File name:

Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com.zip

Full analysis: https://app.any.run/tasks/6fc4bafd-c14e-4a67-b139-9521892e6f01
Verdict: Malicious activity
Analysis date: July 20, 2021, 02:24:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

340AD223F6BB20C94553F97DE6299032

SHA1:

CFCBCBF0B13A7C65BEAD03C337EB62E3F65343B8

SHA256:

5F0C8A01CDB94D3ABF07217701444DEF69BFBF9296047815D144439A9EF39150

SSDEEP:

49152:rheNSnWwsoWKxdG99hPFkGwq4cyWvnfmnyz6gtgwBMy:rheoZsoW4dq9hPxwPctnunY6gtgwKy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3512)
      • Setup.exe (PID: 3432)
      • MsiExec.exe (PID: 3588)
      • MsiExec.exe (PID: 1008)
      • msiexec.exe (PID: 1828)
      • Keygen.exe (PID: 1820)
      • svchost.exe (PID: 768)
      • aspnet_regiis.exe (PID: 2108)
      • mscorsvw.exe (PID: 3836)
      • ngen.exe (PID: 2524)
    • Application was dropped or rewritten from another process

      • Keygen.exe (PID: 1820)
      • ndp48-web.exe (PID: 1996)
      • ndp48-web.exe (PID: 1892)
      • Setup.exe (PID: 3432)
      • SetupUtility.exe (PID: 1984)
      • SetupUtility.exe (PID: 2548)
      • ServiceModelReg.exe (PID: 1916)
      • regtlibv12.exe (PID: 932)
      • regtlibv12.exe (PID: 3876)
      • regtlibv12.exe (PID: 116)
      • regtlibv12.exe (PID: 2424)
      • regtlibv12.exe (PID: 4068)
      • regtlibv12.exe (PID: 3512)
      • regtlibv12.exe (PID: 3124)
      • aspnet_regiis.exe (PID: 2108)
      • ngen.exe (PID: 2524)
      • mscorsvw.exe (PID: 3836)
    • Actions looks like stealing of personal data

      • ndp48-web.exe (PID: 1892)
    • Changes settings of System certificates

      • Setup.exe (PID: 3432)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 1828)
    • Loads the Task Scheduler COM API

      • ngen.exe (PID: 2524)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1532)
      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 404)
      • ndp48-web.exe (PID: 1892)
      • TMPB357.tmp.exe (PID: 332)
      • Setup.exe (PID: 3432)
      • msiexec.exe (PID: 1828)
    • Checks supported languages

      • WinRAR.exe (PID: 1532)
      • Keygen.exe (PID: 1820)
      • ndp48-web.exe (PID: 1892)
      • Setup.exe (PID: 3432)
      • SetupUtility.exe (PID: 2548)
      • SetupUtility.exe (PID: 1984)
      • TMPB357.tmp.exe (PID: 332)
      • ServiceModelReg.exe (PID: 1916)
      • regtlibv12.exe (PID: 932)
      • regtlibv12.exe (PID: 3876)
      • mofcomp.exe (PID: 2776)
      • regtlibv12.exe (PID: 116)
      • regtlibv12.exe (PID: 2424)
      • regtlibv12.exe (PID: 4068)
      • regtlibv12.exe (PID: 3124)
      • regtlibv12.exe (PID: 3512)
      • mofcomp.exe (PID: 1936)
      • aspnet_regiis.exe (PID: 2108)
      • mofcomp.exe (PID: 2516)
      • mscorsvw.exe (PID: 3836)
      • ngen.exe (PID: 2524)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1532)
      • iexplore.exe (PID: 404)
      • ndp48-web.exe (PID: 1892)
      • iexplore.exe (PID: 2868)
      • msiexec.exe (PID: 1828)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1532)
      • msiexec.exe (PID: 1828)
    • Reads the computer name

