File name:

orcus_premium.rar

Full analysis: https://app.any.run/tasks/57445472-a4cb-4614-b576-9ae4ce2f6cf8
Verdict: Malicious activity
Threats:

Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.

Analysis date: January 24, 2022, 15:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
orcus
trojan
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C17C457C5B4E869466BB3F0BBB8F2801

SHA1:

923070A1DAE11B1E5D020D6532330CCEB417FCD1

SHA256:

8AF4B7F47E3848815DC1D5D47CEB8A7F68542F39222A2AB6B01BD23D6E2D7D01

SSDEEP:

24576:ohQqUHMSlgyHEmdL+ZBSeA2xkLEfoT95LarEL:PMSCyHDMVxq75Gu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • orcus_premium.exe (PID: 2612)
    • Application was dropped or rewritten from another process

      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • Synaptics.exe (PID: 4016)
      • orcus_premium.exe (PID: 2640)
      • ._cache_orcus_premium.exe (PID: 3684)
      • ._cache_orcus_premium.exe (PID: 2464)
      • ._cache_orcus_premium.exe (PID: 1292)
      • orcus_premium.exe (PID: 2152)
      • ._cache_orcus_premium.exe (PID: 3980)
      • orcus_premium.exe (PID: 3156)
      • ._cache_orcus_premium.exe (PID: 2524)
      • ._cache_orcus_premium.exe (PID: 1876)
      • orcus_premium.exe (PID: 3968)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 1748)
      • ._cache_orcus_premium.exe (PID: 3116)
      • orcus_premium.exe (PID: 3464)
      • ._cache_orcus_premium.exe (PID: 3936)
      • ._cache_orcus_premium.exe (PID: 3652)
      • orcus_premium.exe (PID: 3496)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3036)
      • orcus_premium.exe (PID: 3560)
      • ._cache_orcus_premium.exe (PID: 3164)
      • orcus_premium.exe (PID: 120)
      • ._cache_orcus_premium.exe (PID: 1556)
      • orcus_premium.exe (PID: 1704)
      • orcus_premium.exe (PID: 3800)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 4048)
      • ._cache_orcus_premium.exe (PID: 3096)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 652)
      • ._cache_orcus_premium.exe (PID: 3240)
    • ORCUS was detected

      • ._cache_orcus_premium.exe (PID: 2464)
      • ._cache_orcus_premium.exe (PID: 3684)
      • ._cache_orcus_premium.exe (PID: 1292)
      • ._cache_orcus_premium.exe (PID: 3980)
      • ._cache_orcus_premium.exe (PID: 2524)
      • ._cache_orcus_premium.exe (PID: 1876)
      • ._cache_orcus_premium.exe (PID: 3116)
      • ._cache_orcus_premium.exe (PID: 568)
      • ._cache_orcus_premium.exe (PID: 3936)
      • ._cache_orcus_premium.exe (PID: 3652)
      • ._cache_orcus_premium.exe (PID: 3036)
      • ._cache_orcus_premium.exe (PID: 3164)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3096)
      • ._cache_orcus_premium.exe (PID: 3452)
      • ._cache_orcus_premium.exe (PID: 3240)
      • ._cache_orcus_premium.exe (PID: 4048)
    • Drops executable file immediately after starts

      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Connects to CnC server

      • Synaptics.exe (PID: 4016)
    • Changes settings of System certificates

      • Synaptics.exe (PID: 4016)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2532)
      • ._cache_orcus_premium.exe (PID: 2464)
      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • Synaptics.exe (PID: 4016)
      • ._cache_orcus_premium.exe (PID: 3684)
      • ._cache_orcus_premium.exe (PID: 1292)
      • orcus_premium.exe (PID: 2152)
      • ._cache_orcus_premium.exe (PID: 3980)
      • orcus_premium.exe (PID: 3156)
      • ._cache_orcus_premium.exe (PID: 2524)
      • orcus_premium.exe (PID: 2640)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 1876)
      • orcus_premium.exe (PID: 3968)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 1748)
      • ._cache_orcus_premium.exe (PID: 3116)
      • orcus_premium.exe (PID: 3464)
      • ._cache_orcus_premium.exe (PID: 3936)
      • orcus_premium.exe (PID: 3496)
      • ._cache_orcus_premium.exe (PID: 3652)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3036)
      • orcus_premium.exe (PID: 3560)
      • ._cache_orcus_premium.exe (PID: 3164)
      • ._cache_orcus_premium.exe (PID: 1556)
      • orcus_premium.exe (PID: 1704)
      • orcus_premium.exe (PID: 120)
      • ._cache_orcus_premium.exe (PID: 3096)
      • orcus_premium.exe (PID: 3800)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 652)
      • ._cache_orcus_premium.exe (PID: 3240)
      • ._cache_orcus_premium.exe (PID: 4048)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2532)
      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Reads the computer name

