File name:

csaudiointcsof.1.0.4-installer.exe

Full analysis: https://app.any.run/tasks/e217bfd7-7612-4302-8ddd-3e80729873dc
Verdict: Malicious activity
Analysis date: May 17, 2025, 16:39:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

379D8A3FA074A375A7E0D4D2D38AB853

SHA1:

7058AC9045ABD2D27A58DCAF49E771CFD218ACEE

SHA256:

70C440F0EF3712D1D00ABCAE7815F2281676A7DD80DAD3A3AD6F82044CE5326D

SSDEEP:

98304:yyFUS/0g8tY2yFneiayvTBiq8m6fAsSccr1fOerbR8axpwlCvBvwxjuA9c630hxz:l1Z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • net.exe (PID: 1300)
      • net.exe (PID: 2088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • drvinst.exe (PID: 2236)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 1056)
      • drvinst.exe (PID: 6988)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 6244)
      • dpinst.exe (PID: 7084)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 6112)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5892)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 2420)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6388)
      • drvinst.exe (PID: 5176)
    • The process creates files with name similar to system file names

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2236)
      • drvinst.exe (PID: 6988)
      • drvinst.exe (PID: 1056)
      • drvinst.exe (PID: 6300)
      • drvinst.exe (PID: 6244)
      • drvinst.exe (PID: 6516)
      • drvinst.exe (PID: 6112)
      • drvinst.exe (PID: 6272)
      • drvinst.exe (PID: 5964)
      • drvinst.exe (PID: 5892)
      • drvinst.exe (PID: 4620)
      • drvinst.exe (PID: 5176)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 2236)
      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 1056)
      • drvinst.exe (PID: 6988)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 5892)
      • dpinst.exe (PID: 7084)
      • drvinst.exe (PID: 6244)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 5008)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 6112)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5892)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6388)
      • drvinst.exe (PID: 5176)
    • Process drops legitimate windows executable

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
    • Creates a software uninstall entry

      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • dpinst.exe (PID: 5892)
      • dpinst.exe (PID: 7084)
      • dpinst.exe (PID: 5008)
      • dpinst.exe (PID: 1164)
      • dpinst.exe (PID: 4408)
      • dpinst.exe (PID: 1672)
      • dpinst.exe (PID: 2420)
      • dpinst.exe (PID: 6592)
      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6388)
    • There is functionality for taking screenshot (YARA)

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
    • Searches for installed software

      • svchost.exe (PID: 2996)
      • CompatTelRunner.exe (PID: 1132)
    • Windows service management via SC.EXE

      • sc.exe (PID: 2148)
    • Creates a new Windows service

      • sc.exe (PID: 1324)
    • Executes as Windows Service

      • csaudioendpointswitcher.exe (PID: 5360)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 6272)
  • INFO

    • Reads the software policy settings

      • consent.exe (PID: 5244)
      • WaaSMedicAgent.exe (PID: 5556)
      • drvinst.exe (PID: 2236)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • drvinst.exe (PID: 6988)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 1056)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 6300)
      • drvinst.exe (PID: 6244)
      • dpinst.exe (PID: 7084)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6112)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 1164)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 5892)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 5176)
      • dpinst.exe (PID: 6388)
      • SIHClient.exe (PID: 6872)
    • Manual execution by a user

      • csaudiointcsof.1.0.4-installer.exe (PID: 6032)
    • Checks supported languages

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • drvinst.exe (PID: 2236)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 6988)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 1056)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 7084)
      • drvinst.exe (PID: 6244)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6516)
      • drvinst.exe (PID: 6112)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 4408)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5892)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 5964)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 5176)
      • dpinst.exe (PID: 6388)
      • csaudioendpointswitcher.exe (PID: 5360)
      • ShellExperienceHost.exe (PID: 6272)
    • Create files in a temporary directory

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • dpinst.exe (PID: 7084)
      • dpinst.exe (PID: 5892)
      • dpinst.exe (PID: 5008)
      • dpinst.exe (PID: 1164)
      • dpinst.exe (PID: 4408)
      • dpinst.exe (PID: 1672)
      • dpinst.exe (PID: 2420)
      • dpinst.exe (PID: 6592)
      • dpinst.exe (PID: 6388)
    • Reads the computer name

