A9DA232B30A03376BBF08F4264FEDF2 | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\amd64\winusbcoinstaller2.dll | executable | |
MD5:246900CE6474718730ECD4F873234CF5 | SHA256:981A17EFFDDBC20377512DDAEC9F22C2B7067E17A3E2A8CCF82BB7BB7B2420B6 | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\x86\install-filter.exe | executable | |
MD5:8D298178C3C4C862B4FA898C2B239286 | SHA256:82730B53C65942D291E65E63D8D268CE2A04433FFE01A89BD26B4069E9751F37 | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\amd64\libusb0_x86.dll | executable | |
MD5:7ACB3296C10A1C16C8F655E422DF653B | SHA256:D3D4DA84D99809FB0FA37C00704AC820D72B6EA5ED6279D9ADFB27E8DE1E785D | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\x86\libusb0_x86.dll | executable | |
MD5:7ACB3296C10A1C16C8F655E422DF653B | SHA256:D3D4DA84D99809FB0FA37C00704AC820D72B6EA5ED6279D9ADFB27E8DE1E785D | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\x86\libusb0.sys | executable | |
MD5:DDC1E2BCED77CCD433353B44C0B09585 | SHA256:1898CB1E61BA4BB5BF752C0B1BBF2E1A5CC066CE82D7230E2C75E67892F49A9B | |||
| 5968 | zadig-2.9.exe | C:\Users\admin\usb_driver\amd64\install-filter.exe | executable | |
MD5:4AC096B59629AA9953F0C470D30C00C2 | SHA256:31F8537A5EC6592BBDA450EB2A6FF45ED683C4FEC17E3FFA6CE1F5ADDA190AA0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.19.11.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7564 | svchost.exe | GET | 200 | 2.19.11.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7564 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7440 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7440 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5968 | zadig-2.9.exe | GET | 200 | 23.209.213.129:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
8020 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.19.11.120:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
7564 | svchost.exe | 2.19.11.120:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
7564 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7564 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.132:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
zadig.akeo.ie |
| whitelisted |