File name:

57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe

Full analysis: https://app.any.run/tasks/f7546398-06b5-4cfb-8aa6-d40fd5d4988b
Verdict: Malicious activity
Threats:

PrivateLoader is a malware family that is specifically created to infect computer systems and drop additional malicious programs. It operates using a pay-per-install business model, which means that the individuals behind it are paid for each instance of successful deployment of different types of harmful programs, including trojans, stealers, and other ransomware.

Analysis date: May 16, 2025, 23:41:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
privateloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 10 sections
MD5:

FDE4EC171A6E988C9640D8F8DCF35AEA

SHA1:

47D357A4E617B46E47DDC8AA9869F33A3C9FFFB8

SHA256:

57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7FD7B89CB97FBA2193355

SSDEEP:

98304:9bRwXuv0bjY0mqBvzKczYA3IycQ6XpyWzI/vjhugtsoQYWb7lFGo3:MeMVvaAPHzhug4pUy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PRIVATELOADER has been detected (YARA)

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
    • Changes the Windows auto-update feature

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8592)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8988)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9172)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8976)
  • SUSPICIOUS

    • Executes application which crashes

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
  • INFO

    • Checks supported languages

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8592)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8988)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9172)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9180)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8196)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8976)
    • The sample compiled with english language support

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
    • Reads the computer name

      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 5324)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8592)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8988)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8976)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9172)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 5728)
    • Manual execution by a user

      • firefox.exe (PID: 1616)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8592)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8880)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8976)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8912)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8988)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9032)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9044)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9172)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9080)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 9180)
      • 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe (PID: 8196)
    • Application launched itself

      • firefox.exe (PID: 1616)
      • firefox.exe (PID: 4220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:05:25 12:13:29+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 3105280
InitializedDataSize: 709120
UninitializedDataSize: -
EntryPoint: 0x8844a9
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.0.45.1145
ProductVersionNumber: 7.0.45.1145
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: N-able Take Control
FileDescription: TCDirectChat
FileVersion: 7.0.45.1145
InternalName: N-able Take Control
ProgramID: com.embarcadero.TCDirectChat
ProductName: TCDirectChat
ProductVersion: 7.0.45.1145
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
187
Monitored processes
30
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #PRIVATELOADER 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe sppextcomobj.exe no specs slui.exe no specs werfault.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe 57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1616"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
2772"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2152 -parentBuildID 20240213221259 -prefsHandle 2148 -prefMapHandle 2136 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {efc47b7a-c7a4-468f-97ed-d3f534b8ba69} 4220 "\\.\pipe\gecko-crash-server-pipe.4220" 1351bd82510 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
4220"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4776"C:\Users\admin\Desktop\57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe" C:\Users\admin\Desktop\57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeexplorer.exe
User:
admin
Company:
N-able Take Control
Integrity Level:
MEDIUM
Description:
TCDirectChat
Exit code:
3221226540
Version:
7.0.45.1145
Modules
Images
c:\users\admin\desktop\57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe
c:\windows\system32\ntdll.dll
5324"C:\Users\admin\Desktop\57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe" C:\Users\admin\Desktop\57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe
explorer.exe
User:
admin
Company:
N-able Take Control
Integrity Level:
HIGH
Description:
TCDirectChat
Exit code:
3221225620
Version:
7.0.45.1145
Modules
Images
c:\users\admin\desktop\57962d6e4dea092778ca4b98d68ee62d11a8cfa88fd7f.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5376"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2600 -childID 1 -isForBrowser -prefsHandle 2636 -prefMapHandle 2756 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1492 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0476f123-5c1e-4bdc-8e6d-3dd75260ea0a} 4220 "\\.\pipe\gecko-crash-server-pipe.4220" 1352d947f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
5728C:\WINDOWS\system32\WerFault.exe -u -p 5324 -s 880C:\Windows\System32\WerFault.exe57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
5892C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6068"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1828 -parentBuildID 20240213221259 -prefsHandle 1856 -prefMapHandle 1848 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b594abde-d65b-472c-931f-d23caaf20dc9} 4220 "\\.\pipe\gecko-crash-server-pipe.4220" 13528cef710 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
6744"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
18 870
Read events
18 400
Write events
285
Delete events
185

