File name:

SpyHunter-Installer.exe

Full analysis: https://app.any.run/tasks/1179fa5d-3450-4e0a-b28b-20f1c0a6afb4
Verdict: Malicious activity
Analysis date: February 24, 2024, 15:32:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E501FA5EA24C1487EF81D6537494908

SHA1:

3458050B90DA73755637A3A8AFC0616EAFE84048

SHA256:

81A1332EC62D7FCF8AAAF9ECB48A03E4DD4011950234FBA11FD5FADA711C77B0

SSDEEP:

98304:zs0GAPsAEqF+nPZcw7UfmxNQt+hq2Ml+x+U66JcZcQyCfZBr4ogdhHy/nT51r9If:Xkjnba/NIn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SpyHunter-Installer.exe (PID: 3660)
      • ShKernel.exe (PID: 3764)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SpyHunter-Installer.exe (PID: 3660)
    • Actions looks like stealing of personal data

      • SpyHunter5.exe (PID: 3092)
    • Steals credentials from Web Browsers

      • SpyHunter5.exe (PID: 3092)
    • Creates a writable file in the system directory

      • ShKernel.exe (PID: 3764)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • SpyHunter-Installer.exe (PID: 3660)
      • SpyHunter5.exe (PID: 3092)
    • Drops 7-zip archiver for unpacking

      • SpyHunter-Installer.exe (PID: 3660)
    • Executable content was dropped or overwritten

      • SpyHunter-Installer.exe (PID: 3660)
      • ShKernel.exe (PID: 3764)
    • Reads the Internet Settings

      • taskmgr.exe (PID: 2184)
      • rundll32.exe (PID: 784)
    • Starts SC.EXE for service management

      • SpyHunter-Installer.exe (PID: 3660)
    • The process executes via Task Scheduler

      • rundll32.exe (PID: 784)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3708)
    • Creates a software uninstall entry

      • SpyHunter-Installer.exe (PID: 3660)
    • Reads the Windows owner or organization settings

      • ShKernel.exe (PID: 3764)
      • SpyHunter5.exe (PID: 3092)
    • Executes as Windows Service

      • ShKernel.exe (PID: 3764)
      • ShMonitor.exe (PID: 3956)
    • Creates files in the driver directory

      • ShKernel.exe (PID: 3764)
    • Drops a system driver (possible attempt to evade defenses)

      • ShKernel.exe (PID: 3764)
  • INFO

    • Checks supported languages

      • SpyHunter-Installer.exe (PID: 3660)
      • ShKernel.exe (PID: 3764)
      • ShMonitor.exe (PID: 3956)
      • SpyHunter5.exe (PID: 3092)
    • Reads the computer name

      • SpyHunter-Installer.exe (PID: 3660)
      • ShKernel.exe (PID: 3764)
      • ShMonitor.exe (PID: 3956)
      • SpyHunter5.exe (PID: 3092)
    • Create files in a temporary directory

      • SpyHunter-Installer.exe (PID: 3660)
    • Creates files in the program directory

      • SpyHunter-Installer.exe (PID: 3660)
      • ShMonitor.exe (PID: 3956)
      • ShKernel.exe (PID: 3764)
      • SpyHunter5.exe (PID: 3092)
    • Manual execution by a user

      • taskmgr.exe (PID: 2184)
      • msedge.exe (PID: 2028)
    • Reads security settings of Internet Explorer

      • taskmgr.exe (PID: 2184)
    • Reads the time zone

      • perfmon.exe (PID: 2488)
    • Application launched itself

      • msedge.exe (PID: 3252)
      • msedge.exe (PID: 2028)
    • Reads Windows Product ID

      • ShKernel.exe (PID: 3764)
      • SpyHunter5.exe (PID: 3092)
    • Reads CPU info

      • ShKernel.exe (PID: 3764)
      • SpyHunter5.exe (PID: 3092)
    • Process checks whether UAC notifications are on

