File name:

AnVir Task Manager 9.4.0.exe

Full analysis: https://app.any.run/tasks/db51ff54-5374-4a9f-aa61-8ded784c85f1
Verdict: Malicious activity
Analysis date: July 09, 2025, 17:01:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
winring0x64-sys
vuln-driver
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

D04D100A8C874657B1BCA8F7858BC7FD

SHA1:

6BC4ADCE0A7FF720E76F17422C9F3D4F04974CA1

SHA256:

5D00BFF2A73948FA2FCCF37AD759A721CB367DF3D3DA3DFEEC4611FEA8341659

SSDEEP:

98304:iPriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhdXCClb6K05bjnzrWcpAw1Rdf1x/8p2:Xs4CtTLpNm1a7GR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
    • Vulnerable driver has been detected

      • OpenHardwareMonitor.exe (PID: 9848)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
    • Uses REG/REGEDIT.EXE to modify registry

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Executable content was dropped or overwritten

      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Reads the Windows owner or organization settings

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Process drops legitimate windows executable

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Application launched itself

      • AnVir.exe (PID: 6828)
    • The process checks if it is being run in the virtual environment

      • AnVir.exe (PID: 6420)
    • Drops a system driver (possible attempt to evade defenses)

      • OpenHardwareMonitor.exe (PID: 9848)
    • Adds/modifies Windows certificates

      • AnVir.exe (PID: 6420)
  • INFO

    • Checks supported languages

      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • SearchApp.exe (PID: 5328)
      • identity_helper.exe (PID: 3872)
      • AnVir.exe (PID: 6420)
      • anvir64.exe (PID: 7264)
      • AnVir.exe (PID: 6828)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
      • cvtres.exe (PID: 8792)
    • Compiled with Borland Delphi (YARA)

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Process checks computer location settings

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6828)
    • Creates files in the program directory

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Application launched itself

      • msedge.exe (PID: 7004)
      • msedge.exe (PID: 7716)
      • msedge.exe (PID: 3656)
      • msedge.exe (PID: 5600)
    • Reads the computer name

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • identity_helper.exe (PID: 3872)
      • AnVir.exe (PID: 6420)
      • anvir64.exe (PID: 7264)
      • AnVir.exe (PID: 6828)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Create files in a temporary directory

      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • mofcomp.exe (PID: 10164)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
      • cvtres.exe (PID: 8792)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • The sample compiled with english language support

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6420)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
    • Manual execution by a user

      • msedge.exe (PID: 5600)
      • AnVir.exe (PID: 6828)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6420)
    • Reads Environment values

      • identity_helper.exe (PID: 3872)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Checks proxy server information

      • AnVir.exe (PID: 6420)
    • Creates files or folders in the user directory

      • AnVir.exe (PID: 6420)
    • The sample compiled with japanese language support

      • OpenHardwareMonitor.exe (PID: 9848)
    • The sample compiled with russian language support

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Detects InnoSetup installer (YARA)

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • AnVir Task Manager 9.4.0.exe (PID: 7080)
    • Creates a software uninstall entry

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 25600
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.4.0.0
ProductVersionNumber: 9.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: LRepacks
FileDescription: AnVir Task Manager Setup
FileVersion: 9.4.0.0
LegalCopyright: Copyright 2007-2021 LRepacks
ProductName: AnVir Task Manager
ProductVersion: 9.4.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
189
Monitored processes
46
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anvir task manager 9.4.0.exe anvir task manager 9.4.0.tmp no specs regedit.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anvir.exe no specs anvir.exe anvir64.exe no specs openhardwaremonitor.exe no specs mofcomp.exe no specs conhost.exe no specs csc.exe no specs conhost.exe no specs cvtres.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs searchapp.exe anvir task manager 9.4.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmp" /SL5="$A036E,5888332,64512,C:\Users\admin\AppData\Local\Temp\AnVir Task Manager 9.4.0.exe" C:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmpAnVir Task Manager 9.4.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-iarpd.tmp\anvir task manager 9.4.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
952"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4280,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=4288 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1468"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --subproc-heap-profiling --always-read-main-dll --field-trial-handle=2260,i,2295321506707407999,1656711355463497522,262144 --variations-seed-version --mojo-platform-channel-handle=2520 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5028,i,1545725194726247926,10290825323775708012,262144 --variations-seed-version --mojo-platform-channel-handle=5016 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2368"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2228,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=2452 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2524"C:\WINDOWS\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\settings.reg"C:\Windows\SysWOW64\regedit.exe
AnVir Task Manager 9.4.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3028"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x2a0,0x2a4,0x2a8,0x298,0x2b0,0x7ffc446bf208,0x7ffc446bf214,0x7ffc446bf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2716,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=2736 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3656"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://lrepacks.net/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3872"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4768,i,1545725194726247926,10290825323775708012,262144 --variations-seed-version --mojo-platform-channel-handle=4292 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
47 934
Read events
47 630
Write events
285
Delete events
19