Modification events

(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\AppHVSI
Operation:writeName:AllowAppHVSI_ProviderSet
Value:
0
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\EdgeUpdate
Operation:writeName:UpdateDefault
Value:
0
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\Network Connections
Operation:writeName:NC_DoNotShowLocalOnlyIcon
Value:
1
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\Windows Feeds
Operation:writeName:EnableFeeds
Value:
0
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUServer
Value:
http://neverupdatewindows10.com
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUStatusServer
Value:
http://neverupdatewindows10.com
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:UpdateServiceUrlAlternate
Value:
http://neverupdatewindows10.com
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:**del.FillEmptyContentUrls
Value:
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
Operation:writeName:UseWUServer
Value:
1
(PID) Process:(5324) 57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8134BEE6-B528-4B81-A92D-DB4DD7C1ABAF}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
Operation:writeName:NoAutoUpdate
Value:
0
Executable files
0
Suspicious files
176
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
5728WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_57962D6E4DEA0927_9cce309a4e5bae7d751c69bc86cfd5159a8098_a4e47463_f50e1640-4662-496a-b399-4e0ba377581f\Report.wer
MD5:
SHA256:
4220firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
532457962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeC:\Windows\System32\GroupPolicy\gpt.initext
MD5:3D89F23265C9E30A0CF055C3EB4D637C
SHA256:806582F6221C79BD4C7EACDC4B63E937CE247EEE2BA159F55C545CDFB2B1C25B
532457962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exeC:\Windows\System32\GroupPolicy\Machine\Registry.polbinary
MD5:551F2716A3AF0148E9A55792A5708892
SHA256:B4E6B3EB7656C4D44F67FBCC6803525C17DCA34BD65AF9F146D8FCA3441AB565
5728WerFault.exeC:\Windows\appcompat\Programs\Amcache.hvebinary
MD5:3443C240CDEC7F56ABE1F8366F0D0368
SHA256:C716736080B53DD3703995E50FCCB0C3445F68066E40C8E8200253A150804F64
5728WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WEREC19.tmp.xmlxml
MD5:16D77D13CE992415F22CB13673765EB4
SHA256:710E84FFE35393585730EF03B99E3D2A82EB86DB1CBE67B9B3CC61C5EA53581C
5728WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WEREB3C.tmp.dmpbinary
MD5:19212B81C742AE88C48A6E57635FAAEB
SHA256:2393702B3A63C0BE7B136B934B6CAE1177BEC6F192BD44A91A82E53B0D6CA7E8
4220firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4220firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:65A78B271364C4FF16070B583295A539
SHA256:710254D1BCAFE9E37C2F148DA294161130B615479D8C4ED4566F57DAD133694A
5728WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe.5324.dmpbinary
MD5:A1B094A7068A8A9EF5AA95C279E2AC5C
SHA256:A6896327494F0B369B776B447488889C39ED9BE79E7FB665F7AFF94DA02FE4DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
158
DNS requests
129
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.177:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4220
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4220
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4220
firefox.exe
POST
200
184.24.77.54:80
http://r11.o.lencr.org/
unknown
whitelisted
4220
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
4220
firefox.exe
POST
200
184.24.77.54:80
http://r10.o.lencr.org/
unknown
whitelisted
4220
firefox.exe
POST
200
184.24.77.54:80
http://r11.o.lencr.org/
unknown
whitelisted
4220
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.177:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2196
svchost.exe
224.0.0.251:5353
unknown
2196
svchost.exe
224.0.0.252:5355
whitelisted
5324
57962D6E4DEA092778CA4B98D68EE62D11A8CFA88FD7F.exe
94.142.138.131:80
Network Management Ltd
RU
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.177
  • 23.48.23.176
  • 23.48.23.164
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.129
  • 20.190.159.68
  • 40.126.31.131
  • 20.190.159.129
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 23.215.0.133
  • 96.7.128.186
  • 23.215.0.132
  • 96.7.128.192
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] hCaptcha Enterprise Challenge
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] hCaptcha Enterprise Challenge
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] hCaptcha Enterprise Challenge
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] hCaptcha Enterprise Challenge
No debug info