File name:

Windows_xp_1.0.8.exe

Full analysis: https://app.any.run/tasks/d4cd8d64-1740-415d-b9c9-469a4a1f777d
Verdict: Malicious activity
Analysis date: February 27, 2024, 11:52:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6F23FF8839102D94B67654941AB620AB

SHA1:

ED5462D19012BED0E2D5DF6F9E779FB3FCF26628

SHA256:

61F6CD23FAFE23A44A41C394321CF9EC445705C8BAF5AA3B50F3C45F12C4594B

SSDEEP:

24576:D7blNima5gbcc77FyFbzjfr1jfoHGIZUjMxOLhTL3ZruoI8B7tcw:D75oT90FydzrlwHGIIaONngo/B7tcw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Windows_xp_1.0.8.exe (PID: 1776)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • Windows_xp_1.0.8.exe (PID: 3672)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3212)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Changes the autorun value in the registry

      • Windows_xp_1.0.8.tmp (PID: 2964)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Executable content was dropped or overwritten

      • Windows_xp_1.0.8.tmp (PID: 2964)
      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Process drops legitimate windows executable

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Drops a system driver (possible attempt to evade defenses)

      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3212)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2856)
    • Reads security settings of Internet Explorer

      • devcon.exe (PID: 3912)
    • Checks Windows Trust Settings

      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
    • Reads settings of System Certificates

      • devcon.exe (PID: 3912)
      • rundll32.exe (PID: 2900)
    • Adds/modifies Windows certificates

      • devcon.exe (PID: 3912)
    • The process drops C-runtime libraries

      • Windows_xp_1.0.8.tmp (PID: 2964)
  • INFO

    • Create files in a temporary directory

      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • devcon.exe (PID: 2332)
      • devcon.exe (PID: 3912)
      • WinDrvInstaller.exe (PID: 2620)
    • Checks supported languages

      • Windows_xp_1.0.8.exe (PID: 1776)
      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.tmp (PID: 3700)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 2332)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 2616)
    • Reads the computer name

      • Windows_xp_1.0.8.tmp (PID: 3700)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Creates files in the program directory

      • Windows_xp_1.0.8.tmp (PID: 2964)
      • WinDrvInstaller.exe (PID: 2620)
    • Creates files or folders in the user directory

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Creates a software uninstall entry

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 2332)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 2616)
      • drvinst.exe (PID: 3528)
      • WinDrvInstaller.exe (PID: 2620)
    • Reads the software policy settings

      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • rundll32.exe (PID: 2900)
      • drvinst.exe (PID: 1892)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 103936
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.8.0
ProductVersionNumber: 1.0.8.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: 深圳市恒亿昌科技有限公司
FileDescription: USB Display Setup
FileVersion: 1.0.8
LegalCopyright: Copyright © MS 2019
ProductName: USB Display
ProductVersion: 1.0.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
16
Malicious processes
13
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows_xp_1.0.8.exe windows_xp_1.0.8.tmp no specs windows_xp_1.0.8.exe windows_xp_1.0.8.tmp devcon.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs devcon.exe drvinst.exe rundll32.exe no specs drvinst.exe windrvinstaller.exe drvinst.exe rundll32.exe no specs drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1112DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{47f94fe9-7d55-3951-4beb-0745d5b9f24f}\dfmirage.inf" "0" "670102fe7" "000004B0" "WinSta0\Default" "00000558" "208" "c:\program files\usb display\video_driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1776"C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
深圳市恒亿昌科技有限公司
Integrity Level:
HIGH
Description:
USB Display Setup
Exit code:
0
Version:
1.0.8
Modules
Images
c:\users\admin\appdata\local\temp\windows_xp_1.0.8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1892DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem4.inf" "dfmirage.inf:DFMirage.Mfg.NTx86:DFMirage:1.0.0.0:dfmirage" "670102fe7" "000004B0" "00000074" "000005EC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2332"C:\Program Files\USB Display\tool\x86\devcon.exe" dp_add "C:\Program Files\USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03C:\Program Files\USB Display\tool\x86\devcon.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 (win7_wdk.100208-1538)
Modules
Images
c:\program files\usb display\tool\x86\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2616DrvInst.exe "2" "211" "ROOT\DISPLAY\0001" "C:\Windows\INF\oem5.inf" "virtualmonitor.inf:Model:VirtualMonitorVideo:0.2.1.0:virtualmonitorvideo" "6036fb98f" "000005D4" "000005E4" "000005EC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2620"C:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe" -iC:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
VirtualMonitor Org
Integrity Level:
HIGH
Description:
VirtualMonitor Driver Installer
Exit code:
0
Version:
.
Modules
Images
c:\program files\usb display\tool\x86\windrvinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2856C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2900rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{6040ed05-7b14-05b0-8dc3-a27b7a5c1262} Global\{40ae3b25-d6c7-5e55-5454-c02f2c08ea6d} C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.inf C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2964"C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp" /SL5="$19013E,1210479,146432,C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp
Windows_xp_1.0.8.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vuob7.tmp\windows_xp_1.0.8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3212DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{68039185-3266-0ff0-4c10-d9645176126d}\MSUSBDisplay.inf" "0" "69b557e9f" "000004B0" "WinSta0\Default" "000005D4" "208" "C:\Program Files\USB Display\lib_usb"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 511
Read events
23 859
Write events
632
Delete events
20

