File name:

Desktop.rar

Full analysis: https://app.any.run/tasks/eac3db97-1bf1-4286-ac99-9d788fd89020
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 13, 2025, 11:37:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
stealer
antivm
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

20D023F8316CBBDAF2C3D1039955D3C1

SHA1:

BF34B7244EE682D827B42844D2019F189E9E0C47

SHA256:

8FB4E752E93DF3367A37974A076B56F86BF42AE318A95A366C42E871B391937F

SSDEEP:

98304:Q3hGHG2loT4eRG3T2FqKc0E5ViHG6//qfJKXcgs92fPm0qLKqwavujdLovRoRx4z:R3Pf36YB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6244)
    • Registers / Runs the DLL via REGSVR32.EXE

      • uninstalltool_setup.tmp (PID: 6976)
    • Application was injected by another process

      • explorer.exe (PID: 4488)
    • Runs injected code in another process

      • PinToTaskbar.exe (PID: 5488)
    • Actions looks like stealing of personal data

      • UninstallTool.exe (PID: 2076)
    • Executing a file with an untrusted certificate

      • UninstallToolHelper.exe (PID: 6940)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • uninstalltool_setup.exe (PID: 6856)
      • uninstalltool_setup.exe (PID: 6952)
      • uninstalltool_setup.tmp (PID: 6976)
      • UninstallTool.exe (PID: 6576)
      • UninstallTool.exe (PID: 2076)
    • Reads security settings of Internet Explorer

      • uninstalltool_setup.tmp (PID: 6876)
      • uninstalltool_setup.tmp (PID: 6976)
      • UninstallTool.exe (PID: 2076)
    • Reads the Windows owner or organization settings

      • uninstalltool_setup.tmp (PID: 6976)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5572)
    • Drops a system driver (possible attempt to evade defenses)

      • UninstallTool.exe (PID: 6576)
    • Creates files in the driver directory

      • UninstallTool.exe (PID: 6576)
    • Reads the date of Windows installation

      • UninstallTool.exe (PID: 6652)
    • Searches for installed software

      • UninstallTool.exe (PID: 6652)
      • UninstallTool.exe (PID: 2076)
    • The process executes via Task Scheduler

      • UninstallTool.exe (PID: 2076)
    • There is functionality for VM detection antiVM strings (YARA)

      • UninstallTool.exe (PID: 2076)
    • Process drops legitimate windows executable

      • UninstallTool.exe (PID: 2076)
  • INFO

    • Manual execution by a user

      • uninstalltool_setup.exe (PID: 6856)
      • msedge.exe (PID: 1616)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6244)
      • msedge.exe (PID: 1616)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4488)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6244)
      • uninstalltool_setup.tmp (PID: 6976)
      • explorer.exe (PID: 4488)
    • Checks supported languages

      • uninstalltool_setup.exe (PID: 6856)
      • uninstalltool_setup.tmp (PID: 6876)
      • uninstalltool_setup.exe (PID: 6952)
      • uninstalltool_setup.tmp (PID: 6976)
      • PinToTaskbar.exe (PID: 5488)
    • Create files in a temporary directory

      • uninstalltool_setup.exe (PID: 6856)
      • uninstalltool_setup.exe (PID: 6952)
      • uninstalltool_setup.tmp (PID: 6976)
      • UninstallTool.exe (PID: 6576)
    • Reads the computer name

      • uninstalltool_setup.tmp (PID: 6876)
      • uninstalltool_setup.tmp (PID: 6976)
      • PinToTaskbar.exe (PID: 5488)
      • UninstallTool.exe (PID: 6576)
      • identity_helper.exe (PID: 7132)
    • Process checks computer location settings

      • uninstalltool_setup.tmp (PID: 6876)
      • uninstalltool_setup.tmp (PID: 6976)
    • The sample compiled with english language support

      • uninstalltool_setup.tmp (PID: 6976)
      • UninstallTool.exe (PID: 6576)
      • UninstallTool.exe (PID: 2076)
    • Creates files or folders in the user directory

      • UninstallTool.exe (PID: 6576)
      • UninstallTool.exe (PID: 6652)
      • explorer.exe (PID: 4488)
    • Creates files in the program directory

      • uninstalltool_setup.tmp (PID: 6976)
    • Checks proxy server information

      • UninstallTool.exe (PID: 2076)
    • Reads the software policy settings

      • UninstallTool.exe (PID: 2076)
    • Application launched itself

      • msedge.exe (PID: 1200)
      • msedge.exe (PID: 1616)
    • Sends debugging messages

      • Adobe.exe (PID: 2676)
    • Reads Environment values

      • identity_helper.exe (PID: 7132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 59163
UncompressedSize: 145973
OperatingSystem: Win32
ArchivedFileName: Adobe.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
194
Monitored processes
61
Malicious processes
4
Suspicious processes
5

