File name:

Recorder-devices-setup.exe

Full analysis: https://app.any.run/tasks/2d3affd7-7b0f-447f-987d-b49c9ae1ca38
Verdict: Malicious activity
Analysis date: June 06, 2025, 12:30:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

C04EA87A65BC213796D30FBA5042D86D

SHA1:

2286675F46E4650840BB020B8D61736ECA4DB482

SHA256:

83010C58D5738A8DBF011C67FEDA1A3DF11943BDAA03F7EB9FAC5613A87FD377

SSDEEP:

49152:+did6SjaviMUfHjT54GRpbI8+Qy5FST0Da1mW+Vbqdjs3xZMEK9TeudYWzpfDt6F:H6GavilX54GRpbINT4TALW+VbqVs3xZ5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Setup.exe (PID: 6700)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Recorder-devices-setup.tmp (PID: 1512)
      • Recorder-devices-setup.tmp (PID: 6660)
      • Recorder-devices-setup.tmp (PID: 7868)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Recorder-devices-setup.tmp (PID: 8012)
      • Recorder-devices-setup.tmp (PID: 1512)
      • Setup.exe (PID: 6700)
    • Executable content was dropped or overwritten

      • Recorder-devices-setup.exe (PID: 5324)
      • Recorder-devices-setup.exe (PID: 6148)
      • Recorder-devices-setup.tmp (PID: 1512)
      • vcredist2010_x64.exe (PID: 1568)
      • Recorder-devices-setup.exe (PID: 6620)
      • Recorder-devices-setup.tmp (PID: 6660)
      • Recorder-devices-setup.exe (PID: 7740)
      • Recorder-devices-setup.exe (PID: 7220)
      • Recorder-devices-setup.tmp (PID: 8164)
      • Recorder-devices-setup.exe (PID: 1040)
      • Recorder-devices-setup.tmp (PID: 7868)
      • Recorder-devices-setup.exe (PID: 4560)
    • Reads the Windows owner or organization settings

      • Recorder-devices-setup.tmp (PID: 1512)
      • msiexec.exe (PID: 6820)
    • Starts a Microsoft application from unusual location

      • vcredist2010_x64.exe (PID: 1568)
    • Process drops legitimate windows executable

      • vcredist2010_x64.exe (PID: 1568)
      • Recorder-devices-setup.tmp (PID: 1512)
      • msiexec.exe (PID: 6820)
    • Creates file in the systems drive root

      • vcredist2010_x64.exe (PID: 1568)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6820)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6744)
      • regsvr32.exe (PID: 2656)
  • INFO

    • Checks supported languages

      • Recorder-devices-setup.tmp (PID: 8012)
      • Recorder-devices-setup.exe (PID: 5324)
      • Recorder-devices-setup.exe (PID: 6148)
      • Recorder-devices-setup.tmp (PID: 1512)
      • vcredist2010_x64.exe (PID: 1568)
      • Setup.exe (PID: 6700)
      • msiexec.exe (PID: 6820)
    • Create files in a temporary directory

      • Recorder-devices-setup.exe (PID: 5324)
      • Recorder-devices-setup.exe (PID: 6148)
      • Recorder-devices-setup.tmp (PID: 1512)
      • Setup.exe (PID: 6700)
    • Reads the computer name

      • Recorder-devices-setup.tmp (PID: 8012)
      • Recorder-devices-setup.exe (PID: 6148)
      • Recorder-devices-setup.tmp (PID: 1512)
      • vcredist2010_x64.exe (PID: 1568)
      • Setup.exe (PID: 6700)
      • msiexec.exe (PID: 6820)
    • Process checks computer location settings

      • Recorder-devices-setup.tmp (PID: 8012)
      • Recorder-devices-setup.tmp (PID: 1512)
    • Checks proxy server information

      • Recorder-devices-setup.tmp (PID: 1512)
      • slui.exe (PID: 5024)
    • Reads the software policy settings

