File name:

Install-PilotsDeck-v0.8.7.exe

Full analysis: https://app.any.run/tasks/378498f5-c261-48ae-9ce1-d8d795b3bd15
Verdict: Malicious activity
Analysis date: March 24, 2025, 16:09:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

6111FB3FF543EA8CDC259C32AB9E0876

SHA1:

DEE39F4BC034D0056B450B11FF3566236A8ED16C

SHA256:

808AF967AD8964AEE6CFFCDE8852613DF27DADA0AFC5B0FF0718A613E0C86C27

SSDEEP:

98304:0uQ8oCAvdEP4aqtvXiVw4YE234Qoqa5kFt8bYv2WKcjPlTCzn7396K8CvkIyoame:rAFiHQhZpjFrSKy6OGFVzlh+t7KKY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • msiexec.exe (PID: 7968)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • ShellExperienceHost.exe (PID: 7372)
    • Command gets lists installed versions of .NET Runtime on the system

      • cmd.exe (PID: 6584)
    • The executable file from the user directory is run by the CMD process

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
    • Searches for installed software

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
    • Starts CMD.EXE for commands execution

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • rundll32.exe (PID: 1276)
      • rundll32.exe (PID: 4012)
      • rundll32.exe (PID: 3992)
      • rundll32.exe (PID: 856)
      • rundll32.exe (PID: 7648)
      • rundll32.exe (PID: 1852)
      • StreamDeck.exe (PID: 7312)
    • Process drops legitimate windows executable

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
      • msiexec.exe (PID: 7968)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 7968)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7968)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 7844)
      • msiexec.exe (PID: 3620)
      • msiexec.exe (PID: 6032)
    • Executes as Windows Service

      • VSSVC.exe (PID: 8180)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7968)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 7968)
  • INFO

    • Create files in a temporary directory

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • rundll32.exe (PID: 1276)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • rundll32.exe (PID: 4012)
      • StreamDeck.exe (PID: 7312)
    • Reads the computer name

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • msiexec.exe (PID: 7968)
      • msiexec.exe (PID: 7476)
      • msiexec.exe (PID: 1532)
      • msiexec.exe (PID: 8116)
      • ShellExperienceHost.exe (PID: 7372)
      • msiexec.exe (PID: 8180)
      • QtWebEngineProcess.exe (PID: 496)
      • QtWebEngineProcess.exe (PID: 7488)
    • Checks supported languages

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
      • msiexec.exe (PID: 7968)
      • msiexec.exe (PID: 7476)
      • msiexec.exe (PID: 1532)
      • msiexec.exe (PID: 8116)
      • ShellExperienceHost.exe (PID: 7372)
      • msiexec.exe (PID: 8180)
      • StreamDeck.exe (PID: 7312)
      • QtWebEngineProcess.exe (PID: 496)
      • ElgatoAudioControlServer.exe (PID: 4056)
      • QtWebEngineProcess.exe (PID: 7488)
      • node20.exe (PID: 6816)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7928)
      • BackgroundTransferHost.exe (PID: 8132)
      • BackgroundTransferHost.exe (PID: 4408)
      • BackgroundTransferHost.exe (PID: 7248)
      • BackgroundTransferHost.exe (PID: 5384)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 8132)
      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • msiexec.exe (PID: 7968)
      • StreamDeck.exe (PID: 7312)
    • Reads the machine GUID from the registry

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • msiexec.exe (PID: 7968)
      • StreamDeck.exe (PID: 7312)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 8132)
      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • cmd.exe (PID: 6468)
      • StreamDeck.exe (PID: 7312)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 8132)
      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • msiexec.exe (PID: 7968)
      • slui.exe (PID: 7412)
      • slui.exe (PID: 7580)
      • StreamDeck.exe (PID: 7312)
    • Reads Environment values

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
      • StreamDeck.exe (PID: 7312)
    • Disables trace logs

      • Install-PilotsDeck-v0.8.7.exe (PID: 664)
    • The sample compiled with english language support

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 2568)
      • msiexec.exe (PID: 7968)
    • Process checks computer location settings

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7352)
      • StreamDeck.exe (PID: 7312)
      • node20.exe (PID: 6816)
    • Creates files in the program directory

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 7888)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7968)
      • msiexec.exe (PID: 7180)
    • Application launched itself

      • msiexec.exe (PID: 7968)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7968)
    • Manages system restore points