      • Keygen.exe (PID: 1820)
      • WinRAR.exe (PID: 1532)
      • ndp48-web.exe (PID: 1892)
      • Setup.exe (PID: 3432)
      • SetupUtility.exe (PID: 2548)
      • SetupUtility.exe (PID: 1984)
      • TMPB357.tmp.exe (PID: 332)
      • ServiceModelReg.exe (PID: 1916)
      • mofcomp.exe (PID: 2776)
      • mofcomp.exe (PID: 1936)
      • aspnet_regiis.exe (PID: 2108)
      • mofcomp.exe (PID: 2516)
      • mscorsvw.exe (PID: 3836)
      • ngen.exe (PID: 2524)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2868)
    • Starts Internet Explorer

      • Keygen.exe (PID: 1820)
    • Reads Environment values

      • Setup.exe (PID: 3432)
    • Reads CPU info

      • Setup.exe (PID: 3432)
    • Executed as Windows Service

      • msiexec.exe (PID: 1828)
    • Application launched itself

      • msiexec.exe (PID: 1828)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 1828)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 1828)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1828)
    • Searches for installed software

      • msiexec.exe (PID: 1828)
    • Checks for the .NET to be installed

      • msiexec.exe (PID: 1828)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 1828)
      • aspnet_regiis.exe (PID: 2108)
    • Removes files from Windows directory

      • lodctr.exe (PID: 3640)
      • msiexec.exe (PID: 1828)
      • aspnet_regiis.exe (PID: 2108)
      • lodctr.exe (PID: 3420)
      • lodctr.exe (PID: 3096)
      • lodctr.exe (PID: 3184)
      • lodctr.exe (PID: 2408)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 1828)
      • lodctr.exe (PID: 3640)
      • aspnet_regiis.exe (PID: 2108)
      • lodctr.exe (PID: 3420)
      • ngen.exe (PID: 2524)
      • lodctr.exe (PID: 3096)
      • lodctr.exe (PID: 2408)
      • lodctr.exe (PID: 3184)
  • INFO

    • Manual execution by user

      • Keygen.exe (PID: 1820)
    • Changes internet zones settings

      • iexplore.exe (PID: 404)
    • Checks supported languages

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 404)
      • msiexec.exe (PID: 1828)
      • MsiExec.exe (PID: 3588)
      • MsiExec.exe (PID: 1008)
      • wevtutil.exe (PID: 3392)
      • wevtutil.exe (PID: 3592)
      • lodctr.exe (PID: 3640)
      • lodctr.exe (PID: 2328)
      • lodctr.exe (PID: 3492)
      • lodctr.exe (PID: 3420)
      • lodctr.exe (PID: 3096)
      • lodctr.exe (PID: 2408)
      • lodctr.exe (PID: 3184)
      • lodctr.exe (PID: 636)
    • Reads the computer name

      • iexplore.exe (PID: 404)
      • iexplore.exe (PID: 2868)
      • msiexec.exe (PID: 1828)
      • MsiExec.exe (PID: 3588)
      • MsiExec.exe (PID: 1008)
      • wevtutil.exe (PID: 3392)
      • wevtutil.exe (PID: 3592)
      • lodctr.exe (PID: 3640)
      • lodctr.exe (PID: 2328)
      • lodctr.exe (PID: 3492)
      • lodctr.exe (PID: 3420)
      • lodctr.exe (PID: 3096)
      • lodctr.exe (PID: 2408)
      • lodctr.exe (PID: 3184)
      • lodctr.exe (PID: 636)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 404)
      • Setup.exe (PID: 3432)
      • msiexec.exe (PID: 1828)
    • Application launched itself

      • iexplore.exe (PID: 404)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 404)
      • Setup.exe (PID: 3432)
      • msiexec.exe (PID: 1828)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2868)
    • Creates files in the user directory

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 404)
    • Changes settings of System certificates

