URL:

https://gamefavorite.ru/igrokam/discord/

Full analysis: https://app.any.run/tasks/db4b8c5e-9981-460b-a2aa-b8e585b895e4
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 25, 2026, 02:08:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
websocket
discord
adware
loader
stealer
inno
installer
delphi
opera
tool
phishing
filename-lure
nodejs
qrcode
Indicators:
MD5:

E00C8AC485E9EBBFAFA76F751DA6BA83

SHA1:

67AB2524CE69FA3EF5A6816DB36BB64057E495E2

SHA256:

79F1800A22BAAEF666F2AA0D8BA5C9FDC3A29A76021618F8D0460AE77906FC2B

SSDEEP:

3:N8lgKxXfDXKAM8:2i6baAv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
    • Actions looks like stealing of personal data

      • Discord.exe (PID: 6272)
      • installer.exe (PID: 7960)
      • opera_crashreporter.exe (PID: 9652)
      • opera_crashreporter.exe (PID: 9668)
      • opera.exe (PID: 9600)
      • opera_crashreporter.exe (PID: 9896)
      • opera.exe (PID: 9956)
      • opera_crashreporter.exe (PID: 9320)
      • opera_crashreporter.exe (PID: 7288)
      • browser_assistant.exe (PID: 9780)
      • opera_crashreporter.exe (PID: 9500)
      • browser_assistant.exe (PID: 9512)
      • opera.exe (PID: 10412)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 10780)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 7316)
      • opera_autoupdate.exe (PID: 4916)
      • opera_autoupdate.exe (PID: 10356)
      • 360TS_Setup.exe (PID: 8928)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 9664)
      • opera.exe (PID: 4348)
      • opera.exe (PID: 10928)
      • opera_autoupdate.exe (PID: 9788)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 9000)
    • Steals credentials from Web Browsers

      • installer.exe (PID: 8124)
      • installer.exe (PID: 7960)
      • installer.exe (PID: 5132)
      • installer.exe (PID: 6840)
      • assistant_installer.exe (PID: 3140)
      • assistant_installer.exe (PID: 2340)
      • installer.exe (PID: 1152)
      • installer.exe (PID: 7568)
      • assistant_installer.exe (PID: 9368)
      • assistant_installer.exe (PID: 9388)
      • assistant_installer.exe (PID: 9448)
      • assistant_installer.exe (PID: 9468)
      • opera_crashreporter.exe (PID: 9652)
      • opera_crashreporter.exe (PID: 9668)
      • opera.exe (PID: 9544)
      • opera.exe (PID: 9600)
      • opera_crashreporter.exe (PID: 9896)
      • opera.exe (PID: 9856)
      • opera.exe (PID: 9956)
      • opera_crashreporter.exe (PID: 9320)
      • opera.exe (PID: 10028)
      • opera_crashreporter.exe (PID: 7288)
      • opera.exe (PID: 9400)
      • browser_assistant.exe (PID: 9780)
      • browser_assistant.exe (PID: 9512)
      • opera_crashreporter.exe (PID: 9500)
      • opera.exe (PID: 9996)
      • opera_crashreporter.exe (PID: 10436)
      • opera.exe (PID: 10412)
      • opera_crashreporter.exe (PID: 10608)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 10780)
      • installer.exe (PID: 5008)
      • installer.exe (PID: 9832)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 1152)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 7316)
      • opera_autoupdate.exe (PID: 10356)
      • opera_autoupdate.exe (PID: 4916)
      • opera_crashreporter.exe (PID: 10476)
      • opera.exe (PID: 4348)
      • opera.exe (PID: 10928)
      • opera_autoupdate.exe (PID: 9788)
      • opera_autoupdate.exe (PID: 6752)
      • opera_autoupdate.exe (PID: 8364)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 9000)
    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 9368)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 4348)
    • Phishing lure filenames

      • Discord.exe (PID: 6240)
    • Executing a file with an untrusted certificate

      • DiscordSystemHelper.exe (PID: 8336)
      • DiscordSystemHelper.exe (PID: 8788)
      • DiscordSystemHelper.exe (PID: 4172)
      • DiscordSystemHelper.exe (PID: 5564)
      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 9148)
      • DiscordSystemHelper.exe (PID: 10988)
      • install-bluestacks-app-player.exe (PID: 8220)
      • DiscordSystemHelper.exe (PID: 11008)
      • BlueStacksInstaller.exe (PID: 11244)
      • install-bluestacks-app-player.exe (PID: 10392)
      • Bootstrapper.exe (PID: 11020)
      • BlueStacksInstaller.exe (PID: 8476)
      • HD-GLCheck.exe (PID: 2736)
      • HD-GLCheck.exe (PID: 10300)
      • HD-GLCheck.exe (PID: 4212)
      • HD-GLCheck.exe (PID: 10936)
      • HD-GLCheck.exe (PID: 10328)
      • HD-GLCheck.exe (PID: 10660)
      • HD-GLCheck.exe (PID: 9404)
      • HD-GLCheck.exe (PID: 10612)
      • HD-GLCheck.exe (PID: 9888)
      • HD-GLCheck.exe (PID: 672)
      • HD-CheckCpu.exe (PID: 9140)
      • HD-ComRegistrar.exe (PID: 9544)
      • HD-InstallImage.exe (PID: 9488)
      • HD-ComRegistrar.exe (PID: 9508)
    • Application was injected by another process

