File name:

Install_CUEcards_241.msi

Full analysis: https://app.any.run/tasks/22be887e-632a-44ea-9503-cc74fa9c62a8
Verdict: Malicious activity
Analysis date: August 19, 2024, 19:21:04
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1031, Number of Pages: 200, Revision Number: {43544E66-127D-4D0E-B9C6-CA3FEE4E32FD}, Title: CUEcards 2000, Author: Marcus Humann Software-Technik, Comments: Version 2.41 (Freeware), Number of Words: 2, Last Saved Time/Date: Tue Mar 6 16:42:51 2018, Last Printed: Tue Mar 6 16:42:51 2018
MD5:

87BB1CBD99CF0188ABEBB0C4F3F96478

SHA1:

E7F7391B65844991CE855B68A621FDBBEBA43694

SHA256:

9531D0A1339C5CCD366A776A82D11B7103894E48E2C06811D8E5AE26BC958BFF

SSDEEP:

49152:aay/ZpQg1m9TNeB5RO13kNb8uP2jNiUveXFabua1DtwLu+SR5dvfURXFeKbs+5gn:ieBelOi9P2eXcbJ1WLuDLvfUneuz5gcd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 6532)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6756)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2144)
    • Application launched itself

      • WinRAR.exe (PID: 2144)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 6756)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 6756)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6756)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6756)
    • Manual execution by a user

      • WinRAR.exe (PID: 2144)
      • firefox.exe (PID: 5548)
      • firefox.exe (PID: 4692)
    • Application launched itself

      • firefox.exe (PID: 5524)
      • firefox.exe (PID: 4692)
      • firefox.exe (PID: 5548)
      • firefox.exe (PID: 5880)
      • firefox.exe (PID: 4880)
      • firefox.exe (PID: 6392)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6756)
      • firefox.exe (PID: 4880)
    • Creates files in the program directory

      • WinRAR.exe (PID: 6644)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4880)
    • Reads the computer name

      • msiexec.exe (PID: 6756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1031
Pages: 200
RevisionNumber: {43544E66-127D-4D0E-B9C6-CA3FEE4E32FD}
Title: CUEcards 2000
Subject: -
Author: Marcus Humann Software-Technik
Keywords: -
Comments: Version 2.41 (Freeware)
Words: 2
ModifyDate: 2018:03:06 16:42:51
LastPrinted: 2018:03:06 16:42:51
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
203
Monitored processes
62
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs rundll32.exe no specs winrar.exe no specs winrar.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1064C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1184"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7764 -parentBuildID 20240213221259 -sandboxingKind 1 -prefsHandle 7776 -prefMapHandle 7772 -prefsLen 35248 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {fce89d48-c6d6-466d-bedc-853670c7716a} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223c8890b10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1356"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2820 -childID 1 -isForBrowser -prefsHandle 2992 -prefMapHandle 1428 -prefsLen 30714 -prefMapSize 244343 -safeMode -parentBuildID 20240213221259 -appDir "C:\Program Files\Mozilla Firefox\browser" - {df3b5915-384e-435d-bddf-1b3f4e381ae6} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223be742d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1372"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6888 -childID 8 -isForBrowser -prefsHandle 5524 -prefMapHandle 5536 -prefsLen 31616 -prefMapSize 244343 -safeMode -parentBuildID 20240213221259 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8d239614-ee7b-46bd-ac23-3f039660087a} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223c6c5cd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1920"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=13552 -childID 32 -isForBrowser -prefsHandle 6860 -prefMapHandle 6852 -prefsLen 31703 -prefMapSize 244343 -safeMode -parentBuildID 20240213221259 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c722d7c1-48c2-4a28-8501-1984216d0da8} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223b8f034d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2016"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1996 -parentBuildID 20240213221259 -prefsHandle 1932 -prefMapHandle 1924 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5b7fe683-ed66-4895-956b-ab802cf524bf} 5524 "\\.\pipe\gecko-crash-server-pipe.5524" 1f9b102a810 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2144"C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -- "CUEcards 2000.rar" "C:\Program Files (x86)\CUEcards 2000\Tips.txt" "C:\Program Files (x86)\CUEcards 2000\DHTML Export" "C:\Program Files (x86)\CUEcards 2000\Banner.jpg" "C:\Program Files (x86)\CUEcards 2000\CUEcards.chm" "C:\Program Files (x86)\CUEcards 2000\CUEcards.exe" "C:\Program Files (x86)\CUEcards 2000\Splash.jpg"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2360"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2308 -parentBuildID 20240213221259 -prefsHandle 2300 -prefMapHandle 2288 -prefsLen 30573 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {202191e4-4b0c-454e-bcf6-14467ee006f1} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223ac885110 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2768"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=10700 -childID 35 -isForBrowser -prefsHandle 6520 -prefMapHandle 8564 -prefsLen 31899 -prefMapSize 244343 -safeMode -parentBuildID 20240213221259 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cd70108f-576e-43b1-a4c0-3f0ced194549} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 223b8f03850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
70 279
Read events
69 858
Write events
389
Delete events
32

