URL:

https://www.highrez.co.uk/downloads/xmousebuttoncontrol.htm

Full analysis: https://app.any.run/tasks/f60fe3d5-40aa-43a2-9ae5-c3f6ceeb80b8
Verdict: Malicious activity
Analysis date: February 06, 2024, 18:42:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

74BF7ACEBA6DC124CB408B9CAEB853AA

SHA1:

03FE03704AE4F372A7702E046C173D05583A1189

SHA256:

76175D8FC16B64DFB11968EB0B4FE9075DB079CC6495D342ED49099A50AE4A16

SSDEEP:

3:N8DSLPK0KE4KKjk9KLRahIn:2OLZDKjkoLz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
    • The process creates files with name similar to system file names

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
    • Checks Windows Trust Settings

      • XMouseButtonControl.exe (PID: 3892)
    • Reads settings of System Certificates

      • XMouseButtonControl.exe (PID: 3892)
    • Reads security settings of Internet Explorer

      • XMouseButtonControl.exe (PID: 3892)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3060)
      • iexplore.exe (PID: 752)
    • Reads the computer name

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
      • XMouseButtonControl.exe (PID: 3892)
      • XMouseButtonControl.exe (PID: 3036)
    • Create files in a temporary directory

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 752)
      • iexplore.exe (PID: 3060)
    • Checks supported languages

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
      • XMouseButtonControl.exe (PID: 3892)
      • XMouseButtonControl.exe (PID: 3036)
    • Creates files in the program directory

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
    • Application launched itself

      • iexplore.exe (PID: 752)
      • msedge.exe (PID: 3008)
    • The process uses the downloaded file

      • iexplore.exe (PID: 752)
    • Creates files or folders in the user directory

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
      • XMouseButtonControl.exe (PID: 3892)
      • XMouseButtonControl.exe (PID: 3036)
    • Manual execution by a user

      • msedge.exe (PID: 3008)
      • XMouseButtonControl.exe (PID: 3080)
      • XMouseButtonControl.exe (PID: 3892)
      • XMouseButtonControl.exe (PID: 2740)
      • XMouseButtonControl.exe (PID: 3036)
    • Reads the machine GUID from the registry

      • XMouseButtonControlSetup.2.20.5.exe (PID: 3368)
      • XMouseButtonControl.exe (PID: 3892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
20
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe xmousebuttoncontrolsetup.2.20.5.exe no specs xmousebuttoncontrolsetup.2.20.5.exe msedge.exe xmousebuttoncontrol.exe no specs msedge.exe no specs xmousebuttoncontrol.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs xmousebuttoncontrol.exe no specs xmousebuttoncontrol.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.highrez.co.uk/downloads/xmousebuttoncontrol.htm"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2188 --field-trial-handle=1360,i,7623971955743036815,7483781011027227546,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1544"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4052 --field-trial-handle=1360,i,7623971955743036815,7483781011027227546,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1676 --field-trial-handle=1360,i,7623971955743036815,7483781011027227546,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1816"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1496 --field-trial-handle=1360,i,7623971955743036815,7483781011027227546,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\XMouseButtonControlSetup.2.20.5.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\XMouseButtonControlSetup.2.20.5.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\xmousebuttoncontrolsetup.2.20.5.exe
c:\windows\system32\ntdll.dll
2472"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xdc,0x6973f598,0x6973f5a8,0x6973f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2640"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2648 --field-trial-handle=1360,i,7623971955743036815,7483781011027227546,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2736"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:752 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2740"C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe" /notportableC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exeexplorer.exe
User:
admin
Company:
Highresolution Enterprises
Integrity Level:
MEDIUM
Description:
X-Mouse Button Control
Exit code:
3221226540
Version:
2.20.5
Modules
Images
c:\program files\highresolution enterprises\x-mouse button control\xmousebuttoncontrol.exe
c:\windows\system32\ntdll.dll
Total events
31 207
Read events
31 069
Write events
126
Delete events
12