Behavior graph

Click at the process to see the details
start winrar.exe uninstalltool_setup.exe uninstalltool_setup.tmp no specs uninstalltool_setup.exe uninstalltool_setup.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs pintotaskbar.exe no specs uninstalltool.exe uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe uninstalltoolhelper.exe no specs msiexec.exe no specs adobe.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x290,0x294,0x298,0x1c0,0x2b0,0x7ff8202e5fd8,0x7ff8202e5fe4,0x7ff8202e5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6400 --field-trial-handle=2324,i,9440458982381886549,5327043659662384349,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
644"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=3912 --field-trial-handle=2324,i,9440458982381886549,5327043659662384349,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1076"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5784 --field-trial-handle=2324,i,9440458982381886549,5327043659662384349,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1200"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.11&gui=trueC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeAdobe.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.11&gui=trueC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=6236 --field-trial-handle=2324,i,9440458982381886549,5327043659662384349,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7448 --field-trial-handle=2324,i,9440458982381886549,5327043659662384349,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1988"C:\Program Files\Uninstall Tool\UninstallTool.exe" C:\Program Files\Uninstall Tool\UninstallTool.exeuninstalltool_setup.tmp
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
MEDIUM
Description:
Uninstall Tool
Exit code:
0
Version:
3.7.4.5725
Modules
Images
c:\program files\uninstall tool\uninstalltool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2076"C:\Program Files\Uninstall Tool\UninstallTool.exe" /admin /taskschC:\Program Files\Uninstall Tool\UninstallTool.exe
svchost.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool
Version:
3.7.4.5725
Modules
Images
c:\program files\uninstall tool\uninstalltool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
25 312
Read events
25 095
Write events
203
Delete events
14

Modification events

(PID) Process:(4488) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000004031E
Operation:writeName:VirtualDesktop
Value:
1000000030304456A48A294F7A40804AB924005FF030B61F
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Desktop.rar
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4488) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010015000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C0000001A00000000000000630061007300650073006F007200670061006E0069007A006100740069006F006E0073002E006A00700067003E0020002000000012000000000000006300680061006E006700650077006F0072006B002E0070006E0067003E002000200000001600000000000000630069007400690065007300730074007200610074006500670079002E007200740066003E002000200000000F000000000000006800690074006C006500610064002E007200740066003E00200020000000110000000000000068006F0070006500730074006100720074002E006A00700067003E0020002000000017000000000000006D0065006D006200650072007300680069007000730074007500660066002E007200740066003E002000200000001700000000000000700072006F0070006F00730065006400700072006F007400650069006E002E007200740066003E00200020000000170000000000000070007500720070006F0073006500730069006D00700072006F00760065002E006A00700067003E0020002000000018000000000000007200650066006500720065006E0063006500730069006D0061006700650073002E0070006E0067003E002000200000000E0000000000000072006C0061007200670065002E006A00700067003E0020002000000012000000000000007400680065006900720070006C006100630065002E007200740066003E00200020000000130000000000000074006900700073006C006500610074006800650072002E007200740066003E002000200000000D00000000000000410064006F00620065002E006500780065003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001500000000000000000000000000000000000000803F0000004008000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A040110000004040000000001200000040400000803F1300000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F070000002041000080401400
Executable files
32
Suspicious files
256
Text files
136
Unknown types
0

Dropped files

PID
Process
Filename
Type
6244WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6244.7561\Adobe.exeexecutable
MD5:EF9F74563443B145529DFC6BAD0B1733
SHA256:F6E330DD78D9F7FE9667702B0C566D5885F3BB873FD6AD3582A0262EC9218EAE
4488explorer.exeC:\Users\admin\Desktop\Adobe.exeexecutable
MD5:EF9F74563443B145529DFC6BAD0B1733
SHA256:F6E330DD78D9F7FE9667702B0C566D5885F3BB873FD6AD3582A0262EC9218EAE
6244WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6244.7561\uninstalltool_setup.exeexecutable
MD5:417161BEF8A9990D7D99CD660042608D
SHA256:66B696E76AF8E72272883E22E7F5E42E168195C2E42FDDF6D9E4E59C8A003EE4
4488explorer.exeC:\Users\admin\Desktop\uninstalltool_setup.exeexecutable
MD5:417161BEF8A9990D7D99CD660042608D
SHA256:66B696E76AF8E72272883E22E7F5E42E168195C2E42FDDF6D9E4E59C8A003EE4
6976uninstalltool_setup.tmpC:\Users\admin\AppData\Local\Temp\is-M659V.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4488explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-msbinary
MD5:14A0DF6A13E5CCBBA7E422DFFA053E2F
SHA256:42E2FA98F024A98422ABB93DE5DC8986ECC9A46ACE656D5AE9EAA060E839937C
4488explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
6856uninstalltool_setup.exeC:\Users\admin\AppData\Local\Temp\is-VTJV6.tmp\uninstalltool_setup.tmpexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
6976uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\PinToTaskbarHelper.dllexecutable
MD5:4C415ADB0750FE1E1D2F52C3902274C0
SHA256:7D0A990C0B976FF4D99ABFA935EADEBCECE34E7D4E711ED86066AB7845D6A417
6976uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\unins000.exeexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
75
DNS requests
78
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5888
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5888
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2076
UninstallTool.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
2076
UninstallTool.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
4684
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2076
UninstallTool.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDfD%2FoApQz6Tjifa39Nky1P
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6072
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.18:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.21.65.154:443
www.bing.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 2.16.164.18
  • 2.16.164.106
  • 2.16.164.72
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
www.bing.com
  • 2.21.65.154
  • 2.21.65.132
  • 2.23.227.208
  • 2.23.227.202
  • 2.23.227.221
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.71
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.0
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
Process
Message
Adobe.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\Adobe.exe Architecture: x64 App host version: 8.0.11 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.11