analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

orcus_premium.rar

Full analysis: https://app.any.run/tasks/57445472-a4cb-4614-b576-9ae4ce2f6cf8
Verdict: Malicious activity
Threats:

Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.

Analysis date: January 24, 2022, 15:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
orcus
trojan
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C17C457C5B4E869466BB3F0BBB8F2801

SHA1:

923070A1DAE11B1E5D020D6532330CCEB417FCD1

SHA256:

8AF4B7F47E3848815DC1D5D47CEB8A7F68542F39222A2AB6B01BD23D6E2D7D01

SSDEEP:

24576:ohQqUHMSlgyHEmdL+ZBSeA2xkLEfoT95LarEL:PMSCyHDMVxq75Gu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ORCUS was detected

      • ._cache_orcus_premium.exe (PID: 2464)
      • ._cache_orcus_premium.exe (PID: 3684)
      • ._cache_orcus_premium.exe (PID: 1292)
      • ._cache_orcus_premium.exe (PID: 3980)
      • ._cache_orcus_premium.exe (PID: 2524)
      • ._cache_orcus_premium.exe (PID: 1876)
      • ._cache_orcus_premium.exe (PID: 568)
      • ._cache_orcus_premium.exe (PID: 3116)
      • ._cache_orcus_premium.exe (PID: 3936)
      • ._cache_orcus_premium.exe (PID: 3652)
      • ._cache_orcus_premium.exe (PID: 3036)
      • ._cache_orcus_premium.exe (PID: 3164)
      • ._cache_orcus_premium.exe (PID: 3096)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3452)
      • ._cache_orcus_premium.exe (PID: 4048)
      • ._cache_orcus_premium.exe (PID: 3240)
    • Changes the autorun value in the registry

      • orcus_premium.exe (PID: 2612)
    • Drops executable file immediately after starts

      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Application was dropped or rewritten from another process

      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2612)
      • ._cache_orcus_premium.exe (PID: 3684)
      • Synaptics.exe (PID: 4016)
      • orcus_premium.exe (PID: 2640)
      • ._cache_orcus_premium.exe (PID: 2464)
      • ._cache_orcus_premium.exe (PID: 1292)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • ._cache_orcus_premium.exe (PID: 3980)
      • ._cache_orcus_premium.exe (PID: 2524)
      • ._cache_orcus_premium.exe (PID: 1876)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 3968)
      • ._cache_orcus_premium.exe (PID: 3116)
      • ._cache_orcus_premium.exe (PID: 3936)
      • orcus_premium.exe (PID: 1748)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3496)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3652)
      • orcus_premium.exe (PID: 3560)
      • ._cache_orcus_premium.exe (PID: 3036)
      • ._cache_orcus_premium.exe (PID: 3164)
      • orcus_premium.exe (PID: 120)
      • orcus_premium.exe (PID: 3800)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 1704)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3096)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 4048)
      • ._cache_orcus_premium.exe (PID: 3240)
      • orcus_premium.exe (PID: 652)
    • Connects to CnC server

      • Synaptics.exe (PID: 4016)
    • Changes settings of System certificates

      • Synaptics.exe (PID: 4016)
  • SUSPICIOUS

    • Checks supported languages

      • orcus_premium.exe (PID: 2612)
      • WinRAR.exe (PID: 2532)
      • ._cache_orcus_premium.exe (PID: 2464)
      • orcus_premium.exe (PID: 2044)
      • Synaptics.exe (PID: 4016)
      • ._cache_orcus_premium.exe (PID: 3684)
      • ._cache_orcus_premium.exe (PID: 1292)
      • orcus_premium.exe (PID: 2640)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • ._cache_orcus_premium.exe (PID: 3980)
      • ._cache_orcus_premium.exe (PID: 2524)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 1876)
      • orcus_premium.exe (PID: 3968)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 1748)
      • ._cache_orcus_premium.exe (PID: 3116)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3496)
      • ._cache_orcus_premium.exe (PID: 3936)
      • ._cache_orcus_premium.exe (PID: 3652)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3036)
      • ._cache_orcus_premium.exe (PID: 3164)
      • orcus_premium.exe (PID: 120)
      • orcus_premium.exe (PID: 3560)
      • orcus_premium.exe (PID: 1704)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3096)
      • orcus_premium.exe (PID: 3800)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 4048)
      • ._cache_orcus_premium.exe (PID: 3240)
      • orcus_premium.exe (PID: 652)
    • Reads the computer name