      • SrTasks.exe (PID: 7808)
    • Reads the time zone

      • StreamDeck.exe (PID: 7312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2059:08:28 15:31:24+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 16090112
InitializedDataSize: 23040
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.8.7.0
ProductVersionNumber: 0.8.7.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Installer for the PilotsDeck StreamDeck-Plugin
CompanyName: Fragtality
FileDescription: PilotsDeck Installer
FileVersion: 0.8.7.0
InternalName: Install-PilotsDeck.exe
LegalCopyright: Copyright © 2025
LegalTrademarks: -
OriginalFileName: Install-PilotsDeck.exe
ProductName: PilotsDeck Installer
ProductVersion: 0.8.7.0
AssemblyVersion: 0.8.7.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
48
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
start install-pilotsdeck-v0.8.7.exe sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe cmd.exe no specs conhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs cmd.exe no specs conhost.exe no specs windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs shellexperiencehost.exe no specs slui.exe cmd.exe conhost.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe rundll32.exe elgatoaudiocontrolserver.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe streamdeck.exe no specs streamdeck.exe crashpad_handler.exe no specs qtwebengineprocess.exe no specs elgatoaudiocontrolserverwatcher.exe no specs elgatoaudiocontrolserver.exe no specs qtwebengineprocess.exe no specs node20.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Program Files\Elgato\StreamDeck\QtWebEngineProcess.exe" --type=renderer --webengine-schemes=qrc:sV --first-renderer-process --disable-speech-api --disable-databases --disable-gpu-compositing --disable-blink-features=EyeDropperAPI,WebOTP --lang=en --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=3 --mojo-platform-channel-handle=3184 --field-trial-handle=3244,i,4363299242590089635,1118783926257081199,262144 --enable-features=NetworkServiceInProcess2,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,EyeDropper,InstalledApp,WebOTP,WebPayments,WebUSB /prefetch:1C:\Program Files\Elgato\StreamDeck\QtWebEngineProcess.exeStreamDeck.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
LOW
Description:
Qt QtWebEngineProcess
Version:
6.7.3.0
Modules
Images
c:\program files\elgato\streamdeck\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
664"C:\Users\admin\AppData\Local\Temp\Install-PilotsDeck-v0.8.7.exe" C:\Users\admin\AppData\Local\Temp\Install-PilotsDeck-v0.8.7.exe
explorer.exe
User:
admin
Company:
Fragtality
Integrity Level:
MEDIUM
Description:
PilotsDeck Installer
Version:
0.8.7.0
Modules
Images
c:\users\admin\appdata\local\temp\install-pilotsdeck-v0.8.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
856rundll32.exe "C:\WINDOWS\Installer\MSI1781.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1251281 33 StreamDeckCustomAction!StreamDeckCustomAction.CustomActions.QuitVolumeControllerServerC:\Windows\System32\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1276rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI9320.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1217390 1 StreamDeckCustomAction!StreamDeckCustomAction.CustomActions.DeleteInvalidPathRegistryKeyC:\Windows\System32\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1532C:\Windows\syswow64\MsiExec.exe -Embedding 8726485AEC51EFD942E6C5E102EFF0ADC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1852rundll32.exe "C:\WINDOWS\Installer\MSIAB15.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1354609 47 StreamDeckOBSCustomAction!StreamDeckCustomAction.CustomActions.CleanUpOldInstallC:\Windows\System32\rundll32.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1912"C:\Program Files\Elgato\StreamDeck\crashpad_handler.exe" --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\Sentry_StreamDeck --metrics-dir=C:\Users\admin\AppData\Local\Temp\Sentry_StreamDeck --url=https://o324181.ingest.sentry.io:443/api/6638213/minidump/?sentry_client=sentry.native/0.7.5&sentry_key=3d87a745f5bc4ff895cd21c0231313c8 --attachment=C:\Users\admin\AppData\Local\Temp\Sentry_StreamDeck\31ba27d1-2b01-455f-8c10-e29b42d3802a.run\__sentry-event --attachment=C:\Users\admin\AppData\Local\Temp\Sentry_StreamDeck\31ba27d1-2b01-455f-8c10-e29b42d3802a.run\__sentry-breadcrumb1 --attachment=C:\Users\admin\AppData\Local\Temp\Sentry_StreamDeck\31ba27d1-2b01-455f-8c10-e29b42d3802a.run\__sentry-breadcrumb2 --initial-client-data=0x4c0,0x4c4,0x4c8,0x48c,0x4cc,0x7ff7033bd958,0x7ff7033bd970,0x7ff7033bd988C:\Program Files\Elgato\StreamDeck\crashpad_handler.exeStreamDeck.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\elgato\streamdeck\crashpad_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2568C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\windowsdesktop-runtime-8.0.11-win-x64.exe /install /quiet /norestartC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\windowsdesktop-runtime-8.0.11-win-x64.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
0
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\inetcache\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3096"C:\Program Files\Elgato\StreamDeck\StreamDeck.exe" -silent_initC:\Program Files\Elgato\StreamDeck\StreamDeck.exemsiexec.exe
User:
admin
Company:
Corsair Memory, Inc.
Integrity Level:
MEDIUM
Description:
Stream Deck
Exit code:
0
Version:
6.8.1.21263
Modules
Images
c:\program files\elgato\streamdeck\streamdeck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
39 599
Read events
36 840
Write events
2 697
Delete events
62

