File name:

cpu-z_2.09-en.exe

Full analysis: https://app.any.run/tasks/5607ee49-1328-4062-a979-e440a6594d45
Verdict: Malicious activity
Analysis date: August 05, 2024, 14:48:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F1CE59F81DE106AA0CA4672E5971C6F2

SHA1:

21D9CA7A12479A0EC2AF4F1C567489A1192B7A21

SHA256:

657B7F4E403269768CD20F1A5B481878CECC775522CEEF119B2723E0844F2361

SSDEEP:

98304:hsgL0lWAa2HBZX30QlcFXkmuUmkeJ/DcSaeLx8J3kLHRDluptW18XCocM7c6BYaN:nyqPAg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cpu-z_2.09-en.exe (PID: 6428)
      • cpu-z_2.09-en.exe (PID: 6520)
      • cpu-z_2.09-en.tmp (PID: 6540)
      • cpuz.exe (PID: 6480)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • cpu-z_2.09-en.exe (PID: 6428)
      • cpu-z_2.09-en.exe (PID: 6520)
      • cpu-z_2.09-en.tmp (PID: 6540)
      • cpuz.exe (PID: 6480)
    • Reads security settings of Internet Explorer

      • cpu-z_2.09-en.tmp (PID: 6448)
      • cpuz.exe (PID: 6480)
    • Reads the date of Windows installation

      • cpu-z_2.09-en.tmp (PID: 6448)
    • Reads the Windows owner or organization settings

      • cpu-z_2.09-en.tmp (PID: 6540)
    • Start notepad (likely ransomware note)

      • cpu-z_2.09-en.tmp (PID: 6448)
    • Drops a system driver (possible attempt to evade defenses)

      • cpuz.exe (PID: 6480)
    • Checks Windows Trust Settings

      • cpuz.exe (PID: 6480)
  • INFO

    • Create files in a temporary directory

      • cpu-z_2.09-en.exe (PID: 6428)
      • cpu-z_2.09-en.exe (PID: 6520)
      • cpu-z_2.09-en.tmp (PID: 6540)
    • Reads the computer name

      • cpu-z_2.09-en.tmp (PID: 6448)
      • cpu-z_2.09-en.tmp (PID: 6540)
      • cpuz.exe (PID: 6480)
      • identity_helper.exe (PID: 7940)
    • Process checks computer location settings

      • cpu-z_2.09-en.tmp (PID: 6448)
    • Checks supported languages

      • cpu-z_2.09-en.tmp (PID: 6448)
      • cpu-z_2.09-en.exe (PID: 6428)
      • cpu-z_2.09-en.exe (PID: 6520)
      • cpu-z_2.09-en.tmp (PID: 6540)
      • _setup64.tmp (PID: 6852)
      • cpuz.exe (PID: 6480)
      • identity_helper.exe (PID: 7940)
    • Creates files in the program directory

      • cpu-z_2.09-en.tmp (PID: 6540)
    • Creates a software uninstall entry

      • cpu-z_2.09-en.tmp (PID: 6540)
    • Manual execution by a user

      • cpuz.exe (PID: 6536)
      • cpuz.exe (PID: 6480)
      • msedge.exe (PID: 6404)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 6964)
    • Checks proxy server information

      • cpuz.exe (PID: 6480)
    • Reads the software policy settings

      • cpuz.exe (PID: 6480)
    • Reads the machine GUID from the registry

      • cpuz.exe (PID: 6480)
    • Reads Environment values

      • cpuz.exe (PID: 6480)
      • identity_helper.exe (PID: 7940)
    • Creates files or folders in the user directory

      • cpuz.exe (PID: 6480)
    • Reads Microsoft Office registry keys

      • cpuz.exe (PID: 6480)
      • msedge.exe (PID: 6288)
      • msedge.exe (PID: 6404)
      • msedge.exe (PID: 6864)
    • Application launched itself

      • msedge.exe (PID: 6864)
      • msedge.exe (PID: 6404)
      • msedge.exe (PID: 6288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: CPUID, Inc.
FileDescription: CPUID CPU-Z Setup
FileVersion:
LegalCopyright:
ProductName: CPUID CPU-Z
ProductVersion: 2.09
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
56
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cpu-z_2.09-en.exe cpu-z_2.09-en.tmp no specs cpu-z_2.09-en.exe cpu-z_2.09-en.tmp _setup64.tmp no specs conhost.exe no specs notepad.exe no specs cpuz.exe no specs cpuz.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2732 --field-trial-handle=2356,i,3595922681998281143,1952853835273504985,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
568"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2b8,0x2bc,0x2c0,0x2b4,0x2c8,0x7fffd4775fd8,0x7fffd4775fe4,0x7fffd4775ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2372 --field-trial-handle=2380,i,2676660466986296739,4602516682095922447,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1168"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2556 --field-trial-handle=2380,i,2676660466986296739,4602516682095922447,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3972"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3688 --field-trial-handle=2356,i,3595922681998281143,1952853835273504985,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6152"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2656 --field-trial-handle=2356,i,3595922681998281143,1952853835273504985,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6288"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-windowC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6312"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2316 --field-trial-handle=2356,i,3595922681998281143,1952853835273504985,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4208 --field-trial-handle=2356,i,3595922681998281143,1952853835273504985,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6404"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://www.cpuid.com/driverfix.phpC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
19 009
Read events
18 835
Write events
164
Delete events
10