Modification events

(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:AnVir Task Manager
Value:
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:AutoCheckUpdate
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:DiskSizeIcons
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ExtendSystemMenu
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ExtendSaveDialog
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:FirstLaunch
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:IconsInTitles
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:MinOnClose
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:Language
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ShowAdverts
Value:
0
Executable files
44
Suspicious files
291
Text files
141
Unknown types
58

Dropped files

PID
Process
Filename
Type
7080AnVir Task Manager 9.4.0.exeC:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmpexecutable
MD5:338B7389F37A93F5279C7974F4DF67FB
SHA256:C9CB258045029DC2CB159E507847E3726666CC35AA16385DEAEF4B4E17255BF9
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\WizardForm.BitmapImage1.bmpimage
MD5:48386BC24D46A3FAC0056AB765A597A1
SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\MetroBlue.vsfbinary
MD5:295D085196B3DA13BFCD53373F82F8EE
SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\VclStylesInno.dllexecutable
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5
SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\OpenHardwareMonitor.exeexecutable
MD5:A261F824AB957A5331AF53C7722FA2DE
SHA256:EC767A74C5659A05BDB7AC10BD42C2EA6D44FA946286029B2866AED476AD83BC
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\HidLibrary.dllexecutable
MD5:DCED840C8ABD94998F8C9A1067EB2C0C
SHA256:8CF2F69939480212628965EC7AF3FA0EEAE50C7FBEFB4DDEB5AB8164BD44A099
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\unins000.exeexecutable
MD5:B00AD0CEA275E48E449F2CA42E5895B8
SHA256:B71126E8BA4D0B632D932A48FB1E17771D609AA02563B3C87A843C3DCA6A6488
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\is-P3828.tmpexecutable
MD5:84F1D429196CC4E89D22B2652E65F669
SHA256:EF02B0991AAC678052BB79DFDFD5BFA0B42B1F34B209E35819BA606909655F58
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\is-D7106.tmpexecutable
MD5:44B4642B1F8930723D2DC0C993A85C35
SHA256:A2A4ECD19AF6717BC21F806EB74F2589F989B509D1625AF6D802B71DFF677D88
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\is-OLFKR.tmpexecutable
MD5:B00AD0CEA275E48E449F2CA42E5895B8
SHA256:B71126E8BA4D0B632D932A48FB1E17771D609AA02563B3C87A843C3DCA6A6488
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
121
DNS requests
112
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2368
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:5cCF7qzyTxDH8-BnFck9A-lgJoGQfVS9XbWgiEJse84&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4320
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6704
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6420
AnVir.exe
GET
200
142.250.186.78:80
http://www.google-analytics.com/collect?v=1&tid=UA-2758427-1&cid=649566714&t=event&ec=Launch%5Fru&ea=ManualInstalled&el=9.4.0
unknown
whitelisted
6704
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6420
AnVir.exe
GET
200
2.17.189.192:80
http://crl.verisign.com/pca3.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2320
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4320
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4320
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.130
  • 40.126.31.73
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.128
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Misc activity
ET WEB_CLIENT Observed Hunter Obfuscator Code M1
Misc activity
ET WEB_CLIENT Observed Hunter Obfuscator Code M1
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2