File name:

Fortect.exe

Full analysis: https://app.any.run/tasks/af8e619d-0597-4078-91d4-3f942a7417b4
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 11, 2025, 23:23:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pua
adware
arch-exec
nodejs
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

1C1F5F83A6CC3820676A0A33885EBAC0

SHA1:

71F951A4DE34A5DC7949AE437A415141F7E6BE2D

SHA256:

52338FFE0CE563424156BE19D9FA42C5FA9642B9CA53F92CEC0AA32DC87CC474

SSDEEP:

24576:DJ8m9Dr1nuCd38xObgBR87+sf9ZX2BDCv:DJ8mlrh/d38sbgBR87+sf9ZX2BDCv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • MainDaemon.exe (PID: 7428)
      • MainService.exe (PID: 2152)
      • Fortect.exe (PID: 7524)
      • svchost.exe (PID: 2196)
      • FortectMain.exe (PID: 5384)
      • MainDaemon.exe (PID: 6744)
    • Changes the autorun value in the registry

      • Fortect.exe (PID: 7524)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Fortect.exe (PID: 7376)
    • Executable content was dropped or overwritten

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • MainProtection.exe (PID: 7708)
      • FortectMain.exe (PID: 8052)
    • Reads security settings of Internet Explorer

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 7428)
      • MainProtection.exe (PID: 7708)
    • Application launched itself

      • Fortect.exe (PID: 7376)
      • FortectMain.exe (PID: 8052)
    • Access to an unwanted program domain was detected

      • svchost.exe (PID: 2196)
      • MainDaemon.exe (PID: 7428)
      • MainService.exe (PID: 2152)
      • Fortect.exe (PID: 7524)
      • FortectMain.exe (PID: 5384)
      • MainDaemon.exe (PID: 6744)
    • There is functionality for taking screenshot (YARA)

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
    • The process drops C-runtime libraries

      • Fortect.exe (PID: 7524)
    • Drops 7-zip archiver for unpacking

      • Fortect.exe (PID: 7524)
    • Process drops legitimate windows executable

      • Fortect.exe (PID: 7524)
    • Drops a system driver (possible attempt to evade defenses)

      • Fortect.exe (PID: 7524)
      • MainProtection.exe (PID: 7708)
    • Executes as Windows Service

      • MainDaemon.exe (PID: 6744)
      • MainService.exe (PID: 2152)
    • Creates a software uninstall entry

      • Fortect.exe (PID: 7524)
    • Reads the date of Windows installation

      • MainService.exe (PID: 2152)
    • Creates or modifies Windows services

      • MainProtection.exe (PID: 7708)
    • Searches for installed software

      • MainService.exe (PID: 2152)
    • Reads the BIOS version

      • MainService.exe (PID: 2152)
    • Creates files in the driver directory

      • MainService.exe (PID: 2152)
  • INFO

    • The sample compiled with english language support

      • Fortect.exe (PID: 7376)
      • MainProtection.exe (PID: 7708)
      • Fortect.exe (PID: 7524)
    • Reads the computer name

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 6744)
      • MainDaemon.exe (PID: 7428)
      • MainService.exe (PID: 1052)
      • MainService.exe (PID: 2152)
      • MainProtection.exe (PID: 7708)
      • MainProtection.exe (PID: 7904)
      • FortectMain.exe (PID: 5384)
      • FortectMain.exe (PID: 8052)
      • FortectMain.exe (PID: 8140)
    • Create files in a temporary directory

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • MainProtection.exe (PID: 7708)
      • FortectMain.exe (PID: 8052)
    • Checks supported languages

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 6744)
      • MainDaemon.exe (PID: 7428)
      • MainService.exe (PID: 2152)
      • MainService.exe (PID: 1052)
      • MainProtection.exe (PID: 7708)
      • MainProtection.exe (PID: 7904)
      • FortectTray.exe (PID: 8020)
      • FortectMain.exe (PID: 8052)
      • FortectMain.exe (PID: 5384)
      • FortectMain.exe (PID: 8140)
      • FortectMain.exe (PID: 6592)
    • Process checks computer location settings

      • Fortect.exe (PID: 7376)
      • Fortect.exe (PID: 7524)
      • FortectMain.exe (PID: 8052)
      • FortectMain.exe (PID: 6592)
    • Reads Environment values

      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 7428)
      • MainDaemon.exe (PID: 6744)
      • MainService.exe (PID: 1052)
      • MainService.exe (PID: 2152)
      • MainProtection.exe (PID: 7708)
      • MainProtection.exe (PID: 7904)
      • FortectMain.exe (PID: 8052)
    • Reads the machine GUID from the registry