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • drvinst.exe (PID: 2236)
      • drvinst.exe (PID: 6988)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 1056)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 7084)
      • drvinst.exe (PID: 6244)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 6112)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5892)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 5176)
      • dpinst.exe (PID: 6388)
      • csaudioendpointswitcher.exe (PID: 5360)
      • ShellExperienceHost.exe (PID: 6272)
    • Creates files in the program directory

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
    • The sample compiled with arabic language support

      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
    • The sample compiled with english language support

      • drvinst.exe (PID: 2236)
      • csaudiointcsof.1.0.4-installer.exe (PID: 2136)
      • dpinst.exe (PID: 6516)
      • dpinst.exe (PID: 6112)
      • dpinst.exe (PID: 6272)
      • drvinst.exe (PID: 6988)
      • drvinst.exe (PID: 1056)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 6244)
      • dpinst.exe (PID: 7084)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 6112)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 1672)
      • drvinst.exe (PID: 5892)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 6592)
      • drvinst.exe (PID: 4620)
      • dpinst.exe (PID: 6388)
      • drvinst.exe (PID: 5176)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 2236)
      • dpinst.exe (PID: 6516)
      • drvinst.exe (PID: 6988)
      • drvinst.exe (PID: 1056)
      • dpinst.exe (PID: 6272)
      • dpinst.exe (PID: 6112)
      • drvinst.exe (PID: 6300)
      • dpinst.exe (PID: 5892)
      • drvinst.exe (PID: 6244)
      • drvinst.exe (PID: 6516)
      • dpinst.exe (PID: 7084)
      • dpinst.exe (PID: 5008)
      • drvinst.exe (PID: 6112)
      • drvinst.exe (PID: 6272)
      • dpinst.exe (PID: 1164)
      • drvinst.exe (PID: 5892)
      • dpinst.exe (PID: 1672)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 5964)
      • dpinst.exe (PID: 2420)
      • drvinst.exe (PID: 4620)
      • drvinst.exe (PID: 5176)
      • dpinst.exe (PID: 6592)
      • dpinst.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
105
Malicious processes
16
Suspicious processes
12

Behavior graph

Click at the process to see the details
start start svchost.exe no specs svchost.exe no specs svchost.exe svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs spoolsv.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs dashost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs officeclicktorun.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs uhssvc.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs ctfmon.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe svchost.exe no specs audiodg.exe no specs svchost.exe no specs svchost.exe svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs upfc.exe no specs sppsvc.exe no specs csaudiointcsof.1.0.4-installer.exe no specs consent.exe no specs csaudiointcsof.1.0.4-installer.exe sppextcomobj.exe no specs slui.exe no specs waasmedicagent.exe no specs conhost.exe no specs dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe net.exe no specs conhost.exe no specs net1.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs csaudioendpointswitcher.exe no specs sihclient.exe shellexperiencehost.exe no specs compattelrunner.exe no specs conhost.exe no specs COpenControlPanel no specs

Process information

PID
CMD
Path
Indicators
Parent process
648"C:\Program Files\Microsoft Update Health Tools\uhssvc.exe"C:\Program Files\Microsoft Update Health Tools\uhssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Update Health Service
Version:
10.0.19041.3626 (WinBuild.160101.0800)
Modules
Images
c:\program files\microsoft update health tools\uhssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
860C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s RmSvcC:\Windows\System32\svchost.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
900C:\WINDOWS\System32\Upfc.exe /launchtype periodic /cv K2N1Da3EsU2/PXiC3HzEnw.0C:\Windows\System32\upfc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Updateability From SCM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netprofm.dll
c:\windows\system32\npmproxy.dll
956"ctfmon.exe"C:\Windows\System32\ctfmon.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CTF Loader
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1056DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{b2cc134a-ce3d-2e4e-8626-7b84a2f9cbcd}\da7219.inf" "9" "4f4128e67" "00000000000001E4" "WinSta0\Default" "00000000000001E0" "208" "c:\program files\csaudiointcsof\drivers\da7219"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCompatTelRunner.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1132C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryWC:\Windows\System32\CompatTelRunner.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Compatibility Telemetry
Exit code:
0
Version:
10.0.19645.1102 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\compattelrunner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Program Files\csaudiointcsof\drivers\dpinst.exe" /sw /f /path "C:\Program Files\csaudiointcsof\drivers\nau8825"C:\Program Files\csaudiointcsof\drivers\dpinst.exe
csaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\csaudiointcsof\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1228\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWaaSMedicAgent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
153 388
Read events
152 269
Write events
1 008
Delete events
111