      • iexplore.exe (PID: 404)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 404)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 404)
      • svchost.exe (PID: 768)
      • SetupUtility.exe (PID: 2548)
      • Setup.exe (PID: 3432)
      • msiexec.exe (PID: 1828)
      • mscorsvw.exe (PID: 3836)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 404)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 404)
    • Creates or modifies windows services

      • msiexec.exe (PID: 1828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com/Crack/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2020:05:23 21:25:14
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
99
Monitored processes
39
Malicious processes
17
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs keygen.exe no specs iexplore.exe iexplore.exe ndp48-web.exe no specs ndp48-web.exe setup.exe setuputility.exe no specs setuputility.exe no specs tmpb357.tmp.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs servicemodelreg.exe no specs wevtutil.exe no specs wevtutil.exe no specs svchost.exe no specs lodctr.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs regtlibv12.exe no specs mofcomp.exe no specs mofcomp.exe no specs aspnet_regiis.exe no specs mofcomp.exe no specs ngen.exe no specs mscorsvw.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe" "C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.tlb"C:\Windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
RegTLib
Exit code:
0
Version:
14.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regtlibv12.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
332TMPB357.tmp.exe /Q /X:C:\2e22b0a275581af8288861d85274dd\TMPB357.tmp.exe.tmpC:\2e22b0a275581af8288861d85274dd\TMPB357.tmp.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.8 Setup
Exit code:
0
Version:
4.8.03761.00
Modules
Images
c:\2e22b0a275581af8288861d85274dd\tmpb357.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
404"C:\Program Files\Internet Explorer\iexplore.exe" http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch&plcid=0x409&o1=.NETFramework,Version=v4.7.2&processName=Keygen.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.34209C:\Program Files\Internet Explorer\iexplore.exe
Keygen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
636"C:\Windows\system32\lodctr.exe" C:\Windows\Microsoft.NET\Framework\v4.0.30319\_DataOracleClientPerfCounters_shared12_neutral.iniC:\Windows\system32\lodctr.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Load PerfMon Counters
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\lodctr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\loadperf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
768C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
932"C:\Windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe" "C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.tlb"C:\Windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
RegTLib
Exit code:
0
Version:
14.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regtlibv12.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1008C:\Windows\system32\MsiExec.exe -Embedding 8196A786D027244DF124C4153B29731D E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1532"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1820"C:\Users\admin\Desktop\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Crack\Keygen.exe" C:\Users\admin\Desktop\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Crack\Keygen.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
GMW
Exit code:
2148734720
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\guna ui framework ultimate 2.0.0.1 worldfreeware.com\crack\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1828C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
85 969
Read events
69 638
Write events
14 529
Delete events
1 802

Modification events

(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1532) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com.zip
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2 485
Suspicious files
79
Text files
557
Unknown types
31

