URL:

https://downloads.canon.com/webcam/EOSWebcamUtilityPro-WIN2.3a.zip

Full analysis: https://app.any.run/tasks/8ed7f0cf-223f-4ed6-979b-8b715415ec94
Verdict: Malicious activity
Analysis date: February 03, 2025, 19:17:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
advancedinstaller
arch-html
Indicators:
MD5:

B1A47D975C9D78972AF816530EF5E6CC

SHA1:

C521D3AE339C0EDC876A0F6A540BADBE3B7A9B24

SHA256:

723BAF47D28BA52ED805CEF2588BAEB04AB8E60D62F3E03A08DC69BA661BB456

SSDEEP:

3:N8SE4LUIJAmE3gNyENRMdjXrU:2SNJlRk7lU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Setup.exe (PID: 1752)
      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x86.exe (PID: 6068)
    • Changes powershell execution policy (Unrestricted)

      • EOS Webcam Utility Pro.exe (PID: 536)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7144)
      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 4320)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 5544)
      • Setup.exe (PID: 4804)
      • MSI909F.tmp (PID: 6340)
    • ADVANCEDINSTALLER mutex has been found

      • Setup.exe (PID: 1752)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 4968)
      • Setup.exe (PID: 4804)
      • drvinst.exe (PID: 6408)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 1752)
      • vc_redist.x64.exe (PID: 7040)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 4320)
      • vc_redist.x86.exe (PID: 4648)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 4020)
      • VC_redist.x86.exe (PID: 5544)
      • Setup.exe (PID: 4804)
      • drvinst.exe (PID: 6408)
    • Reads the Windows owner or organization settings

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 4968)
      • Setup.exe (PID: 4804)
    • There is functionality for taking screenshot (YARA)

      • Setup.exe (PID: 1752)
    • Process drops legitimate windows executable

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • vc_redist.x64.exe (PID: 7040)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 1296)
      • msiexec.exe (PID: 4968)
      • vc_redist.x86.exe (PID: 4648)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 4020)
      • Setup.exe (PID: 4804)
      • msiexec.exe (PID: 4544)
      • msiexec.exe (PID: 5872)
    • Starts a Microsoft application from unusual location

      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 1296)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
    • Searches for installed software

      • vc_redist.x64.exe (PID: 6268)
      • dllhost.exe (PID: 5392)
      • VC_redist.x64.exe (PID: 4320)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 5544)
      • VC_redist.x86.exe (PID: 4020)
    • Starts itself from another location

      • vc_redist.x64.exe (PID: 6268)
      • vc_redist.x86.exe (PID: 4076)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3848)
      • WUDFHost.exe (PID: 732)
      • WUDFHost.exe (PID: 3816)
      • EWCService.exe (PID: 6236)
      • EWCPairingService.exe (PID: 848)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 4544)
    • The process checks if it is being run in the virtual environment

      • msiexec.exe (PID: 4968)
    • Application launched itself

      • VC_redist.x64.exe (PID: 1192)
      • VC_redist.x64.exe (PID: 4320)
      • VC_redist.x86.exe (PID: 5780)
      • VC_redist.x86.exe (PID: 5544)
      • Setup.exe (PID: 1752)
      • EOS Webcam Utility Pro.exe (PID: 536)
    • Creates a software uninstall entry

      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x86.exe (PID: 6068)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6408)
      • msiexec.exe (PID: 5872)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 3896)
      • drvinst.exe (PID: 5780)
    • Creates/Modifies COM task schedule object

      • drvinst.exe (PID: 3896)
      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 6248)
    • Executing commands from a ".bat" file

      • MSI909F.tmp (PID: 6340)
    • Starts CMD.EXE for commands execution

      • MSI909F.tmp (PID: 6340)
      • EOS Webcam Utility Pro.exe (PID: 536)
    • Starts application with an unusual extension

      • cmd.exe (PID: 5032)
    • The process bypasses the loading of PowerShell profile settings

      • EOS Webcam Utility Pro.exe (PID: 536)
    • The process hides Powershell's copyright startup banner