Modification events

(PID) Process:(7928) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7928) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7928) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8132) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8132) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8132) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4408) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4408) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4408) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(664) Install-PilotsDeck-v0.8.7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install-PilotsDeck-v0_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
631
Suspicious files
748
Text files
1 248
Unknown types
3

Dropped files

PID
Process
Filename
Type
8132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\4ea4bd74-e1b0-4e74-848f-ab684e9aed08.down_data
MD5:
SHA256:
664Install-PilotsDeck-v0.8.7.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\windowsdesktop-runtime-8.0.11-win-x64.exe
MD5:
SHA256:
8132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4872BABAF39AA62B8D32695EBB7E9173
SHA256:2EE85DF86EE29BBEB3DCA81AA29B6DE204F605A2769B84C728A329178A2D0999
8132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\4ea4bd74-e1b0-4e74-848f-ab684e9aed08.49f4e541-6376-4ab8-a45f-4c31b692feb0.down_metabinary
MD5:BC7788E463433A2DBFD018DB18ED9192
SHA256:440EB69553749C799CB82EAAE0F1ECB856C57973B07C75DCA6822F2A4D4877B9
8132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:115421F6E48A42615C4D5CCC94BE6BC8
SHA256:D1FB63D5C89E4D05D153571100F36E3F190CD34E1538C9E05ABDBF9A74051FED
664Install-PilotsDeck-v0.8.7.exeC:\Users\admin\AppData\Local\Temp\PilotsDeck-Installer.logtext
MD5:6E8BC09038BE1E72EA02BCEC70D90786
SHA256:15145861CCB046EDA196E3EA4EA3674DB906F7138B84FA0EF0FF34C9E9D882D5
8132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0a3de230-2f4f-44cd-96f2-d997b3c643ff.49f4e541-6376-4ab8-a45f-4c31b692feb0.down_metabinary
MD5:BC7788E463433A2DBFD018DB18ED9192
SHA256:440EB69553749C799CB82EAAE0F1ECB856C57973B07C75DCA6822F2A4D4877B9
2568windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{C0C69CFA-96FB-4D8C-8C76-BC040FD9B44D}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exeexecutable
MD5:FBA0B1010E82EE3896E104749F505F54
SHA256:4AAE588970B5DE7E67C0C46B19D7E671E8186D5FD7082C1F602F57F1CED0E516
7352windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{C08E7F1F-92ED-472E-9EC5-664E37BB574F}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
7352windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{C08E7F1F-92ED-472E-9EC5-664E37BB574F}\.ba\1028\thm.wxlxml
MD5:B9428C94444693B5E3A392C8D0B95170
SHA256:C0413EDFD13FD27EEAB7B8CE60963668236466C48F4173C29F84093011C281AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
50
DNS requests
38
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7312
StreamDeck.exe
GET
200
18.173.189.168:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
7312
StreamDeck.exe
GET
200
18.173.160.201:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEAvQhsRspEalGlLyA6dvXfw%3D
unknown
whitelisted
6652
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6652
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1276
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
8132
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6068
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7968
msiexec.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6068
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6652
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1276
backgroundTaskHost.exe
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1276
backgroundTaskHost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
8132
BackgroundTransferHost.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.64
  • 40.126.32.68
  • 40.126.32.136
  • 20.190.160.66
  • 20.190.160.132
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 23.54.109.203
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 96.7.128.186
  • 23.215.0.132
  • 23.215.0.133
  • 96.7.128.192
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 104.126.37.184
  • 104.126.37.179
  • 104.126.37.163
  • 104.126.37.186
  • 104.126.37.178
  • 104.126.37.171
  • 104.126.37.128
  • 104.126.37.176
  • 104.126.37.168
whitelisted

Threats

No threats detected
No debug info