File name:

Roshade.Setup.3.3.1.exe

Full analysis: https://app.any.run/tasks/ab6c3098-c135-4723-98c4-85c2bdff53d8
Verdict: Malicious activity
Analysis date: July 15, 2024, 16:07:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

FE51CDAC1D70CC17A57CAE25C164BF47

SHA1:

814144CB9DF1C25942321FF04BB9B64BA55FC5FC

SHA256:

83FD3EB8248B4A41AB7BCBBE193D93E57BC0034D20259C6E21DC6A427CFE0DCD

SSDEEP:

98304:wSUoEyUQRr+SLX5fuK5QBEcMXiqvC7CjpLgMFX7e1V0fZAICcB5E3d66cIKwZ/0e:wn1QVFX5fZqBEcqvC2jTx76V0BACY3db

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 4832)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Executable content was dropped or overwritten

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Starts a Microsoft application from unusual location

      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 4316)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6152)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6208)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6244)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Reads the date of Windows installation

      • MicrosoftEdgeUpdate.exe (PID: 4832)
  • INFO

    • Checks supported languages

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
      • MicrosoftEdgeUpdate.exe (PID: 4316)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6152)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6208)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6244)
      • MicrosoftEdgeUpdate.exe (PID: 6364)
      • MicrosoftEdgeUpdate.exe (PID: 6496)
      • MicrosoftEdgeUpdate.exe (PID: 6576)
    • Reads the computer name

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6244)
      • MicrosoftEdgeUpdate.exe (PID: 4316)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6152)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6208)
      • MicrosoftEdgeUpdate.exe (PID: 6364)
      • MicrosoftEdgeUpdate.exe (PID: 6496)
      • MicrosoftEdgeUpdate.exe (PID: 6576)
    • Create files in a temporary directory

      • Roshade.Setup.3.3.1.exe (PID: 740)
      • wv.exe (PID: 2412)
      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 6364)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 4832)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 6364)
      • MicrosoftEdgeUpdate.exe (PID: 6576)
    • UPX packer has been detected

      • Roshade.Setup.3.3.1.exe (PID: 740)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 6364)
      • MicrosoftEdgeUpdate.exe (PID: 6576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (87.1)
.exe | Generic Win/DOS Executable (6.4)
.exe | DOS Executable Generic (6.4)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:04:22 10:23:43+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.31
CodeSize: 5988352
InitializedDataSize: 8192
UninitializedDataSize: 7053312
EntryPoint: 0xc70170
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.3.1.0
ProductVersionNumber: 3.3.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: setup
FileVersion: 3.3.1
ProductVersion: 3.3.1
FileDescription: setup
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
13
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT roshade.setup.3.3.1.exe wv.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
740"C:\Users\admin\Downloads\Roshade.Setup.3.3.1.exe" C:\Users\admin\Downloads\Roshade.Setup.3.3.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
setup
Version:
3.3.1
Modules
Images
c:\users\admin\downloads\roshade.setup.3.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2412"C:\Users\admin\AppData\Local\Temp\wv.exe"C:\Users\admin\AppData\Local\Temp\wv.exe
Roshade.Setup.3.3.1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\temp\wv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4316"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4832C:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdate.exe
wv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\temp\euf871.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6152"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.193.5\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6208"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.193.5\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6244"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.193.5\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6364"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTMuNSIgc2hlbGxfdmVyc2lvbj0iMS4zLjE5My41IiBpc21hY2hpbmU9IjAiIHNlc3Npb25pZD0ie0MzMjhGOTMzLUUyNjMtNDREQS1CNjlDLTNCRTZERjE3QTBGRH0iIHVzZXJpZD0ie0Y4QUUwOTJCLTVENUYtNDdBRC1BQTAzLTJGRjM2ODQ4Qzc2RX0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiByZXF1ZXN0aWQ9IntEODE1ODQ3My1ERjQzLTREQzctQkIwRS0xNkFFQzNGRDkyN0V9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE5My41IiBsYW5nPSIiIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIxOTAxNzE5OTU5NiIgaW5zdGFsbF90aW1lX21zPSI4MjgiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6496"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource taggedmi /sessionid "{C328F933-E263-44DA-B69C-3BE6DF17A0FD}"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.193.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6516C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
14 998
Read events
8 046
Write events
6 918
Delete events
34