      • EOS Webcam Utility Pro.exe (PID: 536)
    • Starts POWERSHELL.EXE for commands execution

      • EOS Webcam Utility Pro.exe (PID: 536)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 7144)
      • EOS Webcam Utility Pro.exe (PID: 536)
    • Checks supported languages

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 6876)
      • vc_redist.x64.exe (PID: 7040)
      • msiexec.exe (PID: 5876)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 1192)
      • VC_redist.x64.exe (PID: 4320)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4648)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 5780)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 5544)
      • VC_redist.x86.exe (PID: 4020)
      • Setup.exe (PID: 4804)
      • msiexec.exe (PID: 4076)
      • msiexec.exe (PID: 5872)
      • drvinst.exe (PID: 6408)
      • drvinst.exe (PID: 5780)
      • drvinst.exe (PID: 3896)
      • EWCService.exe (PID: 6236)
      • EWCPairingService.exe (PID: 848)
      • MSI909F.tmp (PID: 6340)
      • EWCUPNPSV.exe (PID: 3536)
      • msiexec.exe (PID: 2828)
      • EOS Webcam Utility Pro.exe (PID: 536)
      • chcp.com (PID: 6956)
      • EOS Webcam Utility Pro.exe (PID: 4076)
      • EOS Webcam Utility Pro.exe (PID: 1556)
      • EOS Webcam Utility Pro.exe (PID: 1684)
      • EWCProxy.exe (PID: 7456)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7144)
      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • chrome.exe (PID: 6844)
      • msiexec.exe (PID: 1192)
      • vc_redist.x64.exe (PID: 6268)
      • vc_redist.x64.exe (PID: 7040)
      • VC_redist.x64.exe (PID: 1296)
      • msiexec.exe (PID: 4968)
      • VC_redist.x64.exe (PID: 4320)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4648)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 4020)
      • VC_redist.x86.exe (PID: 5544)
      • Setup.exe (PID: 4804)
      • drvinst.exe (PID: 6408)
      • msiexec.exe (PID: 4544)
    • Reads the computer name

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 5876)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 4320)
      • VC_redist.x64.exe (PID: 536)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 4020)
      • VC_redist.x86.exe (PID: 5544)
      • msiexec.exe (PID: 4544)
      • Setup.exe (PID: 4804)
      • msiexec.exe (PID: 5872)
      • drvinst.exe (PID: 6408)
      • msiexec.exe (PID: 4076)
      • drvinst.exe (PID: 3896)
      • drvinst.exe (PID: 5780)
      • MSI909F.tmp (PID: 6340)
      • EWCPairingService.exe (PID: 848)
      • EWCUPNPSV.exe (PID: 3536)
      • msiexec.exe (PID: 2828)
      • EWCService.exe (PID: 6236)
      • EOS Webcam Utility Pro.exe (PID: 536)
      • EOS Webcam Utility Pro.exe (PID: 4076)
      • EWCProxy.exe (PID: 7456)
      • EOS Webcam Utility Pro.exe (PID: 1556)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7144)
      • chrome.exe (PID: 6844)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 1192)
      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 4544)
      • msiexec.exe (PID: 5872)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • VC_redist.x64.exe (PID: 1296)
      • msiexec.exe (PID: 4968)
      • VC_redist.x86.exe (PID: 6068)
      • Setup.exe (PID: 4804)
      • drvinst.exe (PID: 6408)
      • EOS Webcam Utility Pro.exe (PID: 1556)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 4968)
      • EWCService.exe (PID: 6236)
      • EOS Webcam Utility Pro.exe (PID: 536)
      • EOS Webcam Utility Pro.exe (PID: 1556)
    • Checks proxy server information

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • EOS Webcam Utility Pro.exe (PID: 536)
    • Reads the software policy settings

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 1192)
      • msiexec.exe (PID: 4968)
      • Setup.exe (PID: 4804)
      • drvinst.exe (PID: 6408)
      • rundll32.exe (PID: 3724)
      • EOS Webcam Utility Pro.exe (PID: 1556)
    • Reads Environment values