Modification events

(PID) Process:(2104) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\WaaS\WaaSMedic\TaskStore
Operation:writeName:Schedule Work
Value:
Microsoft\Windows\UpdateOrchestrator
(PID) Process:(2104) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\WaaS\WaaSMedic\TaskStore
Operation:writeName:Schedule Wake To Work
Value:
Microsoft\Windows\UpdateOrchestrator
(PID) Process:(2104) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\WaaS\WaaSMedic\TaskStore
Operation:writeName:Schedule Maintenance Work
Value:
Microsoft\Windows\UpdateOrchestrator
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDevicePnp
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDevicePnp\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDeviceContainer
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDeviceContainer\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDriverBinary
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDriverBinary\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(2996) svchost.exeKey:\REGISTRY\A\{e5c6be81-08d8-c148-00cc-3336d59ebd30}\Root\InventoryDeviceMediaClass
Operation:writeName:WritePermissionsCheck
Value:
1
Executable files
72
Suspicious files
290
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2104svchost.exeC:\Windows\Logs\waasmediccapsule\WaasRemediation.004.etletl
MD5:A83C439448C1E67E6FFC948FEF1FCE18
SHA256:9FAA75F166CFDD869D3549B76139DDDDDB6A50790A5C6CC81B2084A432D7D60F
6668sppsvc.exeC:\Windows\System32\spp\store\2.0\data.dat.bakbinary
MD5:E5DAAABF11F4FF9B66226AA2F77C73DC
SHA256:6EC0ED4300D69A4EF9E36D46BD50AF85CE816F2BF3608D38F4EE7DF41556669F
6668sppsvc.exeC:\Windows\System32\spp\store\2.0\data.datbinary
MD5:E5DAAABF11F4FF9B66226AA2F77C73DC
SHA256:6EC0ED4300D69A4EF9E36D46BD50AF85CE816F2BF3608D38F4EE7DF41556669F
6668sppsvc.exeC:\Windows\System32\spp\store\2.0\data.dat.tmpbinary
MD5:E5DAAABF11F4FF9B66226AA2F77C73DC
SHA256:6EC0ED4300D69A4EF9E36D46BD50AF85CE816F2BF3608D38F4EE7DF41556669F
2104svchost.exeC:\Windows\Logs\waasmediccapsule\WaasRemediation.003.etlbinary
MD5:DEDECFD6DDECAA969F2F735761A8363F
SHA256:6D554FD45C5A4651BA508028AF27C5AE6501E3A2E10CFF9A8A925DCB74A68702
2136csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\cs42l42\cs42l42.catbinary
MD5:0BFAF62B95BEEC809DF72227BB91AC27
SHA256:1812033B3C8862D4875AAC0A8B452B6B0A2A3441C71FC2A42640DDB530A54457
2104svchost.exeC:\Windows\Logs\waasmediccapsule\WaasRemediation.002.etletl
MD5:D5C3C6FF92AB9DC318CD2CEA16B05D13
SHA256:AD2AC123C272119801B396032898A17A9C6E0ADF6DE2DE218794E31723136DD2
6544svchost.exeC:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:57DD3B3B7A163EBF2B2DAB214DF5E3AA
SHA256:EA0A603597F58A94D6984D4FAAE8A6E8D4E860FE885624CC11EF85D73D85F1FC
2136csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\dpinst.exeexecutable
MD5:4192A5B905374E423EC1E545599AA86E
SHA256:567F40A09F1D9E72396296AD194FA7CF48B72361D6E259D6B99DA774C2CD8981
2136csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\csaudiointcsof\csaudiointcsof.inftext
MD5:66A6E4D4D6621923A3FB4544AB7F07B9
SHA256:76F111F65CCE4C23A5345C15487242AB171004BA745CC28D5D500EE3D6E63762
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
36
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.43:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6872
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6872
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4156
SystemSettings.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4156
SystemSettings.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.43:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6872
SIHClient.exe
52.149.20.212:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.216.77.43
  • 23.216.77.5
  • 23.216.77.36
  • 23.216.77.39
  • 23.216.77.6
  • 23.216.77.13
  • 23.216.77.10
  • 23.216.77.12
  • 23.216.77.7
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.65
  • 20.190.160.20
  • 40.126.32.140
  • 20.190.160.14
  • 20.190.160.128
  • 40.126.32.134
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted

Threats

No threats detected
No debug info