Modification events

(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.193.5
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.193.5
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\MicrosoftEdgeUpdateCore.exe"
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_c
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001Core{F12DDF7D-4385-4485-A2C9-D60DDBD137ED}
(PID) Process:(4832) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_ua
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001UA{BFECA8F1-B3B1-4146-BDC5-0FD32C7C49AA}
(PID) Process:(6152) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
Executable files
202
Suspicious files
0
Text files
3
Unknown types
2

Dropped files

PID
Process
Filename
Type
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\msedgeupdate.dllexecutable
MD5:D1175F877AB160902113B3A2250D0D78
SHA256:5CCF3EEDF6F1F57D386CEF188F070C72583D9A96FF674CE91E8776CED8E989B5
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:5679308B2E276BD371798AC8D579B1F9
SHA256:C9AEF2D24F1C77A366B327B869E4103ED8276EA83B2B40942718CC134A1E122F
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:4E1BED27BAFAA6F0A9B6B6B1481A76AE
SHA256:868D178EF15F87DF290A4D06DBD7B72F3A1B6E0F2C680D67045AD6051C7DC1E6
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:090901EBEFC233CC46D016AF98BE6D53
SHA256:7864BB95EB14E0AE1C249759CB44AD746E448007563B7430911755CF17EA5A77
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:1ECF8A13497BBC34FC1CF2C7C2DAC9B0
SHA256:8BC7B53FFF82E9BE925BD28FE4F093039CAE5990F203B2EDB4F3C072408412F6
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\psmachine.dllexecutable
MD5:47842E28A3F011BC99A1898CC9A91AF6
SHA256:1B0C4CB716DDCCE5791854376D0BA90BBBD8111048647270F3827EDD1034914A
740Roshade.Setup.3.3.1.exeC:\Users\admin\AppData\Local\Temp\wv.exeexecutable
MD5:2AEB55B75F68B4EA3F949CAE0CEBA066
SHA256:22484FDF3008A593E7CA188863D423B8B2A345391120ED296CE8B156CFA983AB
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\NOTICE.TXTtext
MD5:6DD5BF0743F2366A0BDD37E302783BCD
SHA256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:8428E306E866FE7972F05B6BE814C1CF
SHA256:855E2F2FAB4968261704CAB9BAE294FB7EC8B9C26E4D1708E29E26C454C7B0AF
2412wv.exeC:\Users\admin\AppData\Local\Temp\EUF871.tmp\psmachine_64.dllexecutable
MD5:447D4FD7B37ABB43501AA13F7FD25750
SHA256:3A84348804AEFBE6172F53EAFBE0D87D29DC6F42EA050E68F1D31385384BD72C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
83
DNS requests
25
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2060
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2060
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
768
lsass.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
768
lsass.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
4004
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6804
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/1de3d7f1-ffef-4e28-bcf3-c063e98e7191?P1=1721664451&P2=404&P3=2&P4=dDllcXSuTjFO0VcTSgGTrqz%2fHVHrB48WMN3wyaPjAfJt2lNJyftoRfVjOLM2qBZDSJhwNliFZLJP%2faub35wZng%3d%3d
unknown
whitelisted
6804
svchost.exe
GET
199.232.210.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/1de3d7f1-ffef-4e28-bcf3-c063e98e7191?P1=1721664451&P2=404&P3=2&P4=dDllcXSuTjFO0VcTSgGTrqz%2fHVHrB48WMN3wyaPjAfJt2lNJyftoRfVjOLM2qBZDSJhwNliFZLJP%2faub35wZng%3d%3d
unknown
whitelisted
5908
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4656
SearchApp.exe
104.126.37.171:443
www.bing.com
Akamai International B.V.
DE
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
1292
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2064
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4656
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2060
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
2060
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
740
Roshade.Setup.3.3.1.exe
2.19.246.123:443
go.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.171
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.162
  • 104.126.37.178
  • 104.126.37.154
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.176
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 40.127.240.158
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.46
whitelisted
go.microsoft.com
  • 2.19.246.123
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.68
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.14
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted

Threats

PID
Process
Class
Message
6804
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info