      • ShKernel.exe (PID: 3764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:08 14:36:09+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4766720
InitializedDataSize: 2403328
UninitializedDataSize: -
EntryPoint: 0x2a8097
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.853.5482
ProductVersionNumber: 3.0.853.5482
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: EnigmaSoft Limited
FileDescription: EnigmaSoft Installer
FileVersion: 3.0.853.5482
InternalName: Installer.exe
LegalCopyright: Copyright 2016-2023. EnigmaSoft Limited. All rights reserved.
OriginalFileName: Installer.exe
ProductName: Installer
ProductVersion: 3.0.853.5482
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
87
Monitored processes
34
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spyhunter-installer.exe taskmgr.exe no specs perfmon.exe sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs sc.exe no specs msedge.exe no specs msedge.exe no specs sc.exe no specs regsvr32.exe no specs sc.exe no specs shkernel.exe sc.exe no specs shmonitor.exe no specs msedge.exe no specs spyhunter5.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs spyhunter-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128C:\Windows\System32\sc.exe create ShMonitor start= demand binPath= "\"C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe\"" DisplayName= "SpyHunter 5 Kernel Monitor"C:\Windows\System32\sc.exeSpyHunter-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
448C:\Windows\System32\sc.exe description EsgShKernel "SpyHunter 5 Kernel"C:\Windows\System32\sc.exeSpyHunter-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
532"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1352 --field-trial-handle=1316,i,9186040043753496771,5108019758198677187,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xe4,0x69dbf598,0x69dbf5a8,0x69dbf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
784C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler https://www.enigmasoftware.com/congratulations-spyhunter-installed/?hwx=be61cceca008f70f83a14f29cff82655&lang=EN&purl=https%3A%2F%2Fpurchase%2Eenigmasoftware%2Ecom%2Fpurchase%5Fspyhunter%2Ephp%3Fsid%3Dshc&sid=shcC:\Windows\System32\rundll32.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1540C:\Windows\System32\sc.exe create EsgShKernel start= demand binPath= "\"C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe\"" DisplayName= "SpyHunter 5 Kernel"C:\Windows\System32\sc.exeSpyHunter-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1636C:\Windows\System32\sc.exe description ShMonitor "SpyHunter 5 Kernel Monitor"C:\Windows\System32\sc.exeSpyHunter-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1808"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3448 --field-trial-handle=1228,i,14459502262803801084,3942348753002734842,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
2028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.enigmasoftware.com/congratulations-spyhunter-installed/?hwx=be61cceca008f70f83a14f29cff82655&lang=EN&purl=https%3A%2F%2Fpurchase%2Eenigmasoftware%2Ecom%2Fpurchase%5Fspyhunter%2Ephp%3Fsid%3Dshc&sid=shcC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3528 --field-trial-handle=1228,i,14459502262803801084,3942348753002734842,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
91 645
Read events
91 545
Write events
89
Delete events
11

Modification events

(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:LanguageType
Value:
EN
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ITime
Value:
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardEnabled
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardUnknownExecution
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:GuardUnknownPromptOnlySuspicious
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:CloudAnalysis
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ShowArmW10Warning
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:ICfg
Value:
e72d8cb294cee996ff651da25d101b5aad690c18f315b567a154a745ce4cde89b4b75113893fda6cdde508dc9c7de3002ac8d02a84ce50a341176b2bad9d90ef
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:AdFlags
Value:
1
(PID) Process:(3660) SpyHunter-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EnigmaSoft\SpyHunter\SpyHunterConfig
Operation:writeName:Language
Value:
English.lng
Executable files
10
Suspicious files
46
Text files
34
Unknown types
82