      • explorer.exe (PID: 4696)
    • Runs injected code in another process

      • syspin.exe (PID: 9748)
      • syspin.exe (PID: 9476)
      • syspin.exe (PID: 9004)
      • syspin.exe (PID: 10744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AppWizardSetup_1.140.19.exe (PID: 8772)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • DiscordSetup.exe (PID: 7624)
      • Update.exe (PID: 420)
      • OperaSetup_EjTac5Vqrg.exe (PID: 7624)
      • installer.exe (PID: 7960)
      • Discord.exe (PID: 6384)
      • Discord.exe (PID: 8948)
      • installer.exe (PID: 5132)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9368)
      • Assistant_128.0.5807.52_Setup.exe_sfx.exe (PID: 6684)
      • Discord.exe (PID: 6684)
      • opera_autoupdate.exe (PID: 10952)
      • DiscordSystemHelper.exe (PID: 8788)
      • AppWizard.exe (PID: 3044)
      • install-bluestacks-app-player.exe (PID: 8220)
      • install-bluestacks-app-player.exe (PID: 10392)
      • 7zr.exe (PID: 10148)
      • 7zr.exe (PID: 9940)
      • 7zr.exe (PID: 10012)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 360TS_Setup.exe (PID: 4488)
      • 360TS_Setup.exe (PID: 8928)
      • 7zr.exe (PID: 2648)
      • AppWizardSetup_1.140.19.exe (PID: 1772)
      • AppWizardSetup_1.140.19.exe (PID: 7320)
    • Searches for installed software

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • installer.exe (PID: 1152)
      • browser_assistant.exe (PID: 9512)
      • AppWizardSetup_1.140.19.tmp (PID: 5288)
      • BlueStacksInstaller.exe (PID: 8476)
    • Access to an unwanted program domain was detected

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
    • Application launched itself

      • Discord.exe (PID: 6272)
      • Discord.exe (PID: 8948)
      • installer.exe (PID: 7960)
      • installer.exe (PID: 5132)
      • assistant_installer.exe (PID: 2340)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9368)
      • browser_assistant.exe (PID: 9512)
      • opera.exe (PID: 9600)
      • assistant_installer.exe (PID: 9448)
      • opera.exe (PID: 10412)
      • opera.exe (PID: 10544)
      • installer.exe (PID: 9832)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 3092)
      • Discord.exe (PID: 6684)
      • DiscordSystemHelper.exe (PID: 8336)
      • opera_autoupdate.exe (PID: 10356)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 9664)
      • opera.exe (PID: 4348)
      • opera_autoupdate.exe (PID: 8364)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 4680)
    • Reads the Windows owner or organization settings

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
    • Possible stealing of messenger data

      • Discord.exe (PID: 6272)
      • Discord.exe (PID: 8948)
    • Starts itself from another location

      • installer.exe (PID: 7960)
      • assistant_installer.exe (PID: 9368)
      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 10988)
      • 360TS_Setup.exe (PID: 4488)
    • Reads the date of Windows installation

      • installer.exe (PID: 1152)
      • opera.exe (PID: 10544)
      • DiscordSystemHelper.exe (PID: 8336)
      • BlueStacksInstaller.exe (PID: 11244)
      • Bootstrapper.exe (PID: 11020)
      • opera.exe (PID: 4348)
      • BlueStacksInstaller.exe (PID: 8476)
    • Possible stealing from browsers

      • opera_crashreporter.exe (PID: 9668)
      • opera_crashreporter.exe (PID: 9652)
      • opera.exe (PID: 9600)
      • opera_crashreporter.exe (PID: 9896)
      • opera_crashreporter.exe (PID: 9320)
      • opera_crashreporter.exe (PID: 7288)
      • browser_assistant.exe (PID: 9780)
      • browser_assistant.exe (PID: 9512)
      • opera_crashreporter.exe (PID: 9500)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 4348)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 10544)
      • opera.exe (PID: 4348)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 8364)
    • Executes as Windows Service

      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 10988)
    • The process drops C-runtime libraries

      • install-bluestacks-app-player.exe (PID: 10392)
      • 7zr.exe (PID: 10148)
      • 7zr.exe (PID: 10012)
    • Drops 7-zip archiver for unpacking

      • install-bluestacks-app-player.exe (PID: 10392)
      • 7zr.exe (PID: 10012)
      • AppWizard.exe (PID: 3044)
      • 360TS_Setup.exe (PID: 8928)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3420)
      • cmd.exe (PID: 996)
      • cmd.exe (PID: 9732)
    • Write to the desktop.ini file (may be used to cloak folders)

      • explorer.exe (PID: 4696)
    • Creates file in the systems drive root

      • explorer.exe (PID: 4696)
      • 360TS_Setup.exe (PID: 8928)
    • Drops a system driver (possible attempt to evade defenses)

      • 7zr.exe (PID: 10012)
      • 360TS_Setup.exe (PID: 8928)
    • Uses RUNDLL32.EXE to run a file without a DLL extension

      • rundll32.exe (PID: 8384)
      • rundll32.exe (PID: 6872)
    • Uses RUNDLL32.EXE to load library

      • explorer.exe (PID: 4696)
    • The process verifies whether the antivirus software is installed

      • 360TS_Setup.exe (PID: 8928)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • BlueStacksInstaller.exe (PID: 8476)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • BlueStacksInstaller.exe (PID: 8476)
    • Suspicious use of NETSH.EXE

      • BlueStacksInstaller.exe (PID: 8476)
    • Creates/Modifies COM task schedule object

      • HD-ComRegistrar.exe (PID: 9508)
  • INFO

    • Create files in a temporary directory

      • AppWizardSetup_1.140.19.exe (PID: 8772)
      • AppWizardSetup_1.140.19.exe (PID: 8864)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • DiscordSetup.exe (PID: 7624)
      • Update.exe (PID: 420)
      • Discord.exe (PID: 8948)
      • AppWizard.exe (PID: 3044)
      • OperaSetup_EjTac5Vqrg.exe (PID: 7624)
      • installer.exe (PID: 7960)
      • Assistant_128.0.5807.52_Setup.exe_sfx.exe (PID: 6684)
      • installer.exe (PID: 1152)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 10544)
      • Discord.exe (PID: 6684)
      • opera_autoupdate.exe (PID: 10952)
      • install-bluestacks-app-player.exe (PID: 8220)
      • BlueStacksInstaller.exe (PID: 11244)
      • install-bluestacks-app-player.exe (PID: 10392)
      • 7zr.exe (PID: 10148)
      • BlueStacksInstaller.exe (PID: 8476)
      • 7zr.exe (PID: 9940)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 360TS_Setup.exe (PID: 4488)
      • 360TS_Setup.exe (PID: 8928)
      • opera.exe (PID: 4348)
      • AppWizardSetup_1.140.19.exe (PID: 1772)
      • AppWizardSetup_1.140.19.exe (PID: 7320)
    • Application launched itself

