General Info

File name

8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe

Full analysis
https://app.any.run/tasks/4eabc327-2625-4022-b57f-c57d41b4a196
Verdict
Malicious activity
Analysis date
15/01/2022, 01:46:47
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
MS-DOS executable, MZ for MS-DOS
MD5

e4a624c0559a614dae75c90e7b515e09

SHA1

633c307f61509ffb09cf55f56f905b80e0705f6b

SHA256

8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9

SSDEEP

24576:PFOazsem63blG+KD3DeulpW/g1gIz6N5Fzqr/+KbLjRWPa4FlBORshGRJxMDdq:tLm6LQxlE/XV5Ir+Kn8a4FlBOyhMxq4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 11.0.9600.19596 KB4534251
  • Adobe Acrobat Reader DC (20.013.20064)
  • Adobe Flash Player 32 ActiveX (32.0.0.453)
  • Adobe Flash Player 32 NPAPI (32.0.0.453)
  • Adobe Flash Player 32 PPAPI (32.0.0.453)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.74)
  • FileZilla Client 3.51.0 (3.51.0)
  • Google Chrome (86.0.4240.198)
  • Google Update Helper (1.3.36.31)
  • Java 8 Update 271 (8.0.2710.9)
  • Java Auto Updater (2.8.271.9)
  • Microsoft .NET Framework 4.5.2 (4.5.51209)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 83.0 (x86 en-US) (83.0)
  • Mozilla Maintenance Service (83.0.0.7621)
  • Notepad++ (32-bit x86) (7.9.1)
  • Opera 12.15 (12.15.1748)
  • QGA (2.14.33)
  • Skype version 8.29 (8.29)
  • VLC media player (3.0.11)
  • WinRAR 5.91 (32-bit) (5.91.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Hyphenation Parent Package English
  • IE Spelling Parent Package English
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • InternetExplorer Package TopLevel
  • KB2479943
  • KB2491683
  • KB2506212
  • KB2506928
  • KB2532531
  • KB2533552
  • KB2533623
  • KB2534111
  • KB2545698
  • KB2547666
  • KB2552343
  • KB2560656
  • KB2564958
  • KB2574819
  • KB2579686
  • KB2585542
  • KB2604115
  • KB2620704
  • KB2621440
  • KB2631813
  • KB2639308
  • KB2640148
  • KB2653956
  • KB2654428
  • KB2656356
  • KB2660075
  • KB2667402
  • KB2676562
  • KB2685811
  • KB2685813
  • KB2685939
  • KB2690533
  • KB2698365
  • KB2705219
  • KB2719857
  • KB2726535
  • KB2727528
  • KB2729094
  • KB2729452
  • KB2731771
  • KB2732059
  • KB2736422
  • KB2742599
  • KB2750841
  • KB2758857
  • KB2761217
  • KB2770660
  • KB2773072
  • KB2786081
  • KB2789645
  • KB2799926
  • KB2800095
  • KB2807986
  • KB2808679
  • KB2813347
  • KB2813430
  • KB2820331
  • KB2834140
  • KB2836942
  • KB2836943
  • KB2840631
  • KB2843630
  • KB2847927
  • KB2852386
  • KB2853952
  • KB2857650
  • KB2861698
  • KB2862152
  • KB2862330
  • KB2862335
  • KB2864202
  • KB2868038
  • KB2871997
  • KB2872035
  • KB2884256
  • KB2891804
  • KB2893294
  • KB2893519
  • KB2894844
  • KB2900986
  • KB2908783
  • KB2911501
  • KB2912390
  • KB2918077
  • KB2919469
  • KB2923545
  • KB2931356
  • KB2937610
  • KB2943357
  • KB2952664
  • KB2968294
  • KB2970228
  • KB2972100
  • KB2972211
  • KB2973112
  • KB2973201
  • KB2977292
  • KB2978120
  • KB2978742
  • KB2984972
  • KB2984976
  • KB2984976 SP1
  • KB2985461
  • KB2991963
  • KB2992611
  • KB2999226
  • KB3004375
  • KB3006121
  • KB3006137
  • KB3010788
  • KB3011780
  • KB3013531
  • KB3019978
  • KB3020370
  • KB3020388
  • KB3021674
  • KB3021917
  • KB3022777
  • KB3023215
  • KB3030377
  • KB3031432
  • KB3035126
  • KB3037574
  • KB3042058
  • KB3045685
  • KB3046017
  • KB3046269
  • KB3054476
  • KB3055642
  • KB3059317
  • KB3060716
  • KB3061518
  • KB3067903
  • KB3068708
  • KB3071756
  • KB3072305
  • KB3074543
  • KB3075226
  • KB3078667
  • KB3080149
  • KB3086255
  • KB3092601
  • KB3093513
  • KB3097989
  • KB3101722
  • KB3102429
  • KB3102810
  • KB3107998
  • KB3108371
  • KB3108664
  • KB3109103
  • KB3109560
  • KB3110329
  • KB3115858
  • KB3118401
  • KB3122648
  • KB3123479
  • KB3126587
  • KB3127220
  • KB3133977
  • KB3137061
  • KB3138378
  • KB3138612
  • KB3138910
  • KB3139398
  • KB3139914
  • KB3140245
  • KB3147071
  • KB3150220
  • KB3150513
  • KB3155178
  • KB3156016
  • KB3159398
  • KB3161102
  • KB3161949
  • KB3170735
  • KB3172605
  • KB3179573
  • KB3184143
  • KB3185319
  • KB4019990
  • KB4040980
  • KB4474419
  • KB4490628
  • KB4524752
  • KB4532945
  • KB4536952
  • KB4567409
  • KB958488
  • KB976902
  • KB982018
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • Package 21 for KB2984976
  • Package 38 for KB2984976
  • Package 45 for KB2984976
  • Package 59 for KB2984976
  • Package 7 for KB2984976
  • Package 76 for KB2984976
  • PlatformUpdate Win7 SRV08R2 Package TopLevel
  • ProfessionalEdition
  • RDP BlueIP Package TopLevel
  • RDP WinIP Package TopLevel
  • RollupFix
  • UltimateEdition
  • WUClient SelfUpdate ActiveX
  • WUClient SelfUpdate Aux TopLevel
  • WUClient SelfUpdate Core TopLevel
  • WinMan WinIP Package TopLevel