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 6876)
      • msiexec.exe (PID: 5876)
      • Setup.exe (PID: 4804)
      • msiexec.exe (PID: 4544)
    • Application launched itself

      • chrome.exe (PID: 2800)
      • msiexec.exe (PID: 4968)
    • Create files in a temporary directory

      • Setup.exe (PID: 1752)
      • vc_redist.x64.exe (PID: 7040)
      • vc_redist.x64.exe (PID: 6268)
      • msiexec.exe (PID: 1192)
      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 4320)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 6068)
      • VC_redist.x86.exe (PID: 5544)
      • Setup.exe (PID: 4804)
      • msiexec.exe (PID: 4544)
      • EOS Webcam Utility Pro.exe (PID: 536)
    • The sample compiled with chinese language support

      • Setup.exe (PID: 1752)
      • msiexec.exe (PID: 4968)
      • msiexec.exe (PID: 5872)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 7144)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 1192)
    • Process checks computer location settings

      • Setup.exe (PID: 1752)
      • vc_redist.x64.exe (PID: 6268)
      • VC_redist.x64.exe (PID: 4320)
      • vc_redist.x86.exe (PID: 4076)
      • VC_redist.x86.exe (PID: 5544)
      • MSI909F.tmp (PID: 6340)
      • EOS Webcam Utility Pro.exe (PID: 536)
      • EOS Webcam Utility Pro.exe (PID: 1684)
    • Creates files in the program directory

      • VC_redist.x64.exe (PID: 1296)
      • VC_redist.x86.exe (PID: 6068)
    • Manages system restore points

      • SrTasks.exe (PID: 7092)
      • SrTasks.exe (PID: 5696)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 4968)
    • The sample compiled with japanese language support

      • msiexec.exe (PID: 4968)
      • drvinst.exe (PID: 6408)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 6408)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 4968)
    • Changes the display of characters in the console

      • cmd.exe (PID: 5032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
226
Monitored processes
81
Malicious processes
16
Suspicious processes
3