      • msedge.exe (PID: 684)
      • msedge.exe (PID: 4212)
      • msedge.exe (PID: 10860)
      • msedge.exe (PID: 10152)
    • Checks supported languages

      • identity_helper.exe (PID: 8296)
      • AppWizardSetup_1.140.19.exe (PID: 8772)
      • AppWizardSetup_1.140.19.tmp (PID: 8792)
      • AppWizardSetup_1.140.19.exe (PID: 8864)
      • DiscordSetup.exe (PID: 7624)
      • Update.exe (PID: 420)
      • Discord.exe (PID: 8628)
      • Update.exe (PID: 8668)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Discord.exe (PID: 7152)
      • Discord.exe (PID: 8204)
      • Discord.exe (PID: 8948)
      • Discord.exe (PID: 8780)
      • Discord.exe (PID: 9152)
      • Discord.exe (PID: 8668)
      • Discord.exe (PID: 6952)
      • Discord.exe (PID: 8400)
      • AppWizard.exe (PID: 3044)
      • OperaSetup_EjTac5Vqrg.exe (PID: 7624)
      • Discord.exe (PID: 6272)
      • installer.exe (PID: 8124)
      • installer.exe (PID: 7960)
      • installer.exe (PID: 8120)
      • installer.exe (PID: 6840)
      • installer.exe (PID: 5132)
      • Discord.exe (PID: 6384)
      • assistant_installer.exe (PID: 2340)
      • assistant_installer.exe (PID: 3140)
      • installer.exe (PID: 7568)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9388)
      • assistant_installer.exe (PID: 9368)
      • assistant_installer.exe (PID: 9448)
      • Assistant_128.0.5807.52_Setup.exe_sfx.exe (PID: 6684)
      • assistant_installer.exe (PID: 9468)
      • opera.exe (PID: 9544)
      • opera.exe (PID: 9600)
      • opera_crashreporter.exe (PID: 9668)
      • opera_crashreporter.exe (PID: 9652)
      • browser_assistant.exe (PID: 9512)
      • browser_assistant.exe (PID: 9780)
      • opera.exe (PID: 9856)
      • opera_crashreporter.exe (PID: 9896)
      • opera.exe (PID: 9956)
      • opera.exe (PID: 9936)
      • opera.exe (PID: 10028)
      • opera.exe (PID: 10080)
      • opera_crashreporter.exe (PID: 9320)
      • opera.exe (PID: 9496)
      • opera.exe (PID: 9480)
      • opera.exe (PID: 9524)
      • opera.exe (PID: 9400)
      • opera_crashreporter.exe (PID: 7288)
      • opera.exe (PID: 9660)
      • opera.exe (PID: 9548)
      • opera.exe (PID: 9488)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10332)
      • opera.exe (PID: 10412)
      • opera_crashreporter.exe (PID: 10436)
      • opera_crashreporter.exe (PID: 9500)
      • opera_crashreporter.exe (PID: 10608)
      • opera.exe (PID: 10768)
      • opera.exe (PID: 10780)
      • opera.exe (PID: 10980)
      • opera.exe (PID: 11012)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 10876)
      • opera.exe (PID: 10952)
      • opera.exe (PID: 10944)
      • opera.exe (PID: 10984)
      • opera.exe (PID: 11020)
      • opera.exe (PID: 11004)
      • opera.exe (PID: 11056)
      • opera.exe (PID: 4368)
      • opera.exe (PID: 10040)
      • opera_gx_splash.exe (PID: 10036)
      • opera.exe (PID: 9620)
      • opera.exe (PID: 10128)
      • opera.exe (PID: 9844)
      • opera.exe (PID: 10268)
      • opera.exe (PID: 9408)
      • opera.exe (PID: 9644)
      • opera.exe (PID: 9392)
      • opera.exe (PID: 10376)
      • opera.exe (PID: 9828)
      • opera.exe (PID: 9764)
      • opera.exe (PID: 9904)
      • opera.exe (PID: 9912)
      • opera.exe (PID: 9840)
      • opera.exe (PID: 9936)
      • opera.exe (PID: 9816)
      • opera.exe (PID: 10560)
      • opera.exe (PID: 9720)
      • opera.exe (PID: 9496)
      • opera.exe (PID: 9928)
      • opera.exe (PID: 9652)
      • opera.exe (PID: 9244)
      • opera.exe (PID: 9800)
      • opera.exe (PID: 9820)
      • opera.exe (PID: 9604)
      • opera.exe (PID: 9240)
      • opera.exe (PID: 10416)
      • opera.exe (PID: 10348)
      • opera.exe (PID: 11012)
      • installer.exe (PID: 5008)
      • installer.exe (PID: 9832)
      • opera.exe (PID: 10512)
      • opera.exe (PID: 9804)
      • opera.exe (PID: 3136)
      • opera.exe (PID: 9192)
      • opera.exe (PID: 3172)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 1152)
      • opera_autoupdate.exe (PID: 7316)
      • opera.exe (PID: 6212)
      • opera.exe (PID: 8660)
      • opera.exe (PID: 9936)
      • opera.exe (PID: 10368)
      • opera.exe (PID: 4344)
      • opera.exe (PID: 10464)
      • opera.exe (PID: 11252)
      • opera.exe (PID: 10416)
      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 8328)
      • Discord.exe (PID: 8360)
      • Discord.exe (PID: 6668)