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Drops executable file immediately after starts
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
  • explorer.exe (PID: 1292)
  • icsys.icn.exe (PID: 2616)
  • spoolsv.exe (PID: 2144)
Changes Windows auto-update feature
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Disables Windows Defender
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Changes settings of System certificates
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Changes the autorun value in the registry
  • explorer.exe (PID: 1292)
  • svchost.exe (PID: 2256)
Uses Task Scheduler to run other applications
  • svchost.exe (PID: 2256)
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 3572)
  • schtasks.exe (PID: 832)
Reads the computer name
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
  • svchost.exe (PID: 2256)
Checks supported languages
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
  • icsys.icn.exe (PID: 2616)
  • explorer.exe (PID: 1292)
  • svchost.exe (PID: 2256)
  • spoolsv.exe (PID: 2144)
  • spoolsv.exe (PID: 3580)
Executable content was dropped or overwritten
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
  • icsys.icn.exe (PID: 2616)
  • explorer.exe (PID: 1292)
  • spoolsv.exe (PID: 2144)
Starts application with an unusual extension
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
Creates files in the Windows directory
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
  • icsys.icn.exe (PID: 2616)
  • explorer.exe (PID: 1292)
  • spoolsv.exe (PID: 2144)
Drops a file with too old compile date
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
Starts itself from another location
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe (PID: 3948)
  • icsys.icn.exe (PID: 2616)
  • explorer.exe (PID: 1292)
  • spoolsv.exe (PID: 2144)
  • svchost.exe (PID: 2256)
Creates executable files which already exist in Windows
  • icsys.icn.exe (PID: 2616)
  • spoolsv.exe (PID: 2144)
Adds / modifies Windows certificates
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Removes files from Windows directory
  • icsys.icn.exe (PID: 2616)
  • explorer.exe (PID: 1292)
  • spoolsv.exe (PID: 2144)
Executed via COM
  • vdsldr.exe (PID: 2752)
Executed as Windows Service
  • vds.exe (PID: 700)
Creates or modifies windows services
  • svchost.exe (PID: 2256)
Reads settings of System Certificates
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Checks Windows Trust Settings
  • 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� (PID: 4020)
Checks supported languages
  • vdsldr.exe (PID: 2752)
  • vds.exe (PID: 700)
  • schtasks.exe (PID: 3572)
  • schtasks.exe (PID: 832)
Reads the computer name
  • vds.exe (PID: 700)
  • vdsldr.exe (PID: 2752)
  • schtasks.exe (PID: 3572)
  • schtasks.exe (PID: 832)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2013:04:01 09:08:22+02:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
106496
InitializedDataSize:
12288
UninitializedDataSize:
null
EntryPoint:
0x290c
OSVersion:
4
ImageVersion:
1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.0
ProductVersionNumber:
1.0.0.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
ProductName:
Project1
FileVersion:
1
ProductVersion:
1
InternalName:
TJprojMain
OriginalFileName:
TJprojMain.exe
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
01-Apr-2013 07:08:22
Detected languages
English - United States
ProductName:
Project1
FileVersion:
1.00
ProductVersion:
1.00
InternalName:
TJprojMain
OriginalFilename:
TJprojMain.exe
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000B8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
01-Apr-2013 07:08:22
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000191D4 0x0001A000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.7348
.data 0x0001B000 0x0000180C 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x0001D000 0x000013F0 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.20063
Resources
1

