File name:

Windows_xp_1.0.8.exe

Full analysis: https://app.any.run/tasks/d4cd8d64-1740-415d-b9c9-469a4a1f777d
Verdict: Malicious activity
Analysis date: February 27, 2024, 11:52:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6F23FF8839102D94B67654941AB620AB

SHA1:

ED5462D19012BED0E2D5DF6F9E779FB3FCF26628

SHA256:

61F6CD23FAFE23A44A41C394321CF9EC445705C8BAF5AA3B50F3C45F12C4594B

SSDEEP:

24576:D7blNima5gbcc77FyFbzjfr1jfoHGIZUjMxOLhTL3ZruoI8B7tcw:D75oT90FydzrlwHGIIaONngo/B7tcw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 2616)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • drvinst.exe (PID: 3528)
    • Changes the autorun value in the registry

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3212)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Reads the Windows owner or organization settings

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • The process drops C-runtime libraries

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Drops a system driver (possible attempt to evade defenses)

      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2856)
    • Checks Windows Trust Settings

      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 1112)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3212)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Reads settings of System Certificates

      • devcon.exe (PID: 3912)
      • rundll32.exe (PID: 2900)
    • Reads security settings of Internet Explorer

      • devcon.exe (PID: 3912)
    • Adds/modifies Windows certificates

      • devcon.exe (PID: 3912)
    • Process drops legitimate windows executable

      • Windows_xp_1.0.8.tmp (PID: 2964)
  • INFO

    • Checks supported languages

      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.tmp (PID: 3700)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Create files in a temporary directory

      • Windows_xp_1.0.8.exe (PID: 3672)
      • Windows_xp_1.0.8.exe (PID: 1776)
      • devcon.exe (PID: 2332)
      • devcon.exe (PID: 3912)
      • WinDrvInstaller.exe (PID: 2620)
    • Reads the computer name

      • Windows_xp_1.0.8.tmp (PID: 3700)
      • Windows_xp_1.0.8.tmp (PID: 2964)
      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 3528)
      • drvinst.exe (PID: 2616)
    • Creates files or folders in the user directory

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Creates a software uninstall entry

      • Windows_xp_1.0.8.tmp (PID: 2964)
    • Reads the machine GUID from the registry

      • devcon.exe (PID: 2332)
      • drvinst.exe (PID: 3212)
      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1892)
      • drvinst.exe (PID: 3528)
      • WinDrvInstaller.exe (PID: 2620)
      • drvinst.exe (PID: 2616)
    • Reads the software policy settings

      • devcon.exe (PID: 3912)
      • drvinst.exe (PID: 1112)
      • rundll32.exe (PID: 2900)
      • drvinst.exe (PID: 1892)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2900)
    • Creates files in the program directory

      • WinDrvInstaller.exe (PID: 2620)
      • Windows_xp_1.0.8.tmp (PID: 2964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 103936
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.8.0
ProductVersionNumber: 1.0.8.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: 深圳市恒亿昌科技有限公司
FileDescription: USB Display Setup
FileVersion: 1.0.8
LegalCopyright: Copyright © MS 2019
ProductName: USB Display
ProductVersion: 1.0.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
16
Malicious processes
13
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows_xp_1.0.8.exe windows_xp_1.0.8.tmp no specs windows_xp_1.0.8.exe windows_xp_1.0.8.tmp devcon.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs devcon.exe drvinst.exe rundll32.exe no specs drvinst.exe windrvinstaller.exe drvinst.exe rundll32.exe no specs drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1112DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{47f94fe9-7d55-3951-4beb-0745d5b9f24f}\dfmirage.inf" "0" "670102fe7" "000004B0" "WinSta0\Default" "00000558" "208" "c:\program files\usb display\video_driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1776"C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
深圳市恒亿昌科技有限公司
Integrity Level:
HIGH
Description:
USB Display Setup
Exit code:
0
Version:
1.0.8
Modules
Images
c:\users\admin\appdata\local\temp\windows_xp_1.0.8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1892DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem4.inf" "dfmirage.inf:DFMirage.Mfg.NTx86:DFMirage:1.0.0.0:dfmirage" "670102fe7" "000004B0" "00000074" "000005EC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2332"C:\Program Files\USB Display\tool\x86\devcon.exe" dp_add "C:\Program Files\USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03C:\Program Files\USB Display\tool\x86\devcon.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 (win7_wdk.100208-1538)
Modules
Images
c:\program files\usb display\tool\x86\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2616DrvInst.exe "2" "211" "ROOT\DISPLAY\0001" "C:\Windows\INF\oem5.inf" "virtualmonitor.inf:Model:VirtualMonitorVideo:0.2.1.0:virtualmonitorvideo" "6036fb98f" "000005D4" "000005E4" "000005EC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2620"C:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe" -iC:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe
Windows_xp_1.0.8.tmp
User:
admin
Company:
VirtualMonitor Org
Integrity Level:
HIGH
Description:
VirtualMonitor Driver Installer
Exit code:
0
Version:
.
Modules
Images
c:\program files\usb display\tool\x86\windrvinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2856C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2900rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{6040ed05-7b14-05b0-8dc3-a27b7a5c1262} Global\{40ae3b25-d6c7-5e55-5454-c02f2c08ea6d} C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.inf C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2964"C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp" /SL5="$19013E,1210479,146432,C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp
Windows_xp_1.0.8.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vuob7.tmp\windows_xp_1.0.8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3212DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{68039185-3266-0ff0-4c10-d9645176126d}\MSUSBDisplay.inf" "0" "69b557e9f" "000004B0" "WinSta0\Default" "000005D4" "208" "C:\Program Files\USB Display\lib_usb"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 511
Read events
23 859
Write events
632
Delete events
20

