File name:

AnVir Task Manager 9.4.0.exe

Full analysis: https://app.any.run/tasks/db51ff54-5374-4a9f-aa61-8ded784c85f1
Verdict: Malicious activity
Analysis date: July 09, 2025, 17:01:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
winring0x64-sys
vuln-driver
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

D04D100A8C874657B1BCA8F7858BC7FD

SHA1:

6BC4ADCE0A7FF720E76F17422C9F3D4F04974CA1

SHA256:

5D00BFF2A73948FA2FCCF37AD759A721CB367DF3D3DA3DFEEC4611FEA8341659

SSDEEP:

98304:iPriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhdXCClb6K05bjnzrWcpAw1Rdf1x/8p2:Xs4CtTLpNm1a7GR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
    • Vulnerable driver has been detected

      • OpenHardwareMonitor.exe (PID: 9848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
    • Reads security settings of Internet Explorer

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
    • Uses REG/REGEDIT.EXE to modify registry

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Process drops legitimate windows executable

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Reads the Windows owner or organization settings

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Application launched itself

      • AnVir.exe (PID: 6828)
    • Adds/modifies Windows certificates

      • AnVir.exe (PID: 6420)
    • The process checks if it is being run in the virtual environment

      • AnVir.exe (PID: 6420)
    • Drops a system driver (possible attempt to evade defenses)

      • OpenHardwareMonitor.exe (PID: 9848)
  • INFO

    • Detects InnoSetup installer (YARA)

      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Creates a software uninstall entry

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Creates files in the program directory

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • OpenHardwareMonitor.exe (PID: 9848)
    • The sample compiled with russian language support

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Reads the computer name

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • identity_helper.exe (PID: 3872)
      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
      • anvir64.exe (PID: 7264)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Application launched itself

      • msedge.exe (PID: 7004)
      • msedge.exe (PID: 5600)
      • msedge.exe (PID: 3656)
      • msedge.exe (PID: 7716)
    • Process checks computer location settings

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6828)
    • Create files in a temporary directory

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • mofcomp.exe (PID: 10164)
      • OpenHardwareMonitor.exe (PID: 9848)
      • cvtres.exe (PID: 8792)
      • csc.exe (PID: 8576)
    • Compiled with Borland Delphi (YARA)

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
    • Checks supported languages

      • SearchApp.exe (PID: 5328)
      • identity_helper.exe (PID: 3872)
      • AnVir Task Manager 9.4.0.tmp (PID: 768)
      • AnVir Task Manager 9.4.0.exe (PID: 7080)
      • AnVir.exe (PID: 6828)
      • AnVir.exe (PID: 6420)
      • anvir64.exe (PID: 7264)
      • OpenHardwareMonitor.exe (PID: 9848)
      • csc.exe (PID: 8576)
      • cvtres.exe (PID: 8792)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6420)
    • Manual execution by a user

      • msedge.exe (PID: 5600)
      • AnVir.exe (PID: 6828)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5328)
      • AnVir.exe (PID: 6420)
      • csc.exe (PID: 8576)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Reads Environment values

      • identity_helper.exe (PID: 3872)
      • OpenHardwareMonitor.exe (PID: 9848)
    • Checks proxy server information

      • AnVir.exe (PID: 6420)
    • Creates files or folders in the user directory

      • AnVir.exe (PID: 6420)
    • The sample compiled with japanese language support

      • OpenHardwareMonitor.exe (PID: 9848)
    • The sample compiled with english language support