30001

Imports
    MSVBVM60.DLL

Exports

    No exports.

Screenshots

Processes

Total processes
53
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

+
drop and start start 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe no specs 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� icsys.icn.exe vdsldr.exe no specs vds.exe no specs explorer.exe spoolsv.exe svchost.exe spoolsv.exe no specs schtasks.exe no specs schtasks.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3204
CMD
"C:\Users\admin\AppData\Local\Temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe"
Path
C:\Users\admin\AppData\Local\Temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe

PID
3948
CMD
"C:\Users\admin\AppData\Local\Temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe"
Path
C:\Users\admin\AppData\Local\Temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sxs.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
c:\windows\resources\themes\icsys.icn.exe

PID
4020
CMD
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
Path
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
Indicators
Parent process
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
User
admin
Integrity Level
HIGH
Version:
Company
Akeo Consulting
Description
Rufus
Version
3.17.1846
Modules
Image
c:\windows\system32\gdi32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcrypt.dll
c:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\msctf.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dsuiext.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\dssec.dll
c:\windows\system32\samcli.dll
c:\windows\system32\vds_ps.dll
c:\windows\system32\nsi.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\dfscli.dll
c:\windows\system32\riched20.dll
c:\windows\system32\atl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\gpedit.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\wininet.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\webio.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\duser.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\dui70.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\userenv.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\en-us\shell32.dll.mui
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll

PID
2616
CMD
C:\Windows\Resources\Themes\icsys.icn.exe
Path
C:\Windows\Resources\Themes\icsys.icn.exe
Indicators
Parent process
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\resources\themes\icsys.icn.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\cryptsp.dll
c:\windows\resources\themes\explorer.exe
c:\windows\system32\psapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
2752
CMD
C:\Windows\System32\vdsldr.exe -Embedding
Path
C:\Windows\System32\vdsldr.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Virtual Disk Service Loader
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vdsldr.exe
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\atl.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msctf.dll
c:\windows\system32\vdsutil.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\nsi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\vds_ps.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\srvcli.dll