      • Discord.exe (PID: 9288)
      • Discord.exe (PID: 7988)
      • Discord.exe (PID: 6240)
      • gpu_encoder_helper.exe (PID: 9636)
      • Discord.exe (PID: 7740)
      • Discord.exe (PID: 8404)
      • gpu_encoder_helper.exe (PID: 4172)
      • gpu_encoder_helper.exe (PID: 8316)
      • gpu_encoder_helper.exe (PID: 8240)
      • installer.exe (PID: 8720)
      • DiscordSystemHelper.exe (PID: 8336)
      • DiscordSystemHelper.exe (PID: 8788)
      • DiscordSystemHelper.exe (PID: 5564)
      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 9148)
      • DiscordSystemHelper.exe (PID: 10988)
      • DiscordSystemHelper.exe (PID: 4172)
      • DiscordSystemHelper.exe (PID: 11008)
      • install-bluestacks-app-player.exe (PID: 8220)
      • BlueStacksInstaller.exe (PID: 11244)
      • opera.exe (PID: 1860)
      • opera.exe (PID: 10012)
      • opera.exe (PID: 9136)
      • opera_autoupdate.exe (PID: 10356)
      • install-bluestacks-app-player.exe (PID: 10392)
      • opera_autoupdate.exe (PID: 4916)
      • BlueStacksInstaller.exe (PID: 8476)
      • 7zr.exe (PID: 10148)
      • Bootstrapper.exe (PID: 11020)
      • HD-GLCheck.exe (PID: 2736)
      • HD-ForceGPU.exe (PID: 9828)
      • HD-GLCheck.exe (PID: 10300)
      • HD-GLCheck.exe (PID: 4212)
      • syspin.exe (PID: 9476)
      • 7zr.exe (PID: 9940)
      • HD-GLCheck.exe (PID: 9404)
      • HD-GLCheck.exe (PID: 10936)
      • HD-GLCheck.exe (PID: 10328)
      • syspin.exe (PID: 9748)
      • HD-GLCheck.exe (PID: 10660)
      • syspin.exe (PID: 10744)
      • 7zr.exe (PID: 10012)
      • HD-GLCheck.exe (PID: 10612)
      • HD-GLCheck.exe (PID: 9888)
      • HD-GLCheck.exe (PID: 672)
      • 7zr.exe (PID: 10164)
      • syspin.exe (PID: 9004)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • identity_helper.exe (PID: 5168)
      • 360TS_Setup.exe (PID: 4488)
      • identity_helper.exe (PID: 7268)
      • 360TS_Setup.exe (PID: 8928)
      • Discord.exe (PID: 10656)
      • Update.exe (PID: 7588)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 10796)
      • Discord.exe (PID: 9140)
      • Discord.exe (PID: 9692)
      • Discord.exe (PID: 9664)
      • browser_assistant.exe (PID: 4212)
      • Discord.exe (PID: 10920)
      • 7zr.exe (PID: 10036)
      • Discord.exe (PID: 10144)
      • Update.exe (PID: 9068)
      • opera.exe (PID: 4348)
      • opera_crashreporter.exe (PID: 10476)
      • opera.exe (PID: 10928)
      • Discord.exe (PID: 10084)
      • opera.exe (PID: 11180)
      • opera.exe (PID: 8344)
      • opera.exe (PID: 10552)
      • opera.exe (PID: 8688)
      • opera.exe (PID: 10304)
      • opera.exe (PID: 9796)
      • opera.exe (PID: 10756)
      • opera.exe (PID: 11100)
      • opera.exe (PID: 9588)
      • opera.exe (PID: 10760)
      • opera.exe (PID: 11136)
      • opera.exe (PID: 6104)
      • opera.exe (PID: 8572)
      • opera.exe (PID: 10620)
      • opera.exe (PID: 1048)
      • opera.exe (PID: 4056)
      • opera.exe (PID: 10148)
      • opera.exe (PID: 8856)
      • opera.exe (PID: 10660)
      • opera.exe (PID: 8636)
      • opera.exe (PID: 8632)
      • opera.exe (PID: 8376)
      • opera.exe (PID: 9704)
      • opera_autoupdate.exe (PID: 6752)
      • opera_autoupdate.exe (PID: 9788)
      • opera_autoupdate.exe (PID: 8364)
      • opera_autoupdate.exe (PID: 5444)
      • identity_helper.exe (PID: 4396)
      • opera_autoupdate.exe (PID: 4680)
      • opera.exe (PID: 2456)
      • opera_autoupdate.exe (PID: 9000)
      • opera.exe (PID: 10272)
      • 7zr.exe (PID: 2648)
      • HD-CheckCpu.exe (PID: 9140)
      • AppWizardSetup_1.140.19.exe (PID: 1772)
      • AppWizardSetup_1.140.19.tmp (PID: 10148)
      • AppWizardSetup_1.140.19.tmp (PID: 5288)
      • HD-ComRegistrar.exe (PID: 9544)
      • HD-ComRegistrar.exe (PID: 9508)
      • HD-InstallImage.exe (PID: 9488)
      • AppWizardSetup_1.140.19.exe (PID: 7320)
      • BstkSVC.exe (PID: 5572)
      • BstkVMMgr.exe (PID: 11060)
      • BstkSVC.exe (PID: 5796)
    • Reads Environment values

      • identity_helper.exe (PID: 8296)
      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 6240)
      • BlueStacksInstaller.exe (PID: 11244)
      • BlueStacksInstaller.exe (PID: 8476)
      • identity_helper.exe (PID: 5168)
      • identity_helper.exe (PID: 7268)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 9664)
      • identity_helper.exe (PID: 4396)
    • Reads the computer name