Modification events

(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
940B000020C5AF757369DA01
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
FF95589B20B0B43C303045AB3C1349F63085D7761B6558F9EEC930514D26E5F1
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\USB Display\msvcr100d.dll
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
6EC4F3B3852C2CEB6A404F74E50A954AE9B97B8A1D486EB719FB554D1247DFD6
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Windows Usb Display
Value:
C:\Program Files\USB Display\WinUsbDisplay.exe
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0
Operation:writeName:Attach.ToDesktop
Value:
0
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (a)
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\USB Display
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\USB Display\
Executable files
84
Suspicious files
41
Text files
6
Unknown types
31

Dropped files

PID
Process
Filename
Type
3672Windows_xp_1.0.8.exeC:\Users\admin\AppData\Local\Temp\is-5L3KJ.tmp\Windows_xp_1.0.8.tmpexecutable
MD5:1FDD4368D6B3B32E254143AE65D1FE37
SHA256:9E366C237E2F6CB880943EAE92BD99BA3190C2976A9FDEC65E875E9EE38D4CF5
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\unins000.exeexecutable
MD5:9733369807F170DE2AA6962593C349CC
SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-BOK54.tmpexecutable
MD5:9733369807F170DE2AA6962593C349CC
SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\tool\x64\is-K2DSH.tmpexecutable
MD5:3904D0698962E09DA946046020CBCB17
SHA256:A51E25ACC489948B31B1384E1DC29518D19B421D6BC0CED90587128899275289
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-BO9J1.tmptext
MD5:ACC6C4AFBACC6F88EF7C079D69B07B0D
SHA256:56FD302584C99D597CD81DB3E874EE310C8FBDCBCE0EE0ACA484B169906C696A
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-6KS6R.tmpexecutable
MD5:D57E2EDA325BAC8081FD054209D736AE
SHA256:5E47C4CF08450EA73D10E705FDCE727ACE66F8BCF4984028B1B17C91B8F630A6
1776Windows_xp_1.0.8.exeC:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmpexecutable
MD5:1FDD4368D6B3B32E254143AE65D1FE37
SHA256:9E366C237E2F6CB880943EAE92BD99BA3190C2976A9FDEC65E875E9EE38D4CF5
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\tool\x64\devcon.exeexecutable
MD5:3904D0698962E09DA946046020CBCB17
SHA256:A51E25ACC489948B31B1384E1DC29518D19B421D6BC0CED90587128899275289
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\libusb0.dllexecutable
MD5:DEC43589E19BEFFF9DAFF128C988A8DF
SHA256:CE81628EC616B204EA4E59047DFD5390227CC763CC7FF145A0B06DEC5C2529B4
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\tool\x64\is-ERRKH.tmpbinary
MD5:1683CCC18EE3F96633A1F50399312668
SHA256:64E94F0566AD1D54543E57A51F03BC5C43D61548FE3FA06D827FFF3364A3EB28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info