File name:

VisualStudioSetup.exe

Full analysis: https://app.any.run/tasks/c550f8ed-eb11-4494-a311-cfb9c6574b5e
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:35:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
crypto-regex
github
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

CE97EBAA3196C9C5BC30C27D6D533309

SHA1:

2F3DCF95E76D7927ABBA382FE2B51A971567BA8A

SHA256:

6919B0F76A1D534F0772D97B2143265C88D3F7BF8ED13574A85DEB16618A1573

SSDEEP:

98304:4gx13DrRLo6VpP/dnLX2YPw35KSqyho/G0FBFLNySNgOrPi1P+jdpoHfyeIh6vfW:hV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • msedge.exe (PID: 7472)
      • msedge.exe (PID: 6644)
    • Starts a Microsoft application from unusual location

      • VisualStudioSetup.exe (PID: 7404)
    • Executable content was dropped or overwritten

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • Reads security settings of Internet Explorer

      • vs_setup_bootstrapper.exe (PID: 7620)
      • VisualStudioSetup.exe (PID: 7404)
      • setup.exe (PID: 1660)
    • Found regular expressions for crypto-addresses (YARA)

      • vs_setup_bootstrapper.exe (PID: 7620)
    • The process creates files with name similar to system file names

      • vs_setup_bootstrapper.exe (PID: 7620)
    • The process drops C-runtime libraries

      • vs_setup_bootstrapper.exe (PID: 7620)
    • Creates a software uninstall entry

      • vs_installer.windows.exe (PID: 1912)
    • Searches for installed software

      • vs_installer.windows.exe (PID: 1912)
  • INFO

    • The sample compiled with english language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • msedge.exe (PID: 7472)
      • msedge.exe (PID: 6644)
    • Reads the computer name

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
      • vs_installer.windows.exe (PID: 1912)
      • identity_helper.exe (PID: 6652)
    • Reads the machine GUID from the registry

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Checks supported languages

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
      • vs_installer.windows.exe (PID: 1912)
      • identity_helper.exe (PID: 6652)
    • Create files in a temporary directory

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • The sample compiled with spanish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with turkish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with chinese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with czech language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with portuguese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with french language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with Italian language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with japanese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with german language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with russian language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with polish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with korean language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • Process checks computer location settings

      • VisualStudioSetup.exe (PID: 7404)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 7704)
    • Disables trace logs

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Checks proxy server information

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Reads CPU info

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Creates files in the program directory

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Reads the software policy settings

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Creates files or folders in the user directory

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Manual execution by a user

      • msedge.exe (PID: 6644)
    • Application launched itself

      • msedge.exe (PID: 6644)
    • Reads Environment values

      • identity_helper.exe (PID: 6652)
      • setup.exe (PID: 1660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:31 00:25:46+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 227328
InitializedDataSize: 199680
UninitializedDataSize: -
EntryPoint: 0x1dfd0
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.11.35219.272
ProductVersionNumber: 17.11.35219.272
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 17.11.35219.272
InternalName: vs_community.exe
OriginalFileName: vs_community.exe
ProductName: Microsoft Visual Studio Community
ProductVersion: Visual Studio 2022
LegalCopyright: © Microsoft Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
206
Monitored processes
60
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start visualstudiosetup.exe vs_setup_bootstrapper.exe getmac.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe setup.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs vs_installer.windows.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6940 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
540"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7380 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6972 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5660 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6520 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1452"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7108 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe" /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_202504290835198865.json" --locale en-US --activityId "4513d308-3a57-4c16-a039-e0693b099a8a" --campaign "2030:ce8625825fc2423fa31fd04ca1054174" --pipe "e0935898-86ef-4ee5-a3b9-cefe5eef0d72"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe
vs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Exit code:
0
Version:
3.13.2069.59209
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1912"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exe" /finalizeinstall 6F320B93-EE3C-4826-85E0-ADF79F8D4C61 "Visual Studio Installer" "Microsoft Visual Studio Installer" 3.13.2069.59209 0 "C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exesetup.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Microsoft.VisualStudio.Installer.Windows
Exit code:
0
Version:
3.13.2069.59209
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\vs_installer.windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6232 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5640 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
18 483
Read events
18 300
Write events
182
Delete events
1

