File name:

oCam_v520.0.exe

Full analysis: https://app.any.run/tasks/f74e011d-4597-4830-9498-a3b0948709c6
Verdict: Malicious activity
Analysis date: December 04, 2023, 06:04:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

715BAE1E55676C43B0179D7547AFD96F

SHA1:

2630E1ABA6F8AD9BC21BF4BC0E95C4DC13A9E8E0

SHA256:

729A910181A35D4028CFC2ED8A45C319DC3D1F699537E7710C500331724A582E

SSDEEP:

196608:jiRgPU09IDApbsrKXGtVvoZBDbn1ipny1IOojKbqM277/41V:jiRd0TOYYvk/1ipyuOoWbALQV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • oCam_v520.0.exe (PID: 1556)
      • oCam_v520.0.exe (PID: 1236)
      • oCam_v520.0.tmp (PID: 2920)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • oCam_v520.0.tmp (PID: 2920)
    • Reads the Internet Settings

      • oCam.exe (PID: 4060)
      • oCamTask.exe (PID: 1936)
      • oCam_v520.0.tmp (PID: 2920)
    • Reads Microsoft Outlook installation path

      • oCam.exe (PID: 4060)
    • Searches for installed software

      • oCamTask.exe (PID: 1936)
    • Reads settings of System Certificates

      • oCam.exe (PID: 4060)
    • Adds/modifies Windows certificates

      • oCam.exe (PID: 4060)
    • Checks Windows Trust Settings

      • oCam.exe (PID: 4060)
    • Reads security settings of Internet Explorer

      • oCam.exe (PID: 4060)
    • Reads Internet Explorer settings

      • oCam.exe (PID: 4060)
  • INFO

    • Checks supported languages

      • oCam_v520.0.exe (PID: 1236)
      • oCam_v520.0.tmp (PID: 2740)
      • oCam_v520.0.tmp (PID: 2920)
      • oCam_v520.0.exe (PID: 1556)
      • oCamTask.exe (PID: 2620)
      • oCam.exe (PID: 4060)
      • wmpnscfg.exe (PID: 3860)
      • oCam.exe (PID: 292)
      • oCam.exe (PID: 2088)
      • oCam.exe (PID: 552)
      • oCam.exe (PID: 860)
      • oCamTask.exe (PID: 1936)
    • Create files in a temporary directory

      • oCam_v520.0.exe (PID: 1236)
      • oCam_v520.0.exe (PID: 1556)
      • oCam_v520.0.tmp (PID: 2920)
      • oCam.exe (PID: 4060)
    • Application launched itself

      • msedge.exe (PID: 2908)
      • msedge.exe (PID: 3996)
    • Reads the computer name

      • oCam_v520.0.tmp (PID: 2740)
      • oCam_v520.0.tmp (PID: 2920)
      • oCamTask.exe (PID: 1936)
      • oCam.exe (PID: 4060)
      • wmpnscfg.exe (PID: 3860)
      • oCam.exe (PID: 292)
      • oCam.exe (PID: 2088)
      • oCam.exe (PID: 552)
      • oCam.exe (PID: 860)
      • oCamTask.exe (PID: 2620)
    • Creates files in the program directory

      • oCam_v520.0.tmp (PID: 2920)
    • Manual execution by a user

      • msedge.exe (PID: 3996)
      • wmpnscfg.exe (PID: 3860)
      • oCam.exe (PID: 292)
      • oCam.exe (PID: 552)
    • Checks proxy server information