PID
700
CMD
C:\Windows\System32\vds.exe
Path
C:\Windows\System32\vds.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Virtual Disk Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\user32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vdsutil.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\lpk.dll
c:\windows\system32\untfs.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\atl.dll
c:\windows\system32\netutils.dll
c:\windows\system32\uexfat.dll
c:\windows\system32\ulib.dll
c:\windows\system32\ufat.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\vds_ps.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msctf.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\fmifs.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ifsutil.dll
c:\windows\system32\osuninst.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\uudf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\vds.exe
c:\windows\system32\vdsdyn.dll
c:\windows\system32\vdsbas.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vdsvd.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\wbemcomn2.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\hbaapi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\iscsidsc.dll
c:\windows\system32\iscsium.dll
c:\windows\system32\tbs.dll

PID
1292
CMD
c:\windows\resources\themes\explorer.exe
Path
c:\windows\resources\themes\explorer.exe
Indicators
Parent process
icsys.icn.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\msvbvm60.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rsaenh.dll
c:\windows\resources\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\apphelp.dll
c:\windows\resources\themes\explorer.exe
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\user32.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\psapi.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptsp.dll

PID
2144
CMD
c:\windows\resources\spoolsv.exe SE
Path
c:\windows\resources\spoolsv.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\ntdll.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\msctf.dll
c:\windows\resources\spoolsv.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\resources\svchost.exe
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll

PID
2256
CMD
c:\windows\resources\svchost.exe
Path
c:\windows\resources\svchost.exe
Indicators
Parent process
spoolsv.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\ntdll.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sxs.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rsaenh.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\resources\svchost.exe
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\schtasks.exe
c:\windows\resources\spoolsv.exe

PID
3580
CMD
c:\windows\resources\spoolsv.exe PR
Path
c:\windows\resources\spoolsv.exe
Indicators
No indicators
Parent process
svchost.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
1.00
Modules
Image
c:\windows\system32\uxtheme.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\lpk.dll
c:\windows\system32\sxs.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\resources\spoolsv.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\msctf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\shlwapi.dll

PID
3572
CMD
schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 01:48 /f
Path
C:\Windows\system32\schtasks.exe
Indicators
No indicators
Parent process
svchost.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\clbcatq.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\ole32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\usp10.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll

PID
832
CMD
schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 01:49 /f
Path
C:\Windows\system32\schtasks.exe
Indicators
No indicators
Parent process
svchost.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\sspicli.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\imm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sechost.dll

Registry activity

Total events
6498
Read events
0
Write events
73
Delete events
28

Modification events

PID
Process
Operation
Key
Name
Value
3948
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
write
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Explorer\Process
LO
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft\Windows\CurrentVersion\Policies
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft\Windows\CurrentVersion
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows Defender
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft\Windows
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}User
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
(default)
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
LanguageList
en-US
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDriveTypeAutorun
158
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DFC64576-A972-4D9E-B4F9-DD86B0576EC1}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Akeo Consulting\Rufus
CommCheck64
6DEB130000000000
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Akeo Consulting\Rufus
Locale
en-US
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Akeo Consulting\Rufus
UpdateCheckInterval
86400
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadNetworkName
Network 4
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionReason
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
30E35DC7B109D801
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionReason
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
D6805BC7B109D801
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecision
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecision
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
D6805BC7B109D801
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
30E35DC7B109D801
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Blob
0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Blob
5C0000000100000004000000001000001900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA662000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C60B000000010000001A0000004900530052004700200052006F006F007400200058003100000014000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E1D000000010000001000000073B6876195F5D18E048510422AEF04E309000000010000000C000000300A06082B06010505070301030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E80F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F630400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E20000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
write
HKEY_CURRENT_USER\Software\Akeo Consulting\Rufus
LastUpdateCheck
A2B8F21703000000
2616
icsys.icn.exe
write
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Explorer\Process
LO
1
1292
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
1292
explorer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Svchost
c:\windows\resources\svchost.exe RO
1292
explorer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Explorer
c:\windows\resources\themes\explorer.exe RO
2256
svchost.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
2256
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Explorer
c:\windows\resources\themes\explorer.exe RO
2256
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Svchost
c:\windows\resources\svchost.exe RO
2256
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Schedule
Start
2
2256
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess
Start
4