Modification events

(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:VS.Core.Machine.VirtualMachineType
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features
Operation:writeName:__comment
Value:
True enables feature, False turns feature off
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features
Operation:writeName:RecommendSel
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\SortWklds*
Operation:writeName:0:SortWklds:Flight.VSWSortWklds
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\SortWklds*
Operation:writeName:1:SortWklds
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\RecWklds*
Operation:writeName:0:RecWklds:Flight.VSWRecWklds
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\RecWklds*
Operation:writeName:1:RecWklds
Value:
0
Executable files
470
Suspicious files
889
Text files
245
Unknown types
2

Dropped files

PID
Process
Filename
Type
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1028\help.htmlhtml
MD5:EEAF8CBF54B4E891FF6BE38CF44E3814
SHA256:AAD5B2ACF30EB9C2DD35FF3B5C6C1A76CC4F1AE0AB6F382A635F5C329439F3AF
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1033\help.htmlhtml
MD5:4F7415E811ACBDDED478B40C3E7B287E
SHA256:55846D86DBE60B1B663018D72BEFA0F53A61D34A4EB093563B93A41B2FAA34A5
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1029\help.htmlhtml
MD5:432E50F4764D69625E5143571F823B6A
SHA256:C877FE7CD9544369A42A61B5C51264D74BFCA5B4BC5D4DD1FA703428261D6ABC
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\2052\help.htmlhtml
MD5:1BD86FBD65D005648103E050D9BEB9F1
SHA256:740117157B31BD5C634A232A0BA98A692B28ED2B4829EF52372200EB547D07CF
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1055\help.htmlhtml
MD5:C7B60E697671394781260D5B2CD21810
SHA256:CCF766B55CB0CC623F2705206A2AF04F2C83801580BC40A5AC20F644B814AB8F
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1045\help.htmlhtml
MD5:9147BC24EACE34955B865DAA39DAD8AB
SHA256:322DB9FFDB987D0C824A4DE3B8DB40722BCAF95833DCF90E7B5F250A841E592B
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1046\help.htmlhtml
MD5:C2BDEAA46B13E3CDE01E3DCAA734C0F2
SHA256:5A0802D6CA8D63D8476EEC79BDBD6079A17DC149D5D8C7DF13059D47BBB09F3A
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\3082\help.htmlhtml
MD5:0474106AC825B4F7727FF94576FC15C2
SHA256:A597AA82F35641455E12BD78662A05142F64BC221FF91D4EC4F2A8FA2983297F
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1040\help.htmlhtml
MD5:88289FD0D816A06C1A7B303397D0C122
SHA256:DF46CA96704CBEF3B79E0AA7A8B8239E7ACF12899B6C02A063F138C1F0F9FD34
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1036\help.htmlhtml
MD5:F3F48126539E0BA3A98DD002FD224C3A
SHA256:7A13A7DA236E87310B88E620520C8DAB78F47210C57E1FABBD1AC3162215BAEB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
207
DNS requests
182
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
6728
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
7528
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1746418466&P2=404&P3=2&P4=cveUQd%2bF9TIE7H01%2fjFta4khKGR1F%2bHcrW%2b0GK%2fw5G1HJhPnolNLc%2fhfDpWJ4zOjthYg4VOts%2fgmWE0nd5LcBQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2152
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7620
vs_setup_bootstrapper.exe
23.48.23.34:443
az667904.vo.msecnd.net
Akamai International B.V.
DE
whitelisted
7620
vs_setup_bootstrapper.exe
69.192.162.125:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
7620
vs_setup_bootstrapper.exe
23.48.23.31:443
az700632.vo.msecnd.net
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
az667904.vo.msecnd.net
  • 23.48.23.34
  • 23.48.23.21
whitelisted
go.microsoft.com
  • 69.192.162.125
  • 184.28.89.167
whitelisted
az700632.vo.msecnd.net
  • 23.48.23.31
  • 23.48.23.61
whitelisted
targetednotifications-tm.trafficmanager.net
  • 20.42.128.98
whitelisted
aka.ms
  • 23.193.110.2
  • 92.123.38.9
whitelisted

Threats

PID
Process
Class
Message
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info