File name:

VisualStudioSetup.exe

Full analysis: https://app.any.run/tasks/c550f8ed-eb11-4494-a311-cfb9c6574b5e
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:35:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
crypto-regex
github
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

CE97EBAA3196C9C5BC30C27D6D533309

SHA1:

2F3DCF95E76D7927ABBA382FE2B51A971567BA8A

SHA256:

6919B0F76A1D534F0772D97B2143265C88D3F7BF8ED13574A85DEB16618A1573

SSDEEP:

98304:4gx13DrRLo6VpP/dnLX2YPw35KSqyho/G0FBFLNySNgOrPi1P+jdpoHfyeIh6vfW:hV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • VisualStudioSetup.exe (PID: 7404)
    • Process drops legitimate windows executable

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • msedge.exe (PID: 6644)
      • msedge.exe (PID: 7472)
    • Executable content was dropped or overwritten

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • Reads security settings of Internet Explorer

      • vs_setup_bootstrapper.exe (PID: 7620)
      • VisualStudioSetup.exe (PID: 7404)
      • setup.exe (PID: 1660)
    • Found regular expressions for crypto-addresses (YARA)

      • vs_setup_bootstrapper.exe (PID: 7620)
    • The process creates files with name similar to system file names

      • vs_setup_bootstrapper.exe (PID: 7620)
    • The process drops C-runtime libraries

      • vs_setup_bootstrapper.exe (PID: 7620)
    • Searches for installed software

      • vs_installer.windows.exe (PID: 1912)
    • Creates a software uninstall entry

      • vs_installer.windows.exe (PID: 1912)
  • INFO

    • Create files in a temporary directory

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Reads the computer name

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
      • vs_installer.windows.exe (PID: 1912)
      • identity_helper.exe (PID: 6652)
    • The sample compiled with english language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • msedge.exe (PID: 7472)
      • msedge.exe (PID: 6644)
    • Reads the machine GUID from the registry

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Checks supported languages

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
      • identity_helper.exe (PID: 6652)
      • vs_installer.windows.exe (PID: 1912)
    • The sample compiled with turkish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with portuguese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with spanish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with chinese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with czech language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with french language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with Italian language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with japanese language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with german language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with russian language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with polish language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • The sample compiled with korean language support

      • VisualStudioSetup.exe (PID: 7404)
      • vs_setup_bootstrapper.exe (PID: 7620)
    • Process checks computer location settings

      • VisualStudioSetup.exe (PID: 7404)
    • Reads the software policy settings

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Checks proxy server information

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 7704)
    • Disables trace logs

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Reads CPU info

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Creates files in the program directory

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Creates files or folders in the user directory

      • vs_setup_bootstrapper.exe (PID: 7620)
      • setup.exe (PID: 1660)
    • Reads Environment values

      • setup.exe (PID: 1660)
      • identity_helper.exe (PID: 6652)
    • Manual execution by a user

      • msedge.exe (PID: 6644)
    • Application launched itself

      • msedge.exe (PID: 6644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:31 00:25:46+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 227328
InitializedDataSize: 199680
UninitializedDataSize: -
EntryPoint: 0x1dfd0
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.11.35219.272
ProductVersionNumber: 17.11.35219.272
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 17.11.35219.272
InternalName: vs_community.exe
OriginalFileName: vs_community.exe
ProductName: Microsoft Visual Studio Community
ProductVersion: Visual Studio 2022
LegalCopyright: © Microsoft Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
206
Monitored processes
60
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start visualstudiosetup.exe vs_setup_bootstrapper.exe getmac.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe setup.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs vs_installer.windows.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6940 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
540"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7380 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6972 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5660 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6520 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1452"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7108 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe" /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_202504290835198865.json" --locale en-US --activityId "4513d308-3a57-4c16-a039-e0693b099a8a" --campaign "2030:ce8625825fc2423fa31fd04ca1054174" --pipe "e0935898-86ef-4ee5-a3b9-cefe5eef0d72"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe
vs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Exit code:
0
Version:
3.13.2069.59209
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1912"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exe" /finalizeinstall 6F320B93-EE3C-4826-85E0-ADF79F8D4C61 "Visual Studio Installer" "Microsoft Visual Studio Installer" 3.13.2069.59209 0 "C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exesetup.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Microsoft.VisualStudio.Installer.Windows
Exit code:
0
Version:
3.13.2069.59209
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\vs_installer.windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6232 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5640 --field-trial-handle=2428,i,7299631371377958087,7552106094918050244,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
18 483
Read events
18 300
Write events
182
Delete events
1