      • AnVir Task Manager 9.4.0.tmp (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 25600
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.4.0.0
ProductVersionNumber: 9.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: LRepacks
FileDescription: AnVir Task Manager Setup
FileVersion: 9.4.0.0
LegalCopyright: Copyright 2007-2021 LRepacks
ProductName: AnVir Task Manager
ProductVersion: 9.4.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
189
Monitored processes
46
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anvir task manager 9.4.0.exe anvir task manager 9.4.0.tmp no specs regedit.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anvir.exe no specs anvir.exe anvir64.exe no specs openhardwaremonitor.exe no specs mofcomp.exe no specs conhost.exe no specs csc.exe no specs conhost.exe no specs cvtres.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs searchapp.exe anvir task manager 9.4.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmp" /SL5="$A036E,5888332,64512,C:\Users\admin\AppData\Local\Temp\AnVir Task Manager 9.4.0.exe" C:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmpAnVir Task Manager 9.4.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-iarpd.tmp\anvir task manager 9.4.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
952"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4280,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=4288 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1468"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --subproc-heap-profiling --always-read-main-dll --field-trial-handle=2260,i,2295321506707407999,1656711355463497522,262144 --variations-seed-version --mojo-platform-channel-handle=2520 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5028,i,1545725194726247926,10290825323775708012,262144 --variations-seed-version --mojo-platform-channel-handle=5016 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2368"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2228,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=2452 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2524"C:\WINDOWS\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\settings.reg"C:\Windows\SysWOW64\regedit.exe
AnVir Task Manager 9.4.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3028"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x2a0,0x2a4,0x2a8,0x298,0x2b0,0x7ffc446bf208,0x7ffc446bf214,0x7ffc446bf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2716,i,1434768501967356438,7986543794541322802,262144 --variations-seed-version --mojo-platform-channel-handle=2736 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3656"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://lrepacks.net/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3872"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4768,i,1545725194726247926,10290825323775708012,262144 --variations-seed-version --mojo-platform-channel-handle=4292 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
47 934
Read events
47 630
Write events
285
Delete events
19

Modification events

(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:AnVir Task Manager
Value:
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:AutoCheckUpdate
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:DiskSizeIcons
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ExtendSystemMenu
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ExtendSaveDialog
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:FirstLaunch
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:IconsInTitles
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:MinOnClose
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:Language
Value:
0
(PID) Process:(768) AnVir Task Manager 9.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AnVir
Operation:writeName:ShowAdverts
Value:
0
Executable files
44
Suspicious files
291
Text files
141
Unknown types
58

Dropped files

PID
Process
Filename
Type
7080AnVir Task Manager 9.4.0.exeC:\Users\admin\AppData\Local\Temp\is-IARPD.tmp\AnVir Task Manager 9.4.0.tmpexecutable
MD5:338B7389F37A93F5279C7974F4DF67FB
SHA256:C9CB258045029DC2CB159E507847E3726666CC35AA16385DEAEF4B4E17255BF9
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\ISTask.dllexecutable
MD5:86A1311D51C00B278CB7F27796EA442E
SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D
768AnVir Task Manager 9.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-VTK4R.tmp\is-75715.tmpexecutable
MD5:44B878919F79E365120F1C960434870B
SHA256:A6967E7A3C2251812DD6B3FA0265FB7B61AADC568F562A98C50C345908C6E827
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\HidLibrary.dllexecutable
MD5:DCED840C8ABD94998F8C9A1067EB2C0C
SHA256:8CF2F69939480212628965EC7AF3FA0EEAE50C7FBEFB4DDEB5AB8164BD44A099
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\Aga.Controls.dllexecutable
MD5:F17BE368ADE3F7CFBB6AA9DD734CE328
SHA256:830E520CAF3E89DCCAA3C12E3BFC992221C164F2319A2BA57E402499C24290E3
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\is-4CPF8.tmpexecutable
MD5:F17BE368ADE3F7CFBB6AA9DD734CE328
SHA256:830E520CAF3E89DCCAA3C12E3BFC992221C164F2319A2BA57E402499C24290E3
768AnVir Task Manager 9.4.0.tmpC:\Program Files (x86)\AnVir Task Manager\OpenHardwareMonitor\is-P3828.tmpexecutable
MD5:84F1D429196CC4E89D22B2652E65F669
SHA256:EF02B0991AAC678052BB79DFDFD5BFA0B42B1F34B209E35819BA606909655F58
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
121
DNS requests
112
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6704
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6420
AnVir.exe
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2368
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:5cCF7qzyTxDH8-BnFck9A-lgJoGQfVS9XbWgiEJse84&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
4320
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6704
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6420
AnVir.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6420
AnVir.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2320
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4320
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4320
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.130
  • 40.126.31.73
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.128
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Misc activity
ET WEB_CLIENT Observed Hunter Obfuscator Code M1
Misc activity
ET WEB_CLIENT Observed Hunter Obfuscator Code M1
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2