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs rundll32.exe no specs winrar.exe setup.exe msiexec.exe msiexec.exe chrome.exe msiexec.exe chrome.exe no specs vc_redist.x64.exe msiexec.exe no specs vc_redist.x64.exe vc_redist.x64.exe SPPSurrogate no specs vssvc.exe no specs chrome.exe no specs chrome.exe no specs srtasks.exe no specs conhost.exe no specs vc_redist.x64.exe no specs vc_redist.x64.exe vc_redist.x64.exe vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe SPPSurrogate no specs vc_redist.x86.exe no specs vc_redist.x86.exe vc_redist.x86.exe chrome.exe no specs setup.exe srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe no specs chrome.exe no specs msiexec.exe drvinst.exe rundll32.exe no specs drvinst.exe no specs wudfhost.exe no specs drvinst.exe no specs wudfhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs ewcservice.exe no specs ewcpairingservice.exe no specs msi909f.tmp no specs cmd.exe no specs conhost.exe no specs ewcupnpsv.exe no specs conhost.exe no specs chrome.exe no specs eos webcam utility pro.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs powershell.exe no specs eos webcam utility pro.exe no specs conhost.exe no specs eos webcam utility pro.exe eos webcam utility pro.exe no specs comppkgsrv.exe no specs powershell.exe no specs conhost.exe no specs ewcproxy.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
68"C:\WINDOWS\System32\cmd.exe" /C ""C:\Program Files\Canon\EOS Webcam Utility Pro\register_filters.bat" "C:\Windows\SysWOW64\cmd.exeMSI909F.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
536"C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{30D237B4-8AA2-4AA5-8156-A362F613603D} {DE338474-3639-47A5-AD4E-EC243A9310FB} 4320C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe
VC_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\programdata\package cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
536"C:\Program Files\Canon\EOS Webcam Utility Pro\EOS Webcam Utility UI\EOS Webcam Utility Pro.exe" C:\Program Files\Canon\EOS Webcam Utility Pro\EOS Webcam Utility UI\EOS Webcam Utility Pro.exeexplorer.exe
User:
admin
Company:
Canon U.S.A., Inc.
Integrity Level:
MEDIUM
Description:
EOS Webcam Utility Pro
Version:
2.3.17.20241114.5
Modules
Images
c:\program files\canon\eos webcam utility pro\eos webcam utility ui\eos webcam utility pro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
732"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-905236e6-3206-4b1c-8177-d94ca1ab70a0 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-0b0e76e5-448d-4c7d-8925-ef6784c79329 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-55f5f7c8-f8e1-4161-9df2-71725545b418 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-26ce2c83-ad14-4a51-bc50-ca4d01111d50 -LifetimeId:663a13aa-12d8-4546-9ccf-4481511ef5ab -DeviceGroupId:WudfDefaultDevicePool -HostArg:0C:\Windows\System32\WUDFHost.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Driver Foundation - User-mode Driver Framework Host Process
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wudfhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\devobj.dll
848"C:\Program Files\Canon\EOS Webcam Utility Pro\EWCPairingService.exe"C:\Program Files\Canon\EOS Webcam Utility Pro\EWCPairingService.exeservices.exe
User:
SYSTEM
Company:
Canon U.S.A., Inc.
Integrity Level:
SYSTEM
Description:
EWCPairingService
Version:
2.3.17.0
Modules
Images
c:\program files\canon\eos webcam utility pro\ewcpairingservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1144\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1192"C:\WINDOWS\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa7144.18139\EOS Webcam Utility.msi" C:\Windows\System32\msiexec.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1603
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1192"C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={804e7d66-ccc2-4c12-84ba-476da31d103d} -burn.filehandle.self=928 -burn.embedded BurnPipe.{23371D0E-DEE5-4110-8DAF-65D4AF6D7DD4} {05B350A0-A724-44EE-835F-86E378907A09} 1296C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exeVC_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\programdata\package cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1296"C:\Users\admin\AppData\Local\Temp\{A56EE0F4-E7B6-4445-A6FF-753045CFF577}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{9D1B69B8-FA89-4945-AD9F-BB316F4D4205} {57B55C8E-F001-40F8-BBB2-EE66D13386C7} 6268C:\Users\admin\AppData\Local\Temp\{A56EE0F4-E7B6-4445-A6FF-753045CFF577}\.be\VC_redist.x64.exe
vc_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34433
Exit code:
3010
Version:
14.42.34433.0
Modules
Images
c:\users\admin\appdata\local\temp\{a56ee0f4-e7b6-4445-a6ff-753045cff577}\.be\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1296\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
73 299
Read events
71 026
Write events
1 554
Delete events
719

Modification events

(PID) Process:(2800) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2800) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2800) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2800) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2800) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(3724) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000904FC86E7076DB01
(PID) Process:(7144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\EOSWebcamUtilityPro-WIN2.3a.zip
Executable files
235
Suspicious files
706
Text files
225
Unknown types
3

Dropped files

PID
Process
Filename
Type
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF136332.TMP
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF136332.TMP
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF136332.TMP
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF136341.TMP
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF136332.TMP
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
2800chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
69
DNS requests
44
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3508
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6252
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
6984
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3508
svchost.exe
2.16.164.99:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3508
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6032
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.21.65.154:443
www.bing.com
Akamai International B.V.
NL
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6536
chrome.exe
108.177.127.84:443
accounts.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.99
  • 2.16.164.40
  • 2.16.164.34
  • 2.16.164.81
  • 2.16.164.42
  • 2.16.164.17
  • 2.16.164.96
  • 2.16.164.98
  • 2.16.164.18
  • 95.101.78.32
  • 95.101.78.42
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
  • 69.192.161.161
whitelisted
www.bing.com
  • 2.21.65.154
  • 2.21.65.132
whitelisted
go.microsoft.com
  • 23.35.238.131
  • 184.28.89.167
whitelisted
downloads.canon.com
  • 23.207.210.143
  • 23.207.210.145
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.130
  • 20.190.159.64
  • 20.190.159.68
  • 40.126.31.129
  • 20.190.159.131
  • 40.126.31.3
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
www.google.com
  • 142.250.185.228
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted

Threats

No threats detected
No debug info