Dropped files

PID
Process
Filename
Type
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\.gitignoretext
MD5:
SHA256:
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Crack\Readme.txttext
MD5:
SHA256:
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna UI Activation.xmlxml
MD5:3C39AE459596B6A2B563BF33E043C69E
SHA256:2C9AF4FA0B26201143B19EBE2E140E722E98DB656157F6D738E4A0BD20F0E821
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna UI Activation.exeexecutable
MD5:06082988BD64B3D6514AA5C1E1665349
SHA256:93732E71605B2115FD5CEB1E4FAE438D9CC1637528755B999D9BF35622B7B70D
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna.UI2.dllexecutable
MD5:ACEC68D05E0B9B6C34A24DA530DC07B2
SHA256:BF72939922AFA2CD17071F5170B4A82D05BCEB1FC33CE29CDFBC68DBB97F0277
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna UI Activation.vshost.exeexecutable
MD5:FC9F896933B6123ABEBB21C8476448EC
SHA256:CC0D4C85639DD5E8D68C4B356C9DCF9C501BAE0190A08376BCED2BCC85E2CF79
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna UI Activation.vshost.exe.manifestxml
MD5:13C5BAC1F09AADF2C1F85E0729F69236
SHA256:F60B78D1D3CA2A3EADA7FBAFE3AA0F12803821B4828CDC7CFE88C24BB78A67BF
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Crack\Keygen.pdbpdb
MD5:061D770937FCA83E70FC3838EFE389A5
SHA256:1771EDEB0F66BB54F43000DA2DDBEB7A84245CD19D98F4F3B5A765797B2713A7
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation\bin\Debug\Guna UI Activation.pdbpdb
MD5:F2B5AD4ED64B52A0445E76C034DFAAA9
SHA256:06B0B0EE40C54991306D2F0872E6055F63E18B6090625E29F246212F189E89F0
1532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1532.22927\Guna UI Framework Ultimate 2.0.0.1 worldfreeware.com\Guna UI Framework Ultimate v2.0.0.1 Lib-Master\Guna UI Activation\Guna UI Activation.slntext
MD5:36E1F640B83FB42B2708C0CAF61514B5
SHA256:7E851F80A4C2A694F0855062435FCC7C31724693375E5CD3BBA05CBE09687DE0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
41
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
302
23.15.254.176:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=x86&o1=netfx_Full.mzz
NL
whitelisted
GET
302
23.15.254.176:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=amd64&o1=netfx_Full_x86.msi
NL
whitelisted
HEAD
302
23.15.254.176:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net48Rel1&plcid=0x409&clcid=0x409&ar=03761.00&sar=amd64&o1=netfx_Full_x86.msi
NL
whitelisted
2868
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
US
der
471 b
whitelisted
2868
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAtb9ltrp%2FvQiykNkEU33uA%3D
US
der
471 b
whitelisted
2868
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA9bw6F2y3ieICDHiTyBZ7Q%3D
US
der
1.47 Kb
whitelisted
2868
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
2868
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
3432
Setup.exe
GET
200
2.18.233.62:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
der
1.05 Kb
whitelisted
2868
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2868
iexplore.exe
23.15.254.176:443
go.microsoft.com
Akamai Technologies, Inc.
NL
malicious
2868
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2868
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2868
iexplore.exe
13.107.213.45:443
dotnet.microsoft.com
Microsoft Corporation
US
suspicious
2868
iexplore.exe
2.18.233.62:443
www.microsoft.com
Akamai International B.V.
whitelisted
2868
iexplore.exe
2.16.170.26:443
statics-marketingsites-wcus-ms-com.akamaized.net
Akamai International B.V.
DE
unknown
2868
iexplore.exe
2.16.170.25:443
img-prod-cms-rt-microsoft-com.akamaized.net
Akamai International B.V.
DE
unknown
2868
iexplore.exe
13.107.246.45:443
dotnet.microsoft.com
Microsoft Corporation
US
malicious
2868
iexplore.exe
173.194.198.101:443
www.google-analytics.com
Google Inc.
US
unknown
2868
iexplore.exe
152.199.21.175:443
az416426.vo.msecnd.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.15.254.176
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
dotnet.microsoft.com
  • 13.107.213.45
  • 13.107.246.45
whitelisted
statics-marketingsites-wcus-ms-com.akamaized.net
  • 2.16.170.26
  • 2.16.170.10
whitelisted
www.microsoft.com
  • 2.18.233.62
whitelisted
img-prod-cms-rt-microsoft-com.akamaized.net
  • 2.16.170.25
  • 2.16.170.11
whitelisted
wcpstatic.microsoft.com
  • 13.107.246.45
  • 13.107.213.45
whitelisted
www.google-analytics.com
  • 173.194.198.101
  • 173.194.198.102
  • 173.194.198.138
  • 173.194.198.139
  • 173.194.198.113
  • 173.194.198.100
whitelisted
az416426.vo.msecnd.net
  • 152.199.21.175
whitelisted

Threats

No threats detected
No debug info