      • oCam.exe (PID: 4060)
    • Reads the machine GUID from the registry

      • oCam.exe (PID: 4060)
    • Creates files or folders in the user directory

      • oCam.exe (PID: 4060)
      • oCam_v520.0.tmp (PID: 2920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (62.6)
.exe | Win32 Executable Delphi generic (21.3)
.exe | Win32 Executable (generic) (6.7)
.exe | Win16/32 Executable Delphi generic (3.1)
.exe | Generic Win/DOS Executable (3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:03:20 07:00:21+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 93696
InitializedDataSize: 148992
UninitializedDataSize: -
EntryPoint: 0x177f4
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 520.0.0.0
ProductVersionNumber: 520.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: http://ohsoft.net/
FileDescription: oCam Setup
FileVersion: 520.0
LegalCopyright:
ProductName: oCam
ProductVersion: 520.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
25
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ocam_v520.0.exe no specs ocam_v520.0.tmp no specs ocam_v520.0.exe ocam_v520.0.tmp no specs ocamtask.exe msedge.exe no specs msedge.exe no specs ocamtask.exe no specs ocam.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs ocam.exe no specs ocam.exe no specs ocam.exe no specs ocam.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\oCam\oCam.exe" C:\Program Files\oCam\oCam.exeexplorer.exe
User:
admin
Company:
oh!soft
Integrity Level:
MEDIUM
Description:
oCam
Exit code:
0
Version:
520.0.0.0
Modules
Images
c:\program files\ocam\ocam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
552"C:\Program Files\oCam\oCam.exe" C:\Program Files\oCam\oCam.exeexplorer.exe
User:
admin
Company:
oh!soft
Integrity Level:
MEDIUM
Description:
oCam
Exit code:
0
Version:
520.0.0.0
Modules
Images
c:\program files\ocam\ocam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
860"C:\Program Files\oCam\oCam.exe" /RunC:\Program Files\oCam\oCam.exeoCamTask.exe
User:
admin
Company:
oh!soft
Integrity Level:
HIGH
Description:
oCam
Exit code:
0
Version:
520.0.0.0
Modules
Images
c:\program files\ocam\ocam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1036"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Users\admin\AppData\Local\Temp\oCam_v520.0.exe" C:\Users\admin\AppData\Local\Temp\oCam_v520.0.exeexplorer.exe
User:
admin
Company:
http://ohsoft.net/
Integrity Level:
MEDIUM
Description:
oCam Setup
Exit code:
0
Version:
520.0
Modules
Images
c:\users\admin\appdata\local\temp\ocam_v520.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1556"C:\Users\admin\AppData\Local\Temp\oCam_v520.0.exe" /SPAWNWND=$1B0158 /NOTIFYWND=$25013A C:\Users\admin\AppData\Local\Temp\oCam_v520.0.exe
oCam_v520.0.tmp
User:
admin
Company:
http://ohsoft.net/
Integrity Level:
HIGH
Description:
oCam Setup
Exit code:
0
Version:
520.0
Modules
Images
c:\users\admin\appdata\local\temp\ocam_v520.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1936"C:\Program Files\oCam\oCamTask.exe" /Run /RegisterC:\Program Files\oCam\oCamTask.exeoCam_v520.0.tmp
User:
admin
Company:
oh!soft
Integrity Level:
HIGH
Description:
oCam Background Task
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\program files\ocam\ocamtask.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1416 --field-trial-handle=1320,i,8000587338440079146,7591910313906784195,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files\oCam\oCam.exe" /RunC:\Program Files\oCam\oCam.exeoCamTask.exe
User:
admin
Company:
oh!soft
Integrity Level:
HIGH
Description:
oCam
Exit code:
0
Version:
520.0.0.0
Modules
Images
c:\program files\ocam\ocam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2100"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1244 --field-trial-handle=1320,i,8000587338440079146,7591910313906784195,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
12 650
Read events
12 538
Write events
112
Delete events
0

Modification events

(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(2908) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
(PID) Process:(2920) oCam_v520.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2920) oCam_v520.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2920) oCam_v520.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2920) oCam_v520.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
65
Suspicious files
90
Text files
166
Unknown types
1

