File name:

DriverEasy_Setup.exe

Full analysis: https://app.any.run/tasks/4064a75a-5518-42ee-b8d1-c204ab5000ea
Verdict: Malicious activity
Analysis date: May 04, 2024, 09:13:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

ACF113BDC4583A106696935F4EB019EE

SHA1:

0AEFA5323925BD97BCE4AD1E5B604D5BA9E298F8

SHA256:

538CCBE8745DC8FC45223275CF4E69F9A7085421DB413B795B085400CDE146F4

SSDEEP:

98304:T+cD4dnGok8BazCB+tx/+IBBQHQOZF7CV6W+ytwlUXbZa5ZABAroyWZ98ZCCFvSI:EIvAZapB7q5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DriverEasy_Setup.exe (PID: 3972)
      • DriverEasy_Setup.exe (PID: 928)
      • DriverEasy_Setup.tmp (PID: 1120)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DriverEasy_Setup.exe (PID: 3972)
      • DriverEasy_Setup.exe (PID: 928)
      • DriverEasy_Setup.tmp (PID: 1120)
    • Reads the Windows owner or organization settings

      • DriverEasy_Setup.tmp (PID: 1120)
    • Drops 7-zip archiver for unpacking

      • DriverEasy_Setup.tmp (PID: 1120)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • DriverEasy_Setup.tmp (PID: 1120)
    • Reads security settings of Internet Explorer

      • DriverEasy_Setup.tmp (PID: 1120)
    • Reads the Internet Settings

      • DriverEasy.exe (PID: 308)
      • DriverEasy_Setup.tmp (PID: 1120)
    • Reads settings of System Certificates

      • DriverEasy.exe (PID: 308)
    • Adds/modifies Windows certificates

      • DriverEasy.exe (PID: 308)
  • INFO

    • Create files in a temporary directory

      • DriverEasy_Setup.exe (PID: 3972)
      • DriverEasy_Setup.exe (PID: 928)
      • DriverEasy_Setup.tmp (PID: 1120)
      • DriverEasy.exe (PID: 308)
    • Checks supported languages

      • DriverEasy_Setup.exe (PID: 3972)
      • DriverEasy_Setup.tmp (PID: 3988)
      • DriverEasy_Setup.exe (PID: 928)
      • Easeware.CheckScheduledScan.exe (PID: 2040)
      • DriverEasy_Setup.tmp (PID: 1120)
      • Easeware.ConfigLanguageFromSetup.exe (PID: 2136)
      • DriverEasy.exe (PID: 308)
      • wmpnscfg.exe (PID: 2936)
    • Reads the computer name

      • DriverEasy_Setup.tmp (PID: 3988)
      • DriverEasy_Setup.tmp (PID: 1120)
      • Easeware.CheckScheduledScan.exe (PID: 2040)
      • Easeware.ConfigLanguageFromSetup.exe (PID: 2136)
      • DriverEasy.exe (PID: 308)
      • wmpnscfg.exe (PID: 2936)
    • Creates files in the program directory

      • DriverEasy_Setup.tmp (PID: 1120)
    • Creates a software uninstall entry

      • DriverEasy_Setup.tmp (PID: 1120)
    • Creates files or folders in the user directory

      • Easeware.ConfigLanguageFromSetup.exe (PID: 2136)
    • Reads the machine GUID from the registry

      • DriverEasy.exe (PID: 308)
      • Easeware.CheckScheduledScan.exe (PID: 2040)
    • Manual execution by a user

      • msedge.exe (PID: 188)
      • wmpnscfg.exe (PID: 2936)
    • Application launched itself

      • msedge.exe (PID: 1060)
      • msedge.exe (PID: 188)
    • Reads Environment values

      • DriverEasy.exe (PID: 308)
    • Reads the software policy settings

      • DriverEasy.exe (PID: 308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 314880
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.8.1.41398
ProductVersionNumber: 5.8.1.41398
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Easeware
FileDescription: Driver Easy Setup
FileVersion: 5.8.1.41398
LegalCopyright: Copyright © 2023 Easeware.
OriginalFileName: DriverEasy_Setup.exe
ProductName: Driver Easy
ProductVersion: 5.8.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
22
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drivereasy_setup.exe drivereasy_setup.tmp no specs drivereasy_setup.exe drivereasy_setup.tmp easeware.checkscheduledscan.exe no specs easeware.configlanguagefromsetup.exe no specs drivereasy.exe msedge.exe no specs netsh.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.drivereasy.com/redirect/manager.php?info=postinstall&lang=en&ver=&installer_id=C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
308"C:\Program Files\Easeware\DriverEasy\DriverEasy.exe"C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
DriverEasy_Setup.tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
DriverEasy
Version:
5.8.1
Modules
Images
c:\program files\easeware\drivereasy\drivereasy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
692"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6645f598,0x6645f5a8,0x6645f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
856"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1296 --field-trial-handle=1240,i,258808058230922757,14312172175730833908,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
860"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1216 --field-trial-handle=1340,i,1742158213999427764,5578473956964287071,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
928"C:\Users\admin\AppData\Local\Temp\DriverEasy_Setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\DriverEasy_Setup.exe
DriverEasy_Setup.tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Driver Easy Setup
Exit code:
0
Version:
5.8.1.41398
Modules
Images
c:\users\admin\appdata\local\temp\drivereasy_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1060"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.drivereasy.com/redirect/manager.php?info=postinstall&lang=en&ver=&installer_id=C:\Program Files\Microsoft\Edge\Application\msedge.exeDriverEasy_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1120"C:\Users\admin\AppData\Local\Temp\is-AE46M.tmp\DriverEasy_Setup.tmp" /SL5="$2013A,4429772,1057792,C:\Users\admin\AppData\Local\Temp\DriverEasy_Setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-AE46M.tmp\DriverEasy_Setup.tmp
DriverEasy_Setup.exe
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ae46m.tmp\drivereasy_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1212"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1400 --field-trial-handle=1340,i,1742158213999427764,5578473956964287071,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1652"C:\Windows\System32\netsh.exe" advfirewall firewall add rule name="Driver Easy" description="Allow Driver Easy Access Internet to Scan and Download Drivers." dir=out action=allow program="C:\Program Files\Easeware\DriverEasy\DriverEasy.exe" enable=yes profile=anyC:\Windows\System32\netsh.exeDriverEasy_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
Total events
18 504
Read events
18 319
Write events
168
Delete events
17