      • WinRAR.exe (PID: 2532)
      • orcus_premium.exe (PID: 2612)
      • ._cache_orcus_premium.exe (PID: 2464)
      • orcus_premium.exe (PID: 2044)
      • ._cache_orcus_premium.exe (PID: 3684)
      • Synaptics.exe (PID: 4016)
      • orcus_premium.exe (PID: 2640)
      • ._cache_orcus_premium.exe (PID: 1292)
      • ._cache_orcus_premium.exe (PID: 3980)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 2524)
      • ._cache_orcus_premium.exe (PID: 1876)
      • ._cache_orcus_premium.exe (PID: 568)
      • orcus_premium.exe (PID: 3968)
      • ._cache_orcus_premium.exe (PID: 3116)
      • orcus_premium.exe (PID: 1748)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3496)
      • ._cache_orcus_premium.exe (PID: 3652)
      • ._cache_orcus_premium.exe (PID: 3936)
      • orcus_premium.exe (PID: 3664)
      • ._cache_orcus_premium.exe (PID: 3036)
      • ._cache_orcus_premium.exe (PID: 3164)
      • orcus_premium.exe (PID: 3560)
      • orcus_premium.exe (PID: 120)
      • orcus_premium.exe (PID: 1704)
      • ._cache_orcus_premium.exe (PID: 1556)
      • ._cache_orcus_premium.exe (PID: 3096)
      • orcus_premium.exe (PID: 3800)
      • ._cache_orcus_premium.exe (PID: 3452)
      • orcus_premium.exe (PID: 2480)
      • ._cache_orcus_premium.exe (PID: 4048)
      • orcus_premium.exe (PID: 652)
      • ._cache_orcus_premium.exe (PID: 3240)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2532)
      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2532)
      • orcus_premium.exe (PID: 2612)
    • Drops a file with a compile date too recent

      • orcus_premium.exe (PID: 2612)
      • orcus_premium.exe (PID: 2044)
      • orcus_premium.exe (PID: 2640)
    • Creates files in the program directory

      • orcus_premium.exe (PID: 2612)
    • Reads the date of Windows installation

      • orcus_premium.exe (PID: 2612)
    • Reads Environment values

      • ._cache_orcus_premium.exe (PID: 2464)
    • Adds / modifies Windows certificates

      • Synaptics.exe (PID: 4016)
    • Creates files in the user directory

      • Synaptics.exe (PID: 4016)
  • INFO

    • Manual execution by user

      • orcus_premium.exe (PID: 2640)
      • orcus_premium.exe (PID: 2152)
      • orcus_premium.exe (PID: 3156)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 3968)
      • orcus_premium.exe (PID: 1748)
      • orcus_premium.exe (PID: 3464)
      • orcus_premium.exe (PID: 3496)
      • orcus_premium.exe (PID: 3664)
      • orcus_premium.exe (PID: 3560)
      • orcus_premium.exe (PID: 120)
      • orcus_premium.exe (PID: 3800)
      • orcus_premium.exe (PID: 1704)
      • orcus_premium.exe (PID: 2480)
      • orcus_premium.exe (PID: 652)
    • Reads settings of System Certificates

      • ._cache_orcus_premium.exe (PID: 2464)
      • Synaptics.exe (PID: 4016)
    • Checks Windows Trust Settings

      • Synaptics.exe (PID: 4016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
36
Malicious processes
27
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe orcus_premium.exe #ORCUS ._cache_orcus_premium.exe orcus_premium.exe synaptics.exe #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs orcus_premium.exe no specs #ORCUS ._cache_orcus_premium.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2532"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\orcus_premium.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2612"C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\orcus_premium.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\orcus_premium.exe
WinRAR.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2532.46018\orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2464"C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\._cache_orcus_premium.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2532.46018\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2044"C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\orcus_premium.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\orcus_premium.exe
WinRAR.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2532.46075\orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
4016"C:\ProgramData\Synaptics\Synaptics.exe" InjUpdateC:\ProgramData\Synaptics\Synaptics.exe
orcus_premium.exe
User:
admin
Company:
Synaptics
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Driver
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3684"C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\._cache_orcus_premium.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2532.46075\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2640"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exe
Explorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\orcus_premium.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1292"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2152"C:\Users\admin\Desktop\orcus_premium.exe" C:\Users\admin\Desktop\orcus_premium.exeExplorer.EXE
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
3980"C:\Users\admin\Desktop\._cache_orcus_premium.exe" C:\Users\admin\Desktop\._cache_orcus_premium.exe
orcus_premium.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_orcus_premium.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
14 535
Read events
14 251
Write events
0
Delete events
0