      • AppWizardSetup_1.140.19.tmp (PID: 8792)
      • identity_helper.exe (PID: 8296)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • Discord.exe (PID: 6272)
      • Update.exe (PID: 8668)
      • Discord.exe (PID: 7152)
      • Discord.exe (PID: 8204)
      • Discord.exe (PID: 8948)
      • Discord.exe (PID: 9152)
      • Discord.exe (PID: 8668)
      • Discord.exe (PID: 6952)
      • AppWizard.exe (PID: 3044)
      • installer.exe (PID: 7960)
      • installer.exe (PID: 5132)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9368)
      • assistant_installer.exe (PID: 9448)
      • assistant_installer.exe (PID: 2340)
      • opera.exe (PID: 9544)
      • opera.exe (PID: 9600)
      • browser_assistant.exe (PID: 9512)
      • opera.exe (PID: 9856)
      • opera.exe (PID: 9936)
      • opera.exe (PID: 9956)
      • opera.exe (PID: 10028)
      • opera.exe (PID: 9400)
      • opera.exe (PID: 9660)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10412)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 10768)
      • opera.exe (PID: 10780)
      • opera_gx_splash.exe (PID: 10036)
      • opera.exe (PID: 10268)
      • installer.exe (PID: 9832)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 7316)
      • opera_autoupdate.exe (PID: 1152)
      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 8360)
      • Discord.exe (PID: 6668)
      • Discord.exe (PID: 6240)
      • Discord.exe (PID: 8404)
      • gpu_encoder_helper.exe (PID: 9636)
      • Discord.exe (PID: 7740)
      • gpu_encoder_helper.exe (PID: 4172)
      • gpu_encoder_helper.exe (PID: 8316)
      • gpu_encoder_helper.exe (PID: 8240)
      • DiscordSystemHelper.exe (PID: 8336)
      • DiscordSystemHelper.exe (PID: 8788)
      • DiscordSystemHelper.exe (PID: 5564)
      • DiscordSystemHelper.exe (PID: 4172)
      • DiscordSystemHelper.exe (PID: 10988)
      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 9148)
      • DiscordSystemHelper.exe (PID: 11008)
      • install-bluestacks-app-player.exe (PID: 8220)
      • BlueStacksInstaller.exe (PID: 11244)
      • opera_autoupdate.exe (PID: 10356)
      • install-bluestacks-app-player.exe (PID: 10392)
      • opera_autoupdate.exe (PID: 4916)
      • Bootstrapper.exe (PID: 11020)
      • BlueStacksInstaller.exe (PID: 8476)
      • 7zr.exe (PID: 10148)
      • 7zr.exe (PID: 9940)
      • HD-GLCheck.exe (PID: 2736)
      • HD-GLCheck.exe (PID: 10300)
      • HD-GLCheck.exe (PID: 4212)
      • HD-GLCheck.exe (PID: 9404)
      • HD-GLCheck.exe (PID: 10936)
      • HD-GLCheck.exe (PID: 10328)
      • HD-GLCheck.exe (PID: 10660)
      • 7zr.exe (PID: 10012)
      • HD-GLCheck.exe (PID: 10612)
      • HD-GLCheck.exe (PID: 9888)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 7zr.exe (PID: 10164)
      • HD-GLCheck.exe (PID: 672)
      • 360TS_Setup.exe (PID: 4488)
      • identity_helper.exe (PID: 7268)
      • identity_helper.exe (PID: 5168)
      • 360TS_Setup.exe (PID: 8928)
      • Discord.exe (PID: 10656)
      • Update.exe (PID: 7588)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 9692)
      • Discord.exe (PID: 9140)
      • Update.exe (PID: 9068)
      • 7zr.exe (PID: 10036)
      • Discord.exe (PID: 9664)
      • opera.exe (PID: 4348)
      • opera.exe (PID: 10928)
      • Discord.exe (PID: 10144)
      • Discord.exe (PID: 10084)
      • opera.exe (PID: 10760)
      • opera.exe (PID: 8856)
      • opera_autoupdate.exe (PID: 8364)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 6752)
      • opera_autoupdate.exe (PID: 9788)
      • identity_helper.exe (PID: 4396)
      • opera_autoupdate.exe (PID: 4680)
      • opera_autoupdate.exe (PID: 9000)
      • AppWizardSetup_1.140.19.tmp (PID: 10148)
      • 7zr.exe (PID: 2648)
      • AppWizardSetup_1.140.19.tmp (PID: 5288)
      • HD-ComRegistrar.exe (PID: 9544)
      • HD-ComRegistrar.exe (PID: 9508)
      • HD-InstallImage.exe (PID: 9488)
      • BstkSVC.exe (PID: 5572)
      • BstkVMMgr.exe (PID: 11060)
      • BstkSVC.exe (PID: 5796)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 684)
    • Reads security settings of Internet Explorer

      • AppWizardSetup_1.140.19.tmp (PID: 8792)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • AppWizard.exe (PID: 3044)
      • installer.exe (PID: 7960)
      • explorer.exe (PID: 4696)
      • installer.exe (PID: 1152)
      • browser_assistant.exe (PID: 9512)
      • DiscordSystemHelper.exe (PID: 8336)
      • DiscordSystemHelper.exe (PID: 9148)
      • DiscordSystemHelper.exe (PID: 11008)
      • Discord.exe (PID: 6240)
      • Discord.exe (PID: 6684)
      • install-bluestacks-app-player.exe (PID: 8220)
      • BlueStacksInstaller.exe (PID: 11244)
      • install-bluestacks-app-player.exe (PID: 10392)
      • Bootstrapper.exe (PID: 11020)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • rundll32.exe (PID: 8384)
      • rundll32.exe (PID: 6872)
      • OpenWith.exe (PID: 9704)
      • 360TS_Setup.exe (PID: 8928)
      • Update.exe (PID: 7588)
      • Update.exe (PID: 9068)
      • BlueStacksInstaller.exe (PID: 8476)
      • AppWizardSetup_1.140.19.tmp (PID: 10148)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 684)
    • The sample compiled with chinese language support