      • Recorder-devices-setup.tmp (PID: 1512)
      • Setup.exe (PID: 6700)
      • msiexec.exe (PID: 6820)
      • slui.exe (PID: 7812)
      • slui.exe (PID: 5024)
    • Compiled with Borland Delphi (YARA)

      • Recorder-devices-setup.exe (PID: 5324)
      • Recorder-devices-setup.tmp (PID: 8012)
    • Detects InnoSetup installer (YARA)

      • Recorder-devices-setup.exe (PID: 5324)
      • Recorder-devices-setup.tmp (PID: 8012)
    • The sample compiled with english language support

      • Recorder-devices-setup.tmp (PID: 1512)
      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with Italian language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • Reads the machine GUID from the registry

      • vcredist2010_x64.exe (PID: 1568)
      • Setup.exe (PID: 6700)
      • msiexec.exe (PID: 6820)
    • The sample compiled with russian language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with japanese language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with chinese language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with korean language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with spanish language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with french language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • The sample compiled with german language support

      • vcredist2010_x64.exe (PID: 1568)
      • msiexec.exe (PID: 6820)
    • Reads CPU info

      • Setup.exe (PID: 6700)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6820)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6820)
    • Creates files in the program directory

      • Recorder-devices-setup.tmp (PID: 1512)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6820)
      • Recorder-devices-setup.tmp (PID: 1512)
    • Manual execution by a user

      • Recorder-devices-setup.exe (PID: 6620)
      • Recorder-devices-setup.exe (PID: 7220)
      • Recorder-devices-setup.exe (PID: 1040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:01:08 15:36:35+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 684032
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa7f98
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Recorder Devices for ShareX Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Recorder Devices for ShareX
ProductVersion: 0.12.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
27
Malicious processes
4
Suspicious processes
6

Behavior graph

Click at the process to see the details
start recorder-devices-setup.exe recorder-devices-setup.tmp no specs sppextcomobj.exe no specs slui.exe recorder-devices-setup.exe recorder-devices-setup.tmp vcredist2010_x64.exe setup.exe no specs msiexec.exe regsvr32.exe no specs regsvr32.exe no specs slui.exe rundll32.exe no specs recorder-devices-setup.exe recorder-devices-setup.tmp no specs recorder-devices-setup.exe recorder-devices-setup.tmp regsvr32.exe no specs regsvr32.exe no specs recorder-devices-setup.exe recorder-devices-setup.tmp no specs recorder-devices-setup.exe recorder-devices-setup.tmp recorder-devices-setup.exe recorder-devices-setup.tmp regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
960"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1040"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1512"C:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmp" /SL5="$C034E,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$C00BE /NOTIFYWND=$90274 C:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmp
Recorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2e1l9.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1568"C:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exe" /passive /norestartC:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2010 x64 Redistributable Setup
Exit code:
0
Version:
10.0.40219.325
Modules
Images
c:\users\admin\appdata\local\temp\is-8uub0.tmp\vcredist2010_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1616"C:\Users\admin\AppData\Local\Temp\is-HAKKI.tmp\Recorder-devices-setup.tmp" /SL5="$60288,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\is-HAKKI.tmp\Recorder-devices-setup.tmpRecorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hakki.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
2656"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\virtual-audio-capturer-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3768"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3828"C:\Users\admin\AppData\Local\Temp\is-V11IM.tmp\Recorder-devices-setup.tmp" /SL5="$B02A0,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\is-V11IM.tmp\Recorder-devices-setup.tmpRecorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-v11im.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
4560"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$80348 /NOTIFYWND=$B02A0 C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
5024C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
11 468
Read events
10 890
Write events
553
Delete events
25