Modification events

(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
940B000020C5AF757369DA01
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
FF95589B20B0B43C303045AB3C1349F63085D7761B6558F9EEC930514D26E5F1
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\USB Display\msvcr100d.dll
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
6EC4F3B3852C2CEB6A404F74E50A954AE9B97B8A1D486EB719FB554D1247DFD6
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Windows Usb Display
Value:
C:\Program Files\USB Display\WinUsbDisplay.exe
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0
Operation:writeName:Attach.ToDesktop
Value:
0
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (a)
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\USB Display
(PID) Process:(2964) Windows_xp_1.0.8.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\USB Display\
Executable files
84
Suspicious files
41
Text files
6
Unknown types
31

Dropped files

PID
Process
Filename
Type
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\unins000.exeexecutable
MD5:9733369807F170DE2AA6962593C349CC
SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-BOK54.tmpexecutable
MD5:9733369807F170DE2AA6962593C349CC
SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\msvcr100d.dllexecutable
MD5:D57E2EDA325BAC8081FD054209D736AE
SHA256:5E47C4CF08450EA73D10E705FDCE727ACE66F8BCF4984028B1B17C91B8F630A6
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\config.initext
MD5:ACC6C4AFBACC6F88EF7C079D69B07B0D
SHA256:56FD302584C99D597CD81DB3E874EE310C8FBDCBCE0EE0ACA484B169906C696A
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-BO9J1.tmptext
MD5:ACC6C4AFBACC6F88EF7C079D69B07B0D
SHA256:56FD302584C99D597CD81DB3E874EE310C8FBDCBCE0EE0ACA484B169906C696A
3672Windows_xp_1.0.8.exeC:\Users\admin\AppData\Local\Temp\is-5L3KJ.tmp\Windows_xp_1.0.8.tmpexecutable
MD5:1FDD4368D6B3B32E254143AE65D1FE37
SHA256:9E366C237E2F6CB880943EAE92BD99BA3190C2976A9FDEC65E875E9EE38D4CF5
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-DH6H5.tmpexecutable
MD5:29675ABD5B529FFE9291215A3C3960A9
SHA256:81C54C760773AE879ABDEA27DDB2876D4820CC3189D9C39BDEB47C0869716472
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\WinUsbDisplay.exeexecutable
MD5:29675ABD5B529FFE9291215A3C3960A9
SHA256:81C54C760773AE879ABDEA27DDB2876D4820CC3189D9C39BDEB47C0869716472
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-6KS6R.tmpexecutable
MD5:D57E2EDA325BAC8081FD054209D736AE
SHA256:5E47C4CF08450EA73D10E705FDCE727ACE66F8BCF4984028B1B17C91B8F630A6
2964Windows_xp_1.0.8.tmpC:\Program Files\USB Display\is-2OJL5.tmpimage
MD5:2098EF97358FBBDFAE0206BBCB4E2234
SHA256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info