Modification events

No data
Executable files
9
Suspicious files
13
Text files
2
Unknown types
3

Dropped files

PID
Process
Filename
Type
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\orcus_premium.rarcompressed
MD5:3449248CBCF69EA4C4EB2B50A70E34C8
SHA256:6DC6D3D29A21B8C39358C0A68D688D929264893E6B7DC5D293A4E8C6C2A57DAA
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\__rar_2532.46634compressed
MD5:3449248CBCF69EA4C4EB2B50A70E34C8
SHA256:6DC6D3D29A21B8C39358C0A68D688D929264893E6B7DC5D293A4E8C6C2A57DAA
2464._cache_orcus_premium.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:F2FBB01DC3002C99D9E8676F35BA81E6
SHA256:74F9E1593BA3C0E90749407D50E4E79A8E5A73356ED2CB89FCE48B97EBCB41CE
2612orcus_premium.exeC:\ProgramData\Synaptics\Synaptics.exeexecutable
MD5:28DCEEF73DCF576AFA2F57E55F1170F4
SHA256:49DC2A414921650BA62FDBA2B7A05013E451426D11C64464EFACF54610DB21FC
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\__rar_2532.46817compressed
MD5:7040A02EC1BF710A794E304FC6770FE1
SHA256:991D82A7C824CDDE3C59B09870692114260AD9B3E6D365C71B73E77350BAF58E
2612orcus_premium.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46018\._cache_orcus_premium.exeexecutable
MD5:0498F32DD9F785E3B29001C47BCEF7F2
SHA256:B5A9E6D552748C0E1106DF77AA951CD48DEB4A3AF5F4F5EAC5DF7740B2C6C508
4016Synaptics.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0EF9535DC4321E362ADE7D3F63A47968
SHA256:4A6F9B9BE1A8504BAC51382BD18CF3D373AF3416E422C7AC97F462073B7D9B8F
2044orcus_premium.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2532.46075\._cache_orcus_premium.exeexecutable
MD5:0498F32DD9F785E3B29001C47BCEF7F2
SHA256:B5A9E6D552748C0E1106DF77AA951CD48DEB4A3AF5F4F5EAC5DF7740B2C6C508
2640orcus_premium.exeC:\Users\admin\Desktop\._cache_orcus_premium.exeexecutable
MD5:0498F32DD9F785E3B29001C47BCEF7F2
SHA256:B5A9E6D552748C0E1106DF77AA951CD48DEB4A3AF5F4F5EAC5DF7740B2C6C508
2532WinRAR.exeC:\Users\admin\AppData\Local\Temp\orcus_premium.bak2532.46859compressed
MD5:3449248CBCF69EA4C4EB2B50A70E34C8
SHA256:6DC6D3D29A21B8C39358C0A68D688D929264893E6B7DC5D293A4E8C6C2A57DAA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
11
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4016
Synaptics.exe
GET
69.42.215.252:80
http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
US
whitelisted
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://crl.pki.goog/gsr1/gsr1.crl
US
der
1.61 Kb
whitelisted
2464
._cache_orcus_premium.exe
GET
200
2.16.106.171:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a0a1c65e6b1310f9
unknown
compressed
59.9 Kb
whitelisted
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC04WHG3wyS9QoAAAABK3x8
US
der
472 b
whitelisted
4016
Synaptics.exe
GET
200
2.16.106.233:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d8826548d56b5756
unknown
compressed
4.70 Kb
whitelisted
4016
Synaptics.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2464
._cache_orcus_premium.exe
2.16.106.171:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
2464
._cache_orcus_premium.exe
3.129.187.220:13565
4.tcp.ngrok.io
US
malicious
4016
Synaptics.exe
142.250.185.78:443
docs.google.com
Google Inc.
US
whitelisted
4016
Synaptics.exe
69.42.215.252:80
freedns.afraid.org
Awknet Communications, LLC
US
malicious
192.168.100.2:53
whitelisted
4016
Synaptics.exe
2.16.106.233:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
4016
Synaptics.exe
142.250.184.195:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
4.tcp.ngrok.io
  • 3.129.187.220
malicious
xred.mooo.com
suspicious
ctldl.windowsupdate.com
  • 2.16.106.171
  • 2.16.106.233
  • 2.16.106.163
whitelisted
freedns.afraid.org
  • 69.42.215.252
whitelisted
docs.google.com
  • 142.250.185.78
shared
ocsp.pki.goog
  • 142.250.184.195
whitelisted
crl.pki.goog
  • 142.250.184.195
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY DNS Query to a *.ngrok domain (ngrok.io)
Misc activity
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
4 ETPRO signatures available at the full report
No debug info