Dropped files

PID
Process
Filename
Type
1236oCam_v520.0.exeC:\Users\admin\AppData\Local\Temp\is-947HH.tmp\oCam_v520.0.tmpexecutable
MD5:4C31EAEEE92830C35CB7C8A7DCBB14FA
SHA256:EFB7877BE8B110B5AF74B99DBF4F580D6ECE6F83EEF196120DFF3A0220D96C72
2920oCam_v520.0.tmpC:\Users\admin\AppData\Local\Temp\is-0ISKT.tmp\oCamTask.exeexecutable
MD5:A382DE08090E08EEE61A7CE0EF1BDDAA
SHA256:F0048CE03238E4C06FFC03F5D72142DC5C69A41136E4021972B3C015023672F0
1556oCam_v520.0.exeC:\Users\admin\AppData\Local\Temp\is-SGV51.tmp\oCam_v520.0.tmpexecutable
MD5:4C31EAEEE92830C35CB7C8A7DCBB14FA
SHA256:EFB7877BE8B110B5AF74B99DBF4F580D6ECE6F83EEF196120DFF3A0220D96C72
2920oCam_v520.0.tmpC:\Program Files\oCam\is-2JJGE.tmpexecutable
MD5:128940CE93D705E391F5A489CA81E2BA
SHA256:072B8F74430A15540984A20DD93EBE1A9AE6AAAE63C600E9CD58ED004AD8C3C6
2920oCam_v520.0.tmpC:\Program Files\oCam\v520.0x86\is-97JLG.tmpexecutable
MD5:F949DB9EA1889CEA109A2EACC932FF9E
SHA256:BD433C81E4488B3207D30D512863F856153DA429F3AC73291D95D6397A4D6C9B
2920oCam_v520.0.tmpC:\Program Files\oCam\oCam.exeexecutable
MD5:B072C6E7EC342D8996FE75FB3D5A5CB5
SHA256:635CDA4BE440EE15F1A19A4D948DE8E65209C187E829B1C7EE21BE08D3A44702
2920oCam_v520.0.tmpC:\Program Files\oCam\v520.0x86\is-R7F1A.tmpexecutable
MD5:B4948874913AA4A2642634A30D29078A
SHA256:AE21BE6C87002E8CC87CA6E288D2AF62344813EB52241A9318469FE1DEC64AD0
2920oCam_v520.0.tmpC:\Program Files\oCam\is-3KJ54.tmpexecutable
MD5:A382DE08090E08EEE61A7CE0EF1BDDAA
SHA256:F0048CE03238E4C06FFC03F5D72142DC5C69A41136E4021972B3C015023672F0
2920oCam_v520.0.tmpC:\Program Files\oCam\v520.0x86\DXGICapture.dllexecutable
MD5:B4948874913AA4A2642634A30D29078A
SHA256:AE21BE6C87002E8CC87CA6E288D2AF62344813EB52241A9318469FE1DEC64AD0
2920oCam_v520.0.tmpC:\Program Files\oCam\unins000.exeexecutable
MD5:128940CE93D705E391F5A489CA81E2BA
SHA256:072B8F74430A15540984A20DD93EBE1A9AE6AAAE63C600E9CD58ED004AD8C3C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
52
DNS requests
36
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4060
oCam.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e5128d334fb452c4
unknown
compressed
4.66 Kb
unknown
4060
oCam.exe
GET
200
23.201.254.55:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
4060
oCam.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
4060
oCam.exe
GET
200
2.16.241.8:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOXnK1dKSi1164MUb6doyJVoA%3D%3D
unknown
binary
503 b
unknown
4060
oCam.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
4060
oCam.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEDBPk217SOCuEsxRjJqpuUQ%3D
unknown
binary
471 b
unknown
4060
oCam.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
4060
oCam.exe
GET
200
192.229.221.95:80
http://status.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAJqxLP5DgW758bGnZR3iu4%3D
unknown
binary
471 b
unknown
4060
oCam.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEASnmSgRJpLxdoD57C0Dljs%3D
unknown
binary
471 b
unknown
4060
oCam.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAeMiOauFmgffpRqrXLB9lo%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
3996
msedge.exe
239.255.255.250:1900
whitelisted
2064
msedge.exe
52.123.243.221:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2064
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
2064
msedge.exe
45.56.90.99:80
ohsoft.net
Linode, LLC
US
unknown
2064
msedge.exe
45.56.90.99:443
ohsoft.net
Linode, LLC
US
unknown
868
svchost.exe
184.30.20.134:80
armmf.adobe.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 52.123.243.221
  • 52.123.224.70
  • 52.123.243.207
whitelisted
ohsoft.net
  • 45.56.90.99
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
armmf.adobe.com
  • 184.30.20.134
whitelisted
pagead2.googlesyndication.com
  • 142.250.186.162
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 23.201.254.55
whitelisted
r3.o.lencr.org
  • 2.16.241.8
  • 2.16.241.15
shared
maxcdn.bootstrapcdn.com
  • 104.18.11.207
  • 104.18.10.207
whitelisted
securepubads.g.doubleclick.net
  • 142.250.186.66
whitelisted

Threats

PID
Process
Class
Message
4060
oCam.exe
A Network Trojan was detected
ET MALWARE Generic Dropper Installing PUP 1
4060
oCam.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
Process
Message
oCamTask.exe
C:\Windows\System32\wininit.exe
oCamTask.exe
C:\Windows\System32\svchost.exe
oCamTask.exe
C:\Windows\System32\svchost.exe
oCamTask.exe
C:\Windows\System32\lsass.exe
oCamTask.exe
C:\Windows\System32\SearchProtocolHost.exe
oCamTask.exe
C:\Windows\System32\smss.exe
oCamTask.exe
C:\Windows\System32\spoolsv.exe
oCamTask.exe
C:\Windows\System32\lsm.exe
oCamTask.exe
C:\Windows\System32\svchost.exe
oCamTask.exe
C:\Windows\System32\ctfmon.exe