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • 360TS_Setup.exe (PID: 4488)
      • 360TS_Setup.exe (PID: 8928)
    • The sample compiled with russian language support

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • 360TS_Setup.exe (PID: 8928)
    • The sample compiled with english language support

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • OperaSetup_EjTac5Vqrg.exe (PID: 7624)
      • installer.exe (PID: 7960)
      • Discord.exe (PID: 6384)
      • Assistant_128.0.5807.52_Setup.exe_sfx.exe (PID: 6684)
      • Discord.exe (PID: 8948)
      • installer.exe (PID: 5132)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9368)
      • Discord.exe (PID: 6684)
      • opera_autoupdate.exe (PID: 10952)
      • AppWizard.exe (PID: 3044)
      • install-bluestacks-app-player.exe (PID: 8220)
      • install-bluestacks-app-player.exe (PID: 10392)
      • 7zr.exe (PID: 10148)
      • 7zr.exe (PID: 9940)
      • 7zr.exe (PID: 10012)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 360TS_Setup.exe (PID: 8928)
      • 7zr.exe (PID: 2648)
    • Creates files in the program directory

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • DiscordSystemHelper.exe (PID: 8788)
      • BlueStacksInstaller.exe (PID: 11244)
      • BlueStacksInstaller.exe (PID: 8476)
      • 7zr.exe (PID: 10012)
      • 7zr.exe (PID: 10164)
      • 360TS_Setup.exe (PID: 8928)
      • 360TS_Setup.exe (PID: 4488)
      • 7zr.exe (PID: 10036)
      • 7zr.exe (PID: 2648)
      • HD-ComRegistrar.exe (PID: 9544)
      • BstkSVC.exe (PID: 5572)
      • BstkSVC.exe (PID: 5796)
    • Creates files or folders in the user directory

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • explorer.exe (PID: 4696)
      • DiscordSetup.exe (PID: 7624)
      • Update.exe (PID: 420)
      • Discord.exe (PID: 8628)
      • Update.exe (PID: 8668)
      • Discord.exe (PID: 8204)
      • Discord.exe (PID: 6272)
      • Discord.exe (PID: 8780)
      • Discord.exe (PID: 6952)
      • Discord.exe (PID: 8948)
      • installer.exe (PID: 8124)
      • installer.exe (PID: 7960)
      • AppWizard.exe (PID: 3044)
      • installer.exe (PID: 5132)
      • installer.exe (PID: 1152)
      • assistant_installer.exe (PID: 9368)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 9956)
      • opera.exe (PID: 10412)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 10780)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 7316)
      • browser_assistant.exe (PID: 9512)
      • Discord.exe (PID: 8328)
      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 6668)
      • Discord.exe (PID: 6240)
      • opera_autoupdate.exe (PID: 10952)
      • DiscordSystemHelper.exe (PID: 8336)
      • DiscordSystemHelper.exe (PID: 9148)
      • BlueStacksInstaller.exe (PID: 11244)
      • BlueStacksInstaller.exe (PID: 8476)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 360TS_Setup.exe (PID: 8928)
      • Discord.exe (PID: 9140)
      • Discord.exe (PID: 10084)
      • opera.exe (PID: 4348)
      • opera.exe (PID: 10928)
    • Detects InnoSetup installer (YARA)

      • AppWizardSetup_1.140.19.exe (PID: 8772)
      • AppWizardSetup_1.140.19.tmp (PID: 8792)
      • AppWizardSetup_1.140.19.exe (PID: 8864)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
    • Compiled with Borland Delphi (YARA)

      • AppWizardSetup_1.140.19.tmp (PID: 8792)
      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Discord.exe (PID: 8668)
      • Discord.exe (PID: 8948)
      • AppWizard.exe (PID: 3044)
    • Creates a software uninstall entry

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • installer.exe (PID: 1152)
      • BlueStacksInstaller.exe (PID: 8476)
    • Reads the machine GUID from the registry

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
      • Update.exe (PID: 420)
      • Update.exe (PID: 8668)
      • Discord.exe (PID: 6272)
      • Discord.exe (PID: 8948)
      • Discord.exe (PID: 6952)
      • Discord.exe (PID: 9152)
      • AppWizard.exe (PID: 3044)
      • installer.exe (PID: 7960)
      • installer.exe (PID: 1152)
      • opera.exe (PID: 9600)
      • browser_assistant.exe (PID: 9512)
      • opera.exe (PID: 10544)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 1152)
      • opera_autoupdate.exe (PID: 7316)
      • Discord.exe (PID: 6684)
      • DiscordSystemHelper.exe (PID: 11012)
      • DiscordSystemHelper.exe (PID: 9148)
      • DiscordSystemHelper.exe (PID: 10988)
      • DiscordSystemHelper.exe (PID: 11008)
      • Discord.exe (PID: 6240)
      • BlueStacksInstaller.exe (PID: 11244)
      • opera_autoupdate.exe (PID: 10356)
      • opera_autoupdate.exe (PID: 4916)
      • BlueStacksInstaller.exe (PID: 8476)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
      • 360TS_Setup.exe (PID: 8928)
      • Discord.exe (PID: 10656)
      • Update.exe (PID: 7588)
      • Discord.exe (PID: 8860)
      • Update.exe (PID: 9068)
      • Discord.exe (PID: 9664)
      • opera.exe (PID: 4348)
      • opera_autoupdate.exe (PID: 8364)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 6752)
      • opera_autoupdate.exe (PID: 9788)
      • opera_autoupdate.exe (PID: 4680)
      • opera_autoupdate.exe (PID: 9000)
    • There is functionality for taking screenshot (YARA)

      • AppWizardSetup_1.140.19.tmp (PID: 8888)
    • Launching a file from a Registry key

      • reg.exe (PID: 8948)
      • reg.exe (PID: 7952)
      • assistant_installer.exe (PID: 9368)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 10544)
      • opera.exe (PID: 4348)
    • Node.js compiler has been detected