Files activity

Executable files
5
Suspicious files
15
Text files
4
Unknown types
5

Dropped files

PID
Process
Filename
Type
2144
spoolsv.exe
C:\windows\resources\svchost.exe
executable
MD5: 56f0953c343d1a69a3101b12ea5a7c29
SHA256: 9688a7bad65ef4a9272b330e3ea64885913bd79467ad69b2e7f03eea4460f1bd
3948
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
C:\users\admin\appdata\local\temp\8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
executable
MD5: 9ac5f5010cd28acfd7fb00b4e2fc1310
SHA256: 6d362897059df29d9674112a43e68dbc549ba4c25e7036dd9fae7c92bfafda02
1292
explorer.exe
C:\windows\resources\spoolsv.exe
executable
MD5: e1a7bab3a440aa0684318b6a1d367a0c
SHA256: 2ea6cdf98cb9cc4cfd72abf8fe04532cc95196f59112079774da593a657710c8
2616
icsys.icn.exe
C:\windows\resources\themes\explorer.exe
executable
MD5: 5421257c6b2fb53bc65f6c59ff68ba0f
SHA256: 83ccd138f55becdadb204c00c4ba31f82973c2c69d4ec67a4110677686011c03
3948
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
C:\Windows\Resources\Themes\icsys.icn.exe
executable
MD5: 1a7463500c06544a24f90efc898a2c24
SHA256: c63e40e2f11c7c01991d5e73a1fd9e2722685feae86a12405d899cddee9f76d7
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB
der
MD5: 47396d1f83885b122f30d2d498c9ed2a
SHA256: ad4f35faf489dd92588539892a4ee173c84290d3b2118b21c6283d269db68f5d
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB
binary
MD5: 3892b34312e369a022fbf1495a22feaa
SHA256: 7eefb4981b3f2e37e495fc3d1b718378d2c239c949375a93fa749dee333c4673
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2A7611428D62805A3E4E5BC4103D82E4_D0FA13DADFB59BDF00C474952E166CC1
der
MD5: 74ba1d40ce03de4a7241db2a4705a38b
SHA256: 0ba2a020a9932a123d946e614a115681deb6297ecb585fcf8d2639e8cf496bd8
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\12B578593FDE07EC53D020B1D5DEBF3B_5D74C2DB556F94499BCD6D74A36958A3
der
MD5: 08be4738a45b45b44770334cc225eb1f
SHA256: 10d6234a21679564bf2ccacde3c00f23076c2719e8f5fb7201308c60bcf24465
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Rufus_win.ver[1].sig
binary
MD5: 180a08a677e0c683c1e83d2fa7caeed7
SHA256: d0f5b3a77175e869e63b300fe6836997a353a3aad5660e9af34543dbf42d1dd9
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Fido[1].ver
text
MD5: c3f5c67e83efb5efe9fcf66a99d4040f
SHA256: 17f63b429debfacca5bda1c0c3277c13a9768a1335d440cd4bdd2522d840a366
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\12B578593FDE07EC53D020B1D5DEBF3B_5D74C2DB556F94499BCD6D74A36958A3
binary
MD5: 982a82b10005dfd442c991cf4e796e46
SHA256: 9e14f954800a83c78a967ae404b484a7068bc7d9820650dcbcc921f49a9ee944
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751
binary
MD5: 880871146066da8c4b8b5bdc8bf012a5
SHA256: 07fe7764d62af8f912cda1d49032112fab633005153f5baf474dba01e1a1ed22
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Rufus_win[1].ver
text
MD5: 900c61b94c0725c19de73fb8f9386fc7
SHA256: dd2efaca4ce99e72b81fa383d04afa686f7caae114ba7a61632fb959d378d28c