Modification events

(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
8C190000FD48E28B46E7DA01
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
F77201722899C3E26EBFE95A73500181976EC02377BAAED92930E2C6AE4B93A1
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\CPUID\CPU-Z\cpuz.exe
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
49B49EE076AAEC4FA36F5D468DF85027C9346C2FB4582727BC7B34B86E54DA66
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z
Operation:writeName:PATH
Value:
C:\Program Files\CPUID\CPU-Z
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z
Operation:writeName:PRODUCT_NAME
Value:
CPUID CPU-Z
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z
Operation:writeName:VERSION
Value:
2.09
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (a)
(PID) Process:(6540) cpu-z_2.09-en.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\CPUID\CPU-Z
Executable files
9
Suspicious files
134
Text files
89
Unknown types
9

Dropped files

PID
Process
Filename
Type
6428cpu-z_2.09-en.exeC:\Users\admin\AppData\Local\Temp\is-UUF3D.tmp\cpu-z_2.09-en.tmpexecutable
MD5:77B6D18B219D145C73F779D0D82F6BD0
SHA256:AAB8B17924B8F250D1CA477FA705D342BF620FF5864EBBC0B5E5D177C43A1743
6540cpu-z_2.09-en.tmpC:\Program Files\CPUID\CPU-Z\is-4N6PC.tmpexecutable
MD5:77B6D18B219D145C73F779D0D82F6BD0
SHA256:AAB8B17924B8F250D1CA477FA705D342BF620FF5864EBBC0B5E5D177C43A1743
6540cpu-z_2.09-en.tmpC:\Program Files\CPUID\CPU-Z\unins000.exeexecutable
MD5:77B6D18B219D145C73F779D0D82F6BD0
SHA256:AAB8B17924B8F250D1CA477FA705D342BF620FF5864EBBC0B5E5D177C43A1743
6540cpu-z_2.09-en.tmpC:\Program Files\CPUID\CPU-Z\is-5K3KR.tmpexecutable
MD5:28D0F05B4AA1C04D1D20687287696876
SHA256:07EE15632C25D9519F0E045A091F67C79E432EE01F07F2C0064D0B739840CFC8
6540cpu-z_2.09-en.tmpC:\Users\admin\AppData\Local\Temp\is-LH7HB.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6520cpu-z_2.09-en.exeC:\Users\admin\AppData\Local\Temp\is-IVU0M.tmp\cpu-z_2.09-en.tmpexecutable
MD5:77B6D18B219D145C73F779D0D82F6BD0
SHA256:AAB8B17924B8F250D1CA477FA705D342BF620FF5864EBBC0B5E5D177C43A1743
6540cpu-z_2.09-en.tmpC:\Program Files\CPUID\CPU-Z\cpuz.exeexecutable
MD5:28D0F05B4AA1C04D1D20687287696876
SHA256:07EE15632C25D9519F0E045A091F67C79E432EE01F07F2C0064D0B739840CFC8
6540cpu-z_2.09-en.tmpC:\Program Files\CPUID\CPU-Z\is-7L6FE.tmptext
MD5:E44F547A3378E46171D56A8A80CE9A40
SHA256:AB086F912FF00C8C3AB42B8CA6D01395A96ECA253FAE4B186A3CA72C230B66B0
6540cpu-z_2.09-en.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnklnk
MD5:E02B599D14ADA491E19168878B94F0A6
SHA256:C33350798B88E5EB55D282456AAB6F05812E67EA314AE10ABD6AC73B73369F0B
6540cpu-z_2.09-en.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnklnk
MD5:B68E6391567BCD94EDA08A718358F6F4
SHA256:41329795B226FE177ABD49A2702FB0F6B568BF5CF92EB2B4F2F5667B653FA598
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
135
DNS requests
132
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1928
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7076
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7116
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6480
cpuz.exe
GET
200
95.101.54.105:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgSTi%2FCGxZ2Esn2oh5KTXh7Xlg%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
2340
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3268
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
2.23.209.157:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1928
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.23.209.157
  • 2.23.209.171
  • 2.23.209.168
  • 2.23.209.160
  • 2.23.209.162
  • 2.23.209.169
  • 2.23.209.167
  • 2.23.209.166
  • 2.23.209.158
  • 2.23.209.176
  • 2.23.209.174
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.183
  • 2.23.209.182
  • 2.23.209.191
  • 2.23.209.187
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.140
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.74
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
th.bing.com
  • 2.23.209.158
  • 2.23.209.157
  • 2.23.209.171
  • 2.23.209.168
  • 2.23.209.160
  • 2.23.209.162
  • 2.23.209.169
  • 2.23.209.167
  • 2.23.209.166
whitelisted
download.cpuid.com
  • 195.154.81.43
whitelisted
r11.o.lencr.org
  • 95.101.54.105
  • 95.101.54.121
  • 95.101.54.202
  • 95.101.54.136
  • 95.101.54.122
  • 95.101.54.195
  • 95.101.54.123
  • 95.101.54.137
  • 95.101.54.120
whitelisted

Threats

PID
Process
Class
Message
6152
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6152
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info