Modification events

(PID) Process:(6820) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
A41A000079C4F7E4DED6DB01
(PID) Process:(6820) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
962E8F3548F6D6EC0479AA31165AE3E3671676C95C2D16DE7BE9CF3106272DD8
(PID) Process:(6820) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:c:\Config.Msi\
Value:
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\123311.rbs
Value:
31184606
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\123311.rbsLow
Value:
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0480DC222D01C4F37A2077C032048022
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
02:\SOFTWARE\Microsoft\VisualStudio\10.0\VC\VCRedist\x64\Version
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C065BA555D648923380AAA2171113286
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
02:\SOFTWARE\Microsoft\DevDiv\vc\Servicing\10.0\red\amd64\1033\Install
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:c:\Program Files\Common Files\Microsoft Shared\VC\msdia100.dll
Value:
1
(PID) Process:(6820) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94422102FB8324F41B3E7CD7B422BDC7
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?Program Files\Common Files\Microsoft Shared\VC\msdia100.dll
Executable files
83
Suspicious files
10
Text files
50
Unknown types
10

Dropped files

PID
Process
Filename
Type
1512Recorder-devices-setup.tmpC:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\is-04U5G.tmpexecutable
MD5:02A945866CD1B13E2375C024F0E18301
SHA256:F3B7A76D84D23F91957AA18456A14B4E90609E4CE8194C5653384ED38DADA6F3
6148Recorder-devices-setup.exeC:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmpexecutable
MD5:998C1046FD9851A2CBE08E8432FBBCEB
SHA256:BB0ECB905EF428867C55899D577AEC1AAF822AE756063C754D3FDB245B9003BA
1568vcredist2010_x64.exeC:\78a395924524f76076\SetupUi.dllexecutable
MD5:0D214CED87BF0B55883359160A68DACB
SHA256:29CF99D7E67B4C54BAFD109577A385387A39301BCDEC8AE4BA1A8A0044306713
1568vcredist2010_x64.exeC:\78a395924524f76076\DisplayIcon.icoimage
MD5:F9657D290048E169FFABBBB9C7412BE0
SHA256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160
1512Recorder-devices-setup.tmpC:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exeexecutable
MD5:02A945866CD1B13E2375C024F0E18301
SHA256:F3B7A76D84D23F91957AA18456A14B4E90609E4CE8194C5653384ED38DADA6F3
1568vcredist2010_x64.exeC:\78a395924524f76076\SetupEngine.dllexecutable
MD5:63E7901D4FA7AC7766076720272060D0
SHA256:A5116CCB17B242713E5645C2374ABF5827C0D2752B31553E3540C9123812E952
1568vcredist2010_x64.exeC:\78a395924524f76076\Setup.exeexecutable
MD5:2AF2C1A78542975B12282ACA4300D515
SHA256:531EB45798728CB741043B28B8C1A4F75536DC75F92D100F55F9109D2D63F0D7
1568vcredist2010_x64.exeC:\78a395924524f76076\SetupUi.xsdxml
MD5:2FADD9E618EFF8175F2A6E8B95C0CACC
SHA256:222211E8F512EDF97D78BC93E1F271C922D5E91FA899E092B4A096776A704093
1568vcredist2010_x64.exeC:\78a395924524f76076\SplashScreen.bmpimage
MD5:43B254D97B4FB6F9974AD3F935762C55
SHA256:91A21EBA9F5E1674919EE3B36EFA99714CFB919491423D888CB56C0F25845969
1568vcredist2010_x64.exeC:\78a395924524f76076\sqmapi.dllexecutable
MD5:3F0363B40376047EFF6A9B97D633B750
SHA256:BD6395A58F55A8B1F4063E813CE7438F695B9B086BB965D8AC44E7A97D35A93C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
40
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6960
svchost.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6820
msiexec.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
7424
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7424
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6960
svchost.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5608
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
6960
svchost.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
6960
svchost.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6960
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1512
Recorder-devices-setup.tmp
23.212.89.111:443
download.microsoft.com
AKAMAI-AS
MX
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 95.101.149.131
whitelisted
download.microsoft.com
  • 23.212.89.111
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.22
  • 20.190.160.3
  • 20.190.160.65
  • 40.126.32.138
  • 20.190.159.129
  • 20.190.159.71
  • 20.190.159.75
  • 40.126.31.129
  • 20.190.159.131
  • 40.126.31.128
  • 20.190.159.68
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info