Dropped files

PID
Process
Filename
Type
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\purl.datbinary
MD5:E6F17E43279A13A1D56226176B17E917
SHA256:D1E20650BD99A980EBF1E7BEF5A9B9343C8ED99EE377183640DFD3A3BD240374
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Native.exeexecutable
MD5:A65B45590375B59B2D4267CDBFF65FD4
SHA256:13030203E1CFD38547413CC678A8D49C38B839C545B022AE1354949B0B144EC4
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\English.lngbinary
MD5:6F596223D7F6DA958C0DA90B2CE7D661
SHA256:0E481E82E45FF6BCFEFE06F23C6C8025A28CDD148189B407BEC12533415A2123
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Czech.lngbinary
MD5:78EDA8C7B531040C646D7D0E8BCCF5F0
SHA256:93FC6A23D6872ACF1EF8F400BBBB6E7F90915A8A67A3CF24CABF2004BC069CF8
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\license.txttext
MD5:66507057FFDF4CAF36C3061C80D2D08F
SHA256:A80E70A5E036EAC0C75354D4EE0E4147D606DEBBDDB704435C96CF2DE2C8C777
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\WebSecurityNative.exeexecutable
MD5:545FB7AB5E24A3DDBD542DFA608AFFAC
SHA256:2636794DFE5963B03DC3AFD0F3058324F93749797F0DA3F2470AFFE34ED31355
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\Languages\Danish.lngbinary
MD5:118FC18FBAB4A3626085F584CA4F863E
SHA256:4B788D88A9317F7181582C6855FF230F5BD953F2CDACFAB029D346C765128E9A
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exeexecutable
MD5:83883B09B751698ECC98DEED0B2E5329
SHA256:934DF74001EA2178E2F2E4A510FC56AC7375893905425BA1DD1A9CA6BED072FB
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\7z.dllexecutable
MD5:167ADFA77861F048CDC30016DE4C50A0
SHA256:8DA781422A05AEE0DD134804150845845E67C26E9390507B034B9161623BBAEB
3660SpyHunter-Installer.exeC:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exeexecutable
MD5:68BB2C21CEE9B489D5F97E2462661F30
SHA256:9BBB8DDF3DCD10C8006521C85C67713A8D17A3EF511AE1D63BBAE615A7F3F5F6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
123
DNS requests
137
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3660
SpyHunter-Installer.exe
HEAD
200
142.251.36.196:80
http://www.google.com/
unknown
unknown
3660
SpyHunter-Installer.exe
GET
301
185.24.11.19:80
http://installer.enigmasoftware.com/log_collect.cfg
unknown
html
162 b
unknown
3660
SpyHunter-Installer.exe
GET
301
185.24.11.19:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_initrd.gz.ecf
unknown
html
162 b
unknown
3660
SpyHunter-Installer.exe
GET
301
185.24.11.19:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_shldr.ecf
unknown
html
162 b
unknown
3660
SpyHunter-Installer.exe
GET
301
185.24.11.19:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_vmlinuz.ecf
unknown
html
162 b
unknown
3660
SpyHunter-Installer.exe
GET
301
185.24.11.19:80
http://installer.enigmasoftware.com/shos5/3.18.5/sh5_shldr.mbr.ecf
unknown
html
162 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3660
SpyHunter-Installer.exe
18.66.27.105:443
geo-ip.enigmasoft.net
US
unknown
3660
SpyHunter-Installer.exe
142.251.36.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
3660
SpyHunter-Installer.exe
142.251.36.196:80
www.google.com
GOOGLE
US
whitelisted
3660
SpyHunter-Installer.exe
185.24.11.19:80
installer.enigmasoftware.com
Datacamp Limited
AT
unknown
3660
SpyHunter-Installer.exe
185.24.11.19:443
installer.enigmasoftware.com
Datacamp Limited
AT
unknown
4
System
192.168.100.2:137
whitelisted
2028
msedge.exe
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
geo-ip.enigmasoft.net
  • 18.66.27.105
unknown
www.google-analytics.com
  • 142.251.36.206
  • 142.251.37.14
whitelisted
www.google.com
  • 142.251.36.196
whitelisted
installer.enigmasoftware.com
  • 185.24.11.19
shared
19.11.24.185.in-addr.arpa
unknown
2.100.168.192.in-addr.arpa
unknown
252.0.0.224.in-addr.arpa
unknown
3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
unknown
2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
unknown
www.enigmasoftware.com
  • 18.66.122.99
whitelisted

Threats

No threats detected
Process
Message
ShKernel.exe
Main. Enter. Initializing logger...