Modification events

(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
12
Suspicious files
65
Text files
82
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\default[1].csstext
MD5:D3929CB8A4CDEF051CCD8291211835B7
SHA256:8DAE993738A0AE3518841C5BBEE1F966D9E11CA7D8C9BE825FDBD3F3A87389F0
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\cryptodonate.green[1].csstext
MD5:8B38B84C84827216082E654045BD404C
SHA256:67034CB45A74B9E95EB3C3A763E763306FCACDC6DDC7B1D8C8CE9AD84F2196A2
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\magnific-popup[1].csstext
MD5:C03FE8704D90E35EBA342D2CA2C5A530
SHA256:1155981E8193622F58553EED0BBA2FA43512AF362A3D54DEDEF64C46970BB371
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:932F4C6CB432AC4C2E23F7780682A311
SHA256:CE4C7AD6820018CA7523AA697A8B9A68144C83068D58686F2A78A82A703AF801
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\cryptodonate.dark[1].csstext
MD5:AAB56377493BE85B314E5716479E44CE
SHA256:0DC550F2DFA10BFD971C09067E3936F70D2D3B0FA02CFF2D4D0A8FC445FD435C
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\widget[1].jstext
MD5:6BEFBA3F74EC3BFC642B45AFC353A357
SHA256:E36A84CF4975004EE7D33C84013BA3076778E4C9FBF97663D60955B1CF4476E8
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\janey[1].jpgimage
MD5:78C350402A342D8094A55D6E78E6ED3A
SHA256:2368B2C8C2EE785D188497C3FDEC6568C629EF96138986DF0485BCA83FBBA255
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\xmbcicon[1].pngimage
MD5:F0B4DE100C699658B62F64D3C255902E
SHA256:3DBCBC99AF010AF5E85D6F767A3360B216465D8ECD6E85E6003B49552046430E
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\cryptodonate.pink[1].csstext
MD5:6879958FAB019B2E3640C3E53F38C63E
SHA256:84E0AE45F923E4467FC1413CFFDE8AB4F1439E50B4B93A90EB552A4B6825E44F
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.magnific-popup.min[1].jstext
MD5:B37D7EDF99565D3858EAA1AD80DF3CFF
SHA256:B0A45CD5AED66E27BD8EE861D0E3B782C8E79849BDE32F90F078B9F2451A36F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
61
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2736
iexplore.exe
GET
304
23.48.23.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1e96081ee66de808
unknown
unknown
2736
iexplore.exe
GET
304
23.48.23.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?245ab6ffaf4de696
unknown
unknown
2736
iexplore.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2736
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D
unknown
binary
471 b
unknown
2736
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2736
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEC%2BnQCRf%2B140EujuiYvO6fs%3D
unknown
binary
471 b
unknown
2736
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
752
iexplore.exe
GET
304
23.48.23.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5565915fab5f2bac
unknown
unknown
752
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
752
iexplore.exe
GET
304
23.48.23.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9f1bf971760d5e57
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2736
iexplore.exe
188.74.78.172:443
www.highrez.co.uk
Giganet Limited
GB
unknown
2736
iexplore.exe
23.48.23.8:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2736
iexplore.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
2736
iexplore.exe
192.229.221.25:443
www.paypalobjects.com
EDGECAST
US
unknown
2736
iexplore.exe
142.250.181.226:443
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
2736
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2736
iexplore.exe
142.250.186.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
www.highrez.co.uk
  • 188.74.78.172
whitelisted
ctldl.windowsupdate.com
  • 23.48.23.8
  • 23.48.23.67
  • 23.48.23.21
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
www.paypalobjects.com
  • 192.229.221.25
whitelisted
pagead2.googlesyndication.com
  • 142.250.181.226
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ocsp.pki.goog
  • 142.250.186.99
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.184
  • 104.126.37.139
  • 104.126.37.185
  • 104.126.37.186
  • 104.126.37.179
  • 104.126.37.130
  • 104.126.37.178
  • 104.126.37.131
  • 104.126.37.137
  • 92.123.104.7
  • 92.123.104.11
  • 92.123.104.17
  • 92.123.104.6
  • 92.123.104.9
  • 92.123.104.8
  • 92.123.104.10
  • 92.123.104.18
  • 92.123.104.13
whitelisted
dvps.highrez.co.uk
  • 208.87.103.217
  • 149.255.97.140
unknown

Threats

No threats detected
Process
Message
XMouseButtonControlSetup.2.20.5.exe
ExecShellAsUser: DLL_PROCESS_ATTACH
XMouseButtonControlSetup.2.20.5.exe
ExecShellAsUser: got desktop
XMouseButtonControlSetup.2.20.5.exe
ExecShellAsUser: elevated process detected
XMouseButtonControl.exe
06-02-2024 18:42:58.769> CXButtonControllApp: Constructing Main Application Class
XMouseButtonControl.exe
06-02-2024 18:42:58.769> InitInstance: XMBC is starting
XMouseButtonControl.exe
06-02-2024 18:42:58.785> X-Mouse Button Control v2.20.5 (x86) Startup. Commandline '/installed /notportable'
XMouseButtonControl.exe
06-02-2024 18:42:58.801> Running in high integrity mode (as Administrator) (0x00003000)
XMouseButtonControl.exe
06-02-2024 18:42:58.801> Unable to find the default settings file 'C:\Users\admin\AppData\Roaming\Highresolution Enterprises\XMouseButtonControl\XMBCSettings.xml' (Error code 2: The system cannot find the file specified. )
XMouseButtonControl.exe
06-02-2024 18:42:58.801> HookDLL: Unable to load XML settings
XMouseButtonControl.exe
06-02-2024 18:42:58.801> Running on Microsoft Windows 7 Professional Edition Service Pack 1 (build 7601), 32-bit, Hook Timeout: 1000 ms