      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 7428)
      • MainService.exe (PID: 1052)
      • MainService.exe (PID: 2152)
      • MainProtection.exe (PID: 7708)
      • FortectMain.exe (PID: 8052)
    • Creates files or folders in the user directory

      • Fortect.exe (PID: 7524)
      • MainProtection.exe (PID: 7708)
      • FortectMain.exe (PID: 8052)
      • FortectMain.exe (PID: 5384)
    • Creates files in the program directory

      • Fortect.exe (PID: 7524)
      • MainDaemon.exe (PID: 7428)
      • MainDaemon.exe (PID: 6744)
      • MainService.exe (PID: 1052)
      • MainService.exe (PID: 2152)
      • MainProtection.exe (PID: 7708)
    • Reads the software policy settings

      • slui.exe (PID: 7744)
      • MainDaemon.exe (PID: 7428)
      • MainProtection.exe (PID: 7708)
      • Fortect.exe (PID: 7524)
    • Checks proxy server information

      • MainProtection.exe (PID: 7708)
      • FortectMain.exe (PID: 8052)
      • Fortect.exe (PID: 7524)
    • Manual execution by a user

      • FortectTray.exe (PID: 8020)
      • FortectMain.exe (PID: 8052)
    • Reads product name

      • FortectMain.exe (PID: 8052)
      • MainService.exe (PID: 2152)
    • Reads CPU info

      • MainService.exe (PID: 2152)
    • Node.js compiler has been detected

      • FortectMain.exe (PID: 8052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.2.2.3
ProductVersionNumber: 7.2.2.3
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Fortect
FileDescription: Fortect Setup
FileVersion: 7.2.2.3
InternalName: Fortect.exe
LegalCopyright: © Fortect
LegalTrademarks: © Fortect
OriginalFileName: Fortect.exe
ProductName: Fortect
ProductVersion: 7.2.2.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
18
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fortect.exe #ADWARE fortect.exe #ADWARE svchost.exe sppextcomobj.exe no specs slui.exe #ADWARE maindaemon.exe slui.exe #ADWARE maindaemon.exe mainservice.exe no specs #ADWARE mainservice.exe mainprotection.exe mainprotection.exe no specs fortecttray.exe no specs fortectmain.exe fortectmain.exe no specs #ADWARE fortectmain.exe fortectmain.exe no specs fortectmain.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1052"C:\Program Files\Fortect\MainService.exe" --install --hostId 8a3dee36982280f9964c4c545c7b600246cdea575fb22971dd9699b657fc3036C:\Program Files\Fortect\MainService.exeFortect.exe
User:
admin
Company:
Fortect LTD.
Integrity Level:
HIGH
Description:
Fortect Service
Exit code:
0
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\mainservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2152"C:\Program Files\Fortect\MainService.exe"C:\Program Files\Fortect\MainService.exe
services.exe
User:
SYSTEM
Company:
Fortect LTD.
Integrity Level:
SYSTEM
Description:
Fortect Service
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\mainservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4380C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5384"C:\Program Files\Fortect\FortectMain.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\Fortect" --field-trial-handle=1892,i,5572369690160431216,3697000555166707285,262144 --enable-features=PdfUseShowSaveFilePicker --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=2268 /prefetch:3C:\Program Files\Fortect\FortectMain.exe
FortectMain.exe
User:
admin
Company:
Fortect LTD®
Integrity Level:
MEDIUM
Description:
Fortect Main
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\fortectmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6592"C:\Program Files\Fortect\FortectMain.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Fortect" --app-user-model-id=" " --app-path="C:\Program Files\Fortect\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=1892,i,5572369690160431216,3697000555166707285,262144 --enable-features=PdfUseShowSaveFilePicker --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=2644 /prefetch:1C:\Program Files\Fortect\FortectMain.exeFortectMain.exe
User:
admin
Company:
Fortect LTD®
Integrity Level:
MEDIUM
Description:
Fortect Main
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\fortectmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6744"C:\Program Files\Fortect\bin\MainDaemon.exe"C:\Program Files\Fortect\bin\MainDaemon.exe
services.exe
User:
SYSTEM
Company:
Fortect Ltd.
Integrity Level:
SYSTEM
Description:
Fortect Daemon
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\bin\maindaemon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
7376"C:\Users\admin\AppData\Local\Temp\Fortect.exe" C:\Users\admin\AppData\Local\Temp\Fortect.exe
explorer.exe
User:
admin
Company:
Fortect
Integrity Level:
MEDIUM
Description:
Fortect Setup
Exit code:
2
Version:
7.2.2.3
Modules
Images
c:\users\admin\appdata\local\temp\fortect.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7428"C:\Program Files\Fortect\bin\MainDaemon.exe" --install --hostId 8a3dee36982280f9964c4c545c7b600246cdea575fb22971dd9699b657fc3036C:\Program Files\Fortect\bin\MainDaemon.exe
Fortect.exe
User:
admin
Company:
Fortect Ltd.
Integrity Level:
HIGH
Description:
Fortect Daemon
Exit code:
0
Version:
7.2.2.3
Modules
Images
c:\program files\fortect\bin\maindaemon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7524"C:\Users\admin\AppData\Local\Temp\Fortect.exe" /UAC=newC:\Users\admin\AppData\Local\Temp\Fortect.exe
Fortect.exe
User:
admin
Company:
Fortect
Integrity Level:
HIGH
Description:
Fortect Setup
Exit code:
0
Version:
7.2.2.3
Modules
Images
c:\users\admin\appdata\local\temp\fortect.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
12 924 454
Read events
12 924 373
Write events
63
Delete events
18