Modification events

(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
60040000C6B1875A039EDA01
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4AF0202086B3983C60912843F59095D0DCC9F2A774097740EDAF9C9C4F4029ED
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
8339BFF7AAA72EA934E2CFDE91C5758D2C2CA43AA3260EFC34D8D1CE147127B2
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\drivereasy
Operation:writeName:URL Protocol
Value:
C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverEasy_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverEasy_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Easeware\DriverEasy
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverEasy_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Easeware\DriverEasy\
(PID) Process:(1120) DriverEasy_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverEasy_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Driver Easy
Executable files
32
Suspicious files
46
Text files
78
Unknown types
26

Dropped files

PID
Process
Filename
Type
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\innocallback.dllexecutable
MD5:1C55AE5EF9980E3B1028447DA6105C75
SHA256:6AFA2D104BE6EFE3D9A2AB96DBB75DB31565DAD64DD0B791E402ECC25529809F
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\icon_custom.pngimage
MD5:39AB68A67302E28F0AE08EC418890D2E
SHA256:A22AA447E1F620098E969D56688E79CC4B3B729AFE83A13468E86CD2927545DF
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\isxdl.dllexecutable
MD5:48AD1A1C893CE7BF456277A0A085ED01
SHA256:B0CC4697B2FD1B4163FDDCA2050FC62A9E7D221864F1BD11E739144C90B685B3
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\icon_uncustom.pngimage
MD5:5A7F3314FBD8A3DB765394798BC8A9CE
SHA256:2F67D842567176B42176784BB001EC63E3D84685FA35AEBE5C23DB20A969D427
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\background_welcome_more.pngimage
MD5:A6D3E5688C82C04D29A0A9EE356E9A8B
SHA256:E940C5F6F7CAD5CE4EB7A66E15F5604D4F4DA5902B53A5259EB045775C93EE4C
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\button_browse.pngimage
MD5:C7C746FCC5542D734A3860B425AC6A1E
SHA256:7CDAC82567CDD9719A83BCB62C098C6D2B19D115F10E3DB2B164B5F3B0ED1F89
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\background_welcome.pngimage
MD5:F048154D9062A3C2F147B6380CE6F3AC
SHA256:1D537619EA6508A383387D88E523522436E86DC72B929680E1552B10E44CF0F6
1120DriverEasy_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-NO2SR.tmp\progressbar_background.pngimage
MD5:8590E035E72584CA56EBA6A9DFB23A33
SHA256:C5267FFEA02E06C538C8BE10B1B83513830D6390A069761D10A4B67D9E684F0B
928DriverEasy_Setup.exeC:\Users\admin\AppData\Local\Temp\is-AE46M.tmp\DriverEasy_Setup.tmpexecutable
MD5:945FCB7A7FD86C96A36BEC419F528D1F
SHA256:C9D52631073331262504A87C2D8F10BE1F56D45F8CE837C886970D0F706A287C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
28
DNS requests
43
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
308
DriverEasy.exe
GET
200
2.22.242.122:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6332dae1732afbf8
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
188
msedge.exe
239.255.255.250:1900
unknown
2408
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2408
msedge.exe
51.38.74.198:443
www.drivereasy.com
OVH SAS
FR
unknown
2408
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2408
msedge.exe
142.250.186.136:443
www.googletagmanager.com
GOOGLE
US
unknown
2408
msedge.exe
142.250.185.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
2408
msedge.exe
142.250.185.150:443
i.ytimg.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.drivereasy.com
  • 51.38.74.198
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.googletagmanager.com
  • 142.250.186.136
whitelisted
yt3.ggpht.com
  • 142.250.74.193
whitelisted
i.ytimg.com
  • 142.250.185.150
  • 142.250.181.246
  • 142.250.186.54
  • 172.217.18.118
  • 142.250.184.246
  • 142.250.185.246
  • 216.58.206.86
  • 142.250.185.182
  • 172.217.23.118
  • 216.58.212.150
  • 142.250.186.182
  • 142.250.185.214
  • 142.250.185.86
  • 216.58.206.54
  • 142.250.185.118
  • 142.250.186.86
whitelisted
s.ytimg.com
  • 142.250.186.142
whitelisted
cdn.affiliatable.io
  • 169.150.247.37
unknown
images.drivereasy.com
  • 135.125.140.37
unknown
s.w.org
  • 192.0.77.48
whitelisted

Threats

No threats detected
No debug info