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2A7611428D62805A3E4E5BC4103D82E4_D0FA13DADFB59BDF00C474952E166CC1
binary
MD5: a51fc30dfb727bc9abfb64a7e8b78cc1
SHA256: ff6de893b16c0633e3cfb9baa726c03ebe4767ec270a02e97d4cf0f1e52b0b55
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
compressed
MD5: acaeda60c79c6bcac925eeb3653f45e0
SHA256: 6b0ceccf0103afd89844761417c1d23acc41f8aebf3b7230765209b61eee5658
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751
der
MD5: 54e9306f95f32e50ccd58af19753d929
SHA256: 45f94dceb18a8f738a26da09ce4558995a4fe02b971882e8116fc9b59813bb72
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
compressed
MD5: f7dcb24540769805e5bb30d193944dce
SHA256: 6b88c6ac55bbd6fea0ebe5a760d1ad2cfce251c59d0151a1400701cb927e36ea
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Temp\Cab185A.tmp
compressed
MD5: acaeda60c79c6bcac925eeb3653f45e0
SHA256: 6b0ceccf0103afd89844761417c1d23acc41f8aebf3b7230765209b61eee5658
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Temp\Tar185B.tmp
cat
MD5: d99661d0893a52a0700b8ae68457351a
SHA256: bdd5111162a6fa25682e18fa74e37e676d49cafcb5b7207e98e5256d1ef0d003
2616
icsys.icn.exe
C:\Users\admin\AppData\Local\Temp\~DF6C614ED214349225.TMP
binary
MD5: 55e6d7577378462aaf58ed8230a10380
SHA256: 0ce892827f47c913f3ba69e005565c169174e9c73591ac2e61886fd282d50884
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
binary
MD5: b9e8fe504eeeeac340af9e0bf31a7cd4
SHA256: b3d9e4ac3c595b3a42880dae9d1fdc5474705a77fa0411a8cbea3e1d641c3511
3580
spoolsv.exe
C:\Users\admin\AppData\Local\Temp\~DF80342740D2C63CCB.TMP
binary
MD5: e952864394d99de737fb5a367d813fea
SHA256: 3d7a9cd7c94d3ef2099ed181f7bbcfc97855681413507f9f3bb36e691080ed69
3948
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe
C:\Users\admin\AppData\Local\Temp\~DFC134D08C079B3757.TMP
binary
MD5: 55e6d7577378462aaf58ed8230a10380
SHA256: 0ce892827f47c913f3ba69e005565c169174e9c73591ac2e61886fd282d50884
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
binary
MD5: db167d62a73c72b80b363e1a99f13585
SHA256: 814944c29f50535be56b35afc1cedf579a4ff4dace19a13bbd430530efc58d86
2144
spoolsv.exe
C:\Users\admin\AppData\Local\Temp\~DFFBF9CA35B9EB2823.TMP
binary
MD5: e952864394d99de737fb5a367d813fea
SHA256: 3d7a9cd7c94d3ef2099ed181f7bbcfc97855681413507f9f3bb36e691080ed69
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Windows\System32\GroupPolicy\Machine\Registry.pol
binary
MD5: 377ac641cf4f9667421e54d62a25bd4c
SHA256: f25a5a5aba722fc2f09a1086a132aeebdbcc17adcbbdbde1a7ae960db97dbd37
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Windows\System32\GroupPolicy\gpt.ini
text
MD5: fed929ae34422010496b5b4a1827a501
SHA256: 2dda40a266eca9ddd736701efa24c6fe186edd6737db7bf52bffe32d614667ed
4020
8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe�
C:\Users\admin\AppData\Local\Temp\RufEB0F.tmp
text
MD5: f3b6df0fd4f83167c2f6408b4e497361
SHA256: b6dc3c02b1a6098a12bf23632b1c897666e3b41140aeee9d6075d2c4e5735659