      • Discord.exe (PID: 8668)
      • Discord.exe (PID: 8948)
    • Search a value from a registry key

      • reg.exe (PID: 7324)
    • OPERA mutex has been found

      • opera.exe (PID: 9600)
      • browser_assistant.exe (PID: 9512)
      • opera.exe (PID: 10544)
      • opera_autoupdate.exe (PID: 3092)
      • opera_autoupdate.exe (PID: 10952)
      • opera_autoupdate.exe (PID: 10356)
      • opera.exe (PID: 4348)
      • opera_autoupdate.exe (PID: 5444)
      • opera_autoupdate.exe (PID: 4680)
    • Reads product name

      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 6240)
      • Discord.exe (PID: 8860)
      • Discord.exe (PID: 9664)
    • Reads CPU info

      • Discord.exe (PID: 6684)
      • Discord.exe (PID: 6240)
    • Attempting to use instant messaging service

      • Discord.exe (PID: 6668)
    • Disables trace logs

      • BlueStacksInstaller.exe (PID: 11244)
      • BlueStacksInstaller.exe (PID: 8476)
      • 360TS_Setup_Mini_WW_Coin_CPI202201_6.6.0.1054.exe (PID: 9104)
    • The sample compiled with bulgarian language support

      • AppWizard.exe (PID: 3044)
    • Manual execution by a user

      • rundll32.exe (PID: 8384)
      • rundll32.exe (PID: 6872)
      • Update.exe (PID: 7588)
      • browser_assistant.exe (PID: 4212)
      • Update.exe (PID: 9068)
      • opera.exe (PID: 4348)
      • msedge.exe (PID: 10744)
      • AppWizardSetup_1.140.19.exe (PID: 1772)
    • The sample compiled with turkish language support

      • 360TS_Setup.exe (PID: 8928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
780
Monitored processes
626
Malicious processes
59
Suspicious processes
43

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs appwizardsetup_1.140.19.exe appwizardsetup_1.140.19.tmp no specs appwizardsetup_1.140.19.exe #ADWARE appwizardsetup_1.140.19.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs discordsetup.exe update.exe msedge.exe no specs discord.exe discord.exe no specs update.exe no specs discord.exe no specs discord.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs discord.exe discord.exe no specs discord.exe no specs discord.exe discord.exe no specs reg.exe no specs conhost.exe no specs discord.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs appwizard.exe operasetup_ejtac5vqrg.exe installer.exe installer.exe installer.exe no specs installer.exe installer.exe discord.exe msedge.exe no specs msedge.exe no specs assistant_128.0.5807.52_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs msedge.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe browser_assistant.exe opera.exe opera.exe opera_crashreporter.exe opera_crashreporter.exe browser_assistant.exe opera.exe opera_crashreporter.exe opera.exe no specs opera.exe opera.exe opera.exe no specs opera_crashreporter.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe opera_crashreporter.exe opera.exe no specs opera.exe no specs opera.exe opera_crashreporter.exe unsecapp.exe no specs opera.exe no specs opera.exe opera_crashreporter.exe opera.exe opera_crashreporter.exe opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs installer.exe installer.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs discord.exe discord.exe no specs discord.exe no specs discord.exe reg.exe no specs conhost.exe no specs discord.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs discord.exe no specs #PHISHING discord.exe no specs gpu_encoder_helper.exe no specs discord.exe no specs discord.exe no specs gpu_encoder_helper.exe no specs gpu_encoder_helper.exe no specs conhost.exe no specs gpu_encoder_helper.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs installer.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe discordsystemhelper.exe no specs discordsystemhelper.exe no specs openwith.exe no specs install-bluestacks-app-player.exe bluestacksinstaller.exe msedge.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe msedge.exe no specs install-bluestacks-app-player.exe bootstrapper.exe no specs bluestacksinstaller.exe 7zr.exe conhost.exe no specs 7zr.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs hd-forcegpu.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs syspin.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs syspin.exe no specs conhost.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs syspin.exe no specs conhost.exe no specs 7zr.exe conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs syspin.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs 360ts_setup_mini_ww_coin_cpi202201_6.6.0.1054.exe 7zr.exe no specs conhost.exe no specs rundll32.exe no specs openwith.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs 360ts_setup.exe 360ts_setup.exe discord.exe no specs update.exe no specs discord.exe discord.exe no specs discord.exe no specs discord.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs update.exe no specs discord.exe browser_assistant.exe no specs discord.exe no specs 7zr.exe no specs conhost.exe no specs discord.exe no specs discord.exe no specs opera.exe opera_crashreporter.exe opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe 7zr.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs appwizardsetup_1.140.19.exe netsh.exe no specs conhost.exe no specs appwizardsetup_1.140.19.tmp no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs appwizardsetup_1.140.19.exe netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs appwizardsetup_1.140.19.tmp no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs netsh.exe no specs msedge.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs hd-comregistrar.exe no specs hd-comregistrar.exe no specs hd-installimage.exe no specs bstksvc.exe no specs bstkvmmgr.exe no specs conhost.exe no specs bstksvc.exe no specs svchost.exe explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
420"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
DiscordSetup.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.1.1.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
508\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
508\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Users\admin\AppData\Local\Temp\7zS89824DB0\\HD-GLCheck.exe" 1C:\Users\admin\AppData\Local\Temp\7zS89824DB0\HD-GLCheck.exeBlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems
Integrity Level:
HIGH
Description:
BlueStacks GLCheck Utility
Exit code:
1
Version:
5.0.110.1001
Modules
Images
c:\users\admin\appdata\local\temp\7zs89824db0\hd-glcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --disable-features=HttpsUpgrades,HttpsFirstModeV2,HttpsOnlyMode,HttpsFirstBalancedMode --no-first-run --no-default-browser-check https://gamefavorite.ru/igrokam/discord/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
880"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=5008,i,12203967287056127205,2885582965922527921,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5028 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
880\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
996"cmd" /c dir "C:\Program Files\BlueStacks_nxt" /sC:\Windows\System32\cmd.exeBlueStacksInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
138 012
Read events
136 173
Write events
1 726
Delete events
113