Modification events

(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:VS.Core.Machine.VirtualMachineType
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features
Operation:writeName:__comment
Value:
True enables feature, False turns feature off
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features
Operation:writeName:RecommendSel
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\SortWklds*
Operation:writeName:0:SortWklds:Flight.VSWSortWklds
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\SortWklds*
Operation:writeName:1:SortWklds
Value:
0
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\RecWklds*
Operation:writeName:0:RecWklds:Flight.VSWRecWklds
Value:
1
(PID) Process:(7620) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\420\Installer\Features\RecWklds*
Operation:writeName:1:RecWklds
Value:
0
Executable files
470
Suspicious files
889
Text files
245
Unknown types
2

Dropped files

PID
Process
Filename
Type
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1042\help.htmlhtml
MD5:8125E76142C8438863F35CE5B8E63E57
SHA256:929A97C8A9A4EA4F72E2F17DBB20E76E604B7F1255F20874AA1C44AEC0F456C1
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\2052\help.htmlhtml
MD5:1BD86FBD65D005648103E050D9BEB9F1
SHA256:740117157B31BD5C634A232A0BA98A692B28ED2B4829EF52372200EB547D07CF
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1029\help.htmlhtml
MD5:432E50F4764D69625E5143571F823B6A
SHA256:C877FE7CD9544369A42A61B5C51264D74BFCA5B4BC5D4DD1FA703428261D6ABC
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1028\help.htmlhtml
MD5:EEAF8CBF54B4E891FF6BE38CF44E3814
SHA256:AAD5B2ACF30EB9C2DD35FF3B5C6C1A76CC4F1AE0AB6F382A635F5C329439F3AF
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1031\help.htmlhtml
MD5:6F489A55562732D253AD828581176A9A
SHA256:9502AC0910BCEE0EB3123F7B68A605D71C8DF72FE7B33F4173AFB4A01390581A
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1033\help.htmlhtml
MD5:4F7415E811ACBDDED478B40C3E7B287E
SHA256:55846D86DBE60B1B663018D72BEFA0F53A61D34A4EB093563B93A41B2FAA34A5
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1036\help.htmlhtml
MD5:F3F48126539E0BA3A98DD002FD224C3A
SHA256:7A13A7DA236E87310B88E620520C8DAB78F47210C57E1FABBD1AC3162215BAEB
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\3082\help.htmlhtml
MD5:0474106AC825B4F7727FF94576FC15C2
SHA256:A597AA82F35641455E12BD78662A05142F64BC221FF91D4EC4F2A8FA2983297F
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1049\help.htmlhtml
MD5:66D963430209555CDCB8A5C0219BC60C
SHA256:D9AB0A8DB5A8409C5849AA4E1512576225E5B320EA79B0CDC83C2B4848401611
7404VisualStudioSetup.exeC:\Users\admin\AppData\Local\Temp\ab6b8a0410c6e3e8ca324436\vs_bootstrapper_d15\HelpFile\1041\help.htmlhtml
MD5:92E54A7DB253A0A47C03B44D9651DF3C
SHA256:36C917F205A9C9D5F37788CA45ECD57D0F8EEB498F8320849BBEDF49E012E9F9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
207
DNS requests
182
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
7620
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
7528
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1746418466&P2=404&P3=2&P4=cveUQd%2bF9TIE7H01%2fjFta4khKGR1F%2bHcrW%2b0GK%2fw5G1HJhPnolNLc%2fhfDpWJ4zOjthYg4VOts%2fgmWE0nd5LcBQ%3d%3d
unknown
whitelisted
6728
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2152
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7620
vs_setup_bootstrapper.exe
23.48.23.34:443
az667904.vo.msecnd.net
Akamai International B.V.
DE
whitelisted
7620
vs_setup_bootstrapper.exe
69.192.162.125:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
7620
vs_setup_bootstrapper.exe
23.48.23.31:443
az700632.vo.msecnd.net
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
az667904.vo.msecnd.net
  • 23.48.23.34
  • 23.48.23.21
whitelisted
go.microsoft.com
  • 69.192.162.125
  • 184.28.89.167
whitelisted
az700632.vo.msecnd.net
  • 23.48.23.31
  • 23.48.23.61
whitelisted
targetednotifications-tm.trafficmanager.net
  • 20.42.128.98
whitelisted
aka.ms
  • 23.193.110.2
  • 92.123.38.9
whitelisted

Threats

PID
Process
Class
Message
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7472
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info