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
6
TCP/UDP connections
15
DNS requests
6
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 8.253.204.121:80 http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9b2e1c393cb1c8a US
compressed
whitelisted
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 8.253.204.121:80 http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6673e19e61d5b752 US
compressed
whitelisted
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 23.45.105.185:80 http://x1.c.lencr.org/ NL
der
whitelisted
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAZnA1u7FP1jr8DWqFNO%2FhY%3D US
der
shared
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTGMlruL6P9M9B3if1rTM7wyj%2FQKQQUUGGmoNI1xBEqII0fD6xC8M0pz0sCEA6L83cNktGW8Lth%2BTxBZr4%3D US
der
shared
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D US
der
shared

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 8.253.204.121:80 Global Crossing US malicious
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 23.45.105.185:80 Akamai International B.V. NL unknown
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 140.82.121.3:443 US suspicious
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 185.199.111.153:443 GitHub, Inc. NL shared
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
4020 8e156f615ed8bf61f64cc940d3493c1d31fded9beb66fcfa31affff190fc5de9.exe� 185.199.108.133:443 GitHub, Inc. NL malicious

DNS requests

Domain IP Reputation
rufus.ie 185.199.111.153
185.199.108.153
185.199.109.153
185.199.110.153
malicious
ctldl.windowsupdate.com 8.253.204.121
67.27.158.254
8.248.135.254
8.248.143.254
67.27.233.254
whitelisted
x1.c.lencr.org 23.45.105.185
whitelisted
github.com 140.82.121.3
shared
ocsp.digicert.com 93.184.220.29
shared
objects.githubusercontent.com 185.199.108.133
185.199.110.133
185.199.111.133
185.199.109.133
malicious

Threats

No threats detected.

Debug output strings

Process Message
–– Binary executable is signed by 'Akeo Consulting'
–– *** Rufus init ***
–– Will use settings from registry
–– embedded.loc(762): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'de-DE'
–– embedded.loc(4368): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: extracted data to 'C:\Users\admin\AppData\Local\Temp\RufEB0F.tmp'
–– localization: found locale 'ar-SA'
–– localization: found locale 'fa-IR'
–– localization: found locale 'hu-HU'
–– localization: found locale 'id-ID'
–– localization: found locale 'sv-SE'
–– localization: found locale 'it-IT'
–– embedded.loc(408): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'ko-KR'
–– embedded.loc(8329): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'lt-LT'
–– localization: found locale 'fr-FR'
–– localization: found locale 'da-DK'
–– embedded.loc(5089): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'sr-SP'
–– localization: found locale 'sl-SI'
–– localization: found locale 'th-TH'
–– loc file not found in current directory - embedded one will be used
–– embedded.loc(7622): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'nb-NO'
–– localization: found locale 'pt-BR'
–– localization: found locale 'pl-PL'
–– localization: found locale 'en-US'
–– localization: found locale 'ja-JP'
–– localization: found locale 'ro-RO'
–– localization: found locale 'ru-RU'
–– localization: found locale 'bg-BG'
–– localization: found locale 'fi-FI'
–– localization: found locale 'pt-PT'
–– localization: found locale 'vi-VN'
–– localization: found locale 'nl-NL'
–– localization: found locale 'lv-LV'
–– localization: found locale 'uk-UA'
–– embedded.loc(13386): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– embedded.loc(10108): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'es-ES'
–– localization: found locale 'ms-MY'
–– localization: initializing default message table
–– localization: found locale 'tr-TR'
–– localization: found locale 'zh-TW'
–– localization: found locale 'hr-HR'
–– embedded.loc(2219): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'he-IL'
–– embedded.loc(9042): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'cs-CZ'
–– localization: found locale 'el-GR'
–– embedded.loc(9752): the version of this translation is older than the base one and may result in some messages not being properly translated. If you are the translator, please update your translation with the changes that intervened between v3.5 and v3.14. See https://github.com/pbatard/rufus/blob/master/res/loc/ChangeLog.txt
–– localization: found locale 'sk-SK'
–– Note: UAC is active
–– localization: found locale 'zh-CN'
–– Rufus x86 v3.17.1846
–– Windows version: Windows 7 SP1 32 bit
–– Will use default UI locale 0x0409 SetLGP: Successfully set NoDriveTypeAutorun policy to 0x0000009E Localization set to 'en-US'
–– 0 devices found
–– Syslinux versions: 4.07/2013-07-25, 6.04/pre1
–– Grub versions: 0.4.6a, 2.06
–– System locale ID: 0x0409 (en-US)
–– Checking release channel...
–– Checking for Rufus updates...
–– No new release version found.