Modification events

(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000050414
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000006041A
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A03DC
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000903D2
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000903D2
Operation:delete keyName:(default)
Value:
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000F02AC
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000160260
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(8888) AppWizardSetup_1.140.19.tmpKey:HKEY_CURRENT_USER\SOFTWARE\AppWizard
Operation:writeName:hid
Value:
522639CE-89CF-46BB-B12C-E6BD3E7BB73D
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched
Operation:writeName:*PID000022b8
Value:
1
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
0000000000000000000000000000000003000100010001000F000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000001600000000000000620061006E006B00700072006F0063006500640075007200650073002E0070006E0067003E0020002000000011000000000000006E00650074007000750062006C00690063002E0070006E0067003E00200020000000140000000000000069006E0063006C00750064006500730069007200610071002E007200740066003E002000200000001A000000000000006F00760065007200760069006500770065007800700065007200690065006E00630065002E0070006E0067003E00200020000000110000000000000074006500730074006D0075007300690063002E007200740066003E002000200000001100000000000000410070007000570069007A006100720064002E006C006E006B003E0020007C000000140000000000000070006F00730074006500720061006C0077006100790073002E007200740066003E002000200000000F000000000000007400680069006E006700700070002E0070006E0067003E00200020000000020000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000000F0000000000000000000000000000000000000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000004008000000803F0000803F07000000803F0000404009000000803F000080400A0000000040000040400D000000803F0000A0400B0000000040000080400E0000000040000000000C0002000100000000000000000001000000000000000200010000000000000000001200000007000000010000000F000000000000000000000000000000000000000040000000000C000000803F0000000007000000803F000000400900000000000000404008000000803F000040400A000000803F000080400D000000803F0000A0400B000000803F0000C0400E00000000000000803F01000000000000000040020000000000000080400300000000000000A0400400000000000000C04005000000803F0000803F0600
Executable files
925
Suspicious files
2 652
Text files
5 238
Unknown types
3

Dropped files

PID
Process
Filename
Type
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFdfe27.TMP
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFdfe36.TMP
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFdfe36.TMP
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFdfe36.TMP
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFdfe46.TMP
MD5:
SHA256:
684msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
466
TCP/UDP connections
658
DNS requests
654
Threats
65

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4136
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
US
text
4.59 Kb
whitelisted
4136
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:m1_RVzVuBzWzHwyEBschOoBtUIEq7zU_2daUo3vUH8g&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
98 b
whitelisted
4136
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-css02fc5eb50037c784280746ad40ef52d9cf759eb3c71b3ec1abb84e0663917.css
RU
text
43.8 Kb
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/igrokam/discord/
RU
html
148 Kb
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-css38fab2fcc48228ea20747e4c73653089f710a263cdd37aeeaaaef523933e2.css
RU
text
113 Kb
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-css0bd96732d47ec62ff2ffbd661a488a7785c2f34268385d424c2a81e5a813d.css
RU
text
374 b
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-csse93ee86233639505bcf5c7615fc5162b89c22c7dcb60856d65471f23e62f7.css
RU
text
57.2 Kb
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-cssf53797c877e9fedab070715bc3f9987171b58b44c9a99635a875a2fe9b41b.css
RU
text
93.2 Kb
unknown
4136
msedge.exe
GET
200
87.236.16.201:443
https://gamefavorite.ru/wp-content/cache/fvm/min/1774143673-cssaf22709a7d800226350cc071f20b36b330c7225f7f55ced240c7ccc39897f.css
RU
text
19.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8000
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4136
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4136
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4136
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4136
msedge.exe
104.18.22.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted
4136
msedge.exe
142.250.201.78:443
www.youtube.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.127.138
  • 142.251.127.101
  • 142.251.127.139
  • 142.251.127.113
  • 142.251.127.100
  • 142.251.127.102
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
gamefavorite.ru
  • 87.236.16.201
unknown
api.edgeoffer.microsoft.com
  • 13.107.213.44
  • 13.107.246.44
whitelisted
copilot.microsoft.com
  • 104.18.22.222
  • 104.18.23.222
whitelisted
www.bing.com
  • 92.123.104.34
  • 92.123.104.32
  • 92.123.104.38
  • 2.16.241.218
  • 2.16.241.201
whitelisted
www.youtube.com
  • 142.250.201.78
  • 142.251.127.136
  • 142.251.140.174
  • 172.217.16.174
  • 142.251.141.78
  • 142.251.127.190
  • 142.251.127.91
  • 142.251.141.110
  • 142.251.141.142
  • 216.58.206.78
  • 142.250.186.78
  • 142.251.36.110
  • 172.217.16.206
  • 142.251.127.93
  • 142.251.37.14
  • 142.251.143.110
whitelisted

Threats

PID
Process
Class
Message
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request field missing colon
4136
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request header invalid
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request header invalid
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP METHOD terminated by non-compliant character
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request field missing colon
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP URI terminated by non-compliant character
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP METHOD terminated by non-compliant character
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request field missing colon
4136
msedge.exe
Generic Protocol Command Decode
SURICATA HTTP request header invalid
Process
Message
DiscordSetup.exe
Start up installer:
DiscordSetup.exe
Elevated process: ?
DiscordSetup.exe
Want standard install
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
[0324/221002.905:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:171] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\7a5e1c25-18d7-4335-8d0e-9fcef81b420b Opera Installer Temp\opera_package_202603242209461\assistant\assistant_installer.exe" --version
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
[0324/221012.340:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:171] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\7a5e1c25-18d7-4335-8d0e-9fcef81b420b Opera Installer Temp\opera_package_202603242209461\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --copyonly=0 --allusers=0