Modification events

(PID) Process:(7524) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7524) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7524) Fortect.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7524) Fortect.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Engine
Operation:writeName:lang
Value:
1033
(PID) Process:(7524) Fortect.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon
Operation:writeName:Version
Value:
7.2.2.3
(PID) Process:(7428) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:user_settings
Value:
(PID) Process:(7428) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon
Operation:writeName:rid
Value:
1
(PID) Process:(7428) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:daily_license
Value:
(PID) Process:(7428) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:ack_event
Value:
(PID) Process:(7428) MainDaemon.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Fortect\Daemon\timers
Operation:writeName:notifications
Value:
Executable files
137
Suspicious files
297
Text files
114
Unknown types
1

Dropped files

PID
Process
Filename
Type
7524Fortect.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\FortectSetup64[1].tgz
MD5:
SHA256:
7524Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\FortectSetup64.7z
MD5:
SHA256:
7524Fortect.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:7E3584771FF6B2ABE84801F07E923702
SHA256:47C20A7A9CC6134BD02A924A1ECB99426B24485C66E8588F018921CC2432857E
7376Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\System.dllexecutable
MD5:074A2FECD36EF94675CB4623884B762C
SHA256:4C7C26BB007517A74CCB1EBBD78E2EBDABD75A33CE6CEAFCF8C3D868A7404D50
7376Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\LogEx.dllexecutable
MD5:9C3BC2EF57B3D38DD4738FB82F5643F2
SHA256:1D445ECD219B93D07FD1A6F04180C2260C35F368CD469BA6624F150E364F34FC
7524Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\nsDialogs.dllexecutable
MD5:7E0A4543D7B051950A74CD0AA3395343
SHA256:4C177764AC8D5B4608E0036AA5CECD18C735C1E276D5EF08A8D3F87C37379F48
7524Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\modern-header.bmpimage
MD5:1E608F54C109218745C0D7A06BCD5235
SHA256:843BB7E3A52E3EEB58A0EF385F21D80383C8E5E65DAF12BC297D570BC6722F22
7524Fortect.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\version[1].jsonbinary
MD5:EF5741CF8DE37A41D15DCD2F279D6310
SHA256:835942382A9BD43B9F000E7A1A745B2C07908F2F8E2537858B318C3B296993E8
7524Fortect.exeC:\Users\admin\AppData\Local\Temp\Fortect\plugins\nsJSON.dllexecutable
MD5:2F0E6646EEA3D1CF4BDC2EDC30D82ADC
SHA256:A5B6D5C332333576A950A5502882A3B1436F223662D0D3CE6AFAC89EDC013DD7
7524Fortect.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\events[2].htmtext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
70
DNS requests
29
Threats
46

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7524
Fortect.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
7524
Fortect.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7184
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7184
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7708
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7708
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7708
MainProtection.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAYWounW1yoM1LbA47gYwNs%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
7524
Fortect.exe
104.26.3.16:443
app.fortect.com
CLOUDFLARENET
US
unknown
7524
Fortect.exe
142.250.186.99:80
c.pki.goog
GOOGLE
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.16.206
whitelisted
app.fortect.com
  • 104.26.3.16
  • 172.67.75.40
  • 104.26.2.16
unknown
c.pki.goog
  • 142.250.186.99
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
cloud.fortect.com
  • 104.26.3.16
  • 172.67.75.40
  • 104.26.2.16
unknown
login.live.com
  • 20.190.159.4
  • 20.190.159.131
  • 20.190.159.0
  • 40.126.31.0
  • 40.126.31.69
  • 40.126.31.128
  • 40.126.31.129
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
7524
Fortect.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
7524
Fortect.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
7428
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
2196
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PC Optimizer Software Domain (fortect .com)
7428
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
7428
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
7428
MainDaemon.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
2152
MainService.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed PC Optimizer Software Domain (fortect .com in TLS SNI)
No debug info