      • orcus_premium.exe (PID: 2612)
      • WinRAR.exe (PID: 2532)
      • ._cache_orcus_premium.exe (PID: 2464)
      • orcus_premium.exe (PID: 2044)
      • Synaptics.exe (PID: 4016)
      • ._cache_orcus_premium.exe (PID: 3684)
      • orcus_premium.exe (PID: 2640)
      • ._cache_orcus_premium.exe (PID: 1292)
      • ._cache_orcus_premium.exe (PID: 3980)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • ._cache_orcus_premium.exe (PID: 2524)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 1876)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 1748)
      • ._cache_orcus_premium.exe (PID: 3116)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3968)
      • ._cache_orcus_premium.exe (PID: 3936)
      • orcus_premium.exe (PID: 3496)
      • ._cache_orcus_premium.exe (PID: 3652)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3036)
      • orcus_premium.exe (PID: 3560)
      • orcus_premium.exe (PID: 120)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3164)
      • ._cache_orcus_premium.exe (PID: 3096)
      • orcus_premium.exe (PID: 3800)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 1704)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 652)
      • ._cache_orcus_premium.exe (PID: 3240)
      • ._cache_orcus_premium.exe (PID: 4048)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2532)
      • orcus_premium.exe (PID: 2612)
    • Reads the date of Windows installation

      • orcus_premium.exe (PID: 2612)
    • Creates files in the program directory

      • orcus_premium.exe (PID: 2612)
    • Drops a file with a compile date too recent

      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Reads Environment values

      • ._cache_orcus_premium.exe (PID: 2464)
    • Adds / modifies Windows certificates

      • Synaptics.exe (PID: 4016)
    • Creates files in the user directory

      • Synaptics.exe (PID: 4016)
  • INFO

    • Reads settings of System Certificates

      • ._cache_orcus_premium.exe (PID: 2464)
      • Synaptics.exe (PID: 4016)
    • Manual execution by user

      • orcus_premium.exe (PID: 2640)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 3968)
      • orcus_premium.exe (PID: 1748)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3496)
      • orcus_premium.exe (PID: 3664)
      • orcus_premium.exe (PID: 3560)
      • orcus_premium.exe (PID: 120)
      • orcus_premium.exe (PID: 1704)
      • orcus_premium.exe (PID: 3800)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 652)
    • Checks Windows Trust Settings

      • Synaptics.exe (PID: 4016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
36
Malicious processes
27
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe orcus_premium.exe #ORCUS ._cache_orcus_premium.exe orcus_premium.exe synaptics.exe #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\orcus_premium.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
568"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
652"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\desktop\orcus_premium.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
1292"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1556"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1704"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\orcus_premium.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1748"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\orcus_premium.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
1876"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2044"C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\orcus_premium.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\orcus_premium.exe
WinRAR.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2532.46075\orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2152"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
Total events
14 535
Read events
14 251
Write events
284
Delete events
0

Modification events

(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2532) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\orcus_premium.rar
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2532) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
13
Text files
2
Unknown types
3

Dropped files

PID
Process
Filename
Type
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\orcus_premium.exeexecutable
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\orcus_premium.exeexecutable
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\orcus_premium.bak2532.46690compressed
MD5:
SHA256:
2612orcus_premium.exeC:\ProgramData\Synaptics\RCXFFFE.tmpexecutable
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\orcus_premium.rarcompressed
MD5:
SHA256:
2640orcus_premium.exeC:\Users\admin\Desktop\._cache_orcus_premium.exeexecutable
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\orcus_premium.bak2532.46859compressed
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\__rar_2532.46817compressed
MD5:
SHA256:
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2532.48625\orcus_premium.exeexecutable
MD5:
SHA256:
4016Synaptics.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\646C991C2A28825F3CC56E0A1D1E3FA9binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
11
DNS requests
9
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4016
Synaptics.exe
GET
69.42.215.252:80
http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
US
malicious
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://crl.pki.goog/gsr1/gsr1.crl
US
der
1.61 Kb
whitelisted
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC04WHG3wyS9QoAAAABK3x8
US
der
472 b
whitelisted
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
2464
._cache_orcus_premium.exe
GET
200
2.16.106.171:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a0a1c65e6b1310f9
unknown
compressed
59.9 Kb
whitelisted
4016
Synaptics.exe
GET
200
2.16.106.233:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d8826548d56b5756
unknown
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2464
._cache_orcus_premium.exe
2.16.106.171:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
2464
._cache_orcus_premium.exe
3.129.187.220:13565
4.tcp.ngrok.io
US
malicious
192.168.100.2:53
whitelisted
4016
Synaptics.exe
142.250.185.78:443
docs.google.com
Google Inc.
US
whitelisted
4016
Synaptics.exe
2.16.106.233:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
4016
Synaptics.exe
69.42.215.252:80
freedns.afraid.org
Awknet Communications, LLC
US
malicious
4016
Synaptics.exe
142.250.184.195:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
4.tcp.ngrok.io
  • 3.129.187.220
malicious
xred.mooo.com
suspicious
ctldl.windowsupdate.com
  • 2.16.106.171
  • 2.16.106.233
  • 2.16.106.163
whitelisted
freedns.afraid.org
  • 69.42.215.252
malicious
docs.google.com
  • 142.250.185.78
shared
ocsp.pki.goog
  • 142.250.184.195
whitelisted
crl.pki.goog
  • 142.250.184.195
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY DNS Query to a *.ngrok domain (ngrok.io)
Misc activity
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
4 ETPRO signatures available at the full report
No debug info