Modification events

(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000032A067FD6CF2DA01641A000070190000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000BC036AFD6CF2DA01641A000070190000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000479FA5FD6CF2DA01641A000070190000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000479FA5FD6CF2DA01641A000070190000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000010EFA7FD6CF2DA01641A000070190000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000D752AAFD6CF2DA01641A000070190000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000008F7B0EFE6CF2DA01641A000070190000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6756) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000067DF10FE6CF2DA01641A0000141B0000E80300000100000000000000000000005A56AF197E69284797C4580011BF110A00000000000000000000000000000000
(PID) Process:(6532) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000009E0918FE6CF2DA0184190000A8190000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
6
Suspicious files
177
Text files
54
Unknown types
5

Dropped files

PID
Process
Filename
Type
6756msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6756msiexec.exeC:\Windows\Temp\~DFC7D4ACB41808E5E2.TMPbinary
MD5:172E3333BA5AA0119FAF80E3CC3C8FAF
SHA256:E936AA2FD3C6C19ACF3195996279DC29228A78129A8267D39BBDF2523ECD57F9
6756msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:172E3333BA5AA0119FAF80E3CC3C8FAF
SHA256:E936AA2FD3C6C19ACF3195996279DC29228A78129A8267D39BBDF2523ECD57F9
6756msiexec.exeC:\Windows\Installer\125a3e.msiexecutable
MD5:87BB1CBD99CF0188ABEBB0C4F3F96478
SHA256:9531D0A1339C5CCD366A776A82D11B7103894E48E2C06811D8E5AE26BC958BFF
6756msiexec.exeC:\Program Files (x86)\CUEcards 2000\DHTML Export\branch.gifimage
MD5:5AAF2EDCD176EA43245D04B6612303D9
SHA256:4AD0AB27BA2F901AB96DB9EA4A593E27120EA78FAC1ADDA3E66FEEBBBEA2E01C
6756msiexec.exeC:\Program Files (x86)\CUEcards 2000\DHTML Export\DHTML Export Template.htmhtml
MD5:E5D8EFE93BE173C510CAEDDE5A60F8BC
SHA256:9F35F9BFDE74548333C85C098E575FA2B4B7CD27256D9DAE29E873727C0F8014
6756msiexec.exeC:\Program Files (x86)\CUEcards 2000\DHTML Export\plus_last.gifimage
MD5:E26E3E173DF63558AEBCE40FC2DFBD92
SHA256:CD7683B1FD4DB662BB24B1547352D07B221A58141517F0DB251645EEEA2E2F62
6756msiexec.exeC:\Program Files (x86)\CUEcards 2000\DHTML Export\minus.gifimage
MD5:60CE2F27C114D464A6F4BC81F31DFEE1
SHA256:4F8CEA23F4220DE2E2692E1241C1898AFE617DD0F14DF672D0FFF2DC58D3CD93
6756msiexec.exeC:\Windows\Installer\MSI5DA9.tmpbinary
MD5:3157B7A46F993180FB10C443BBCB7CDB
SHA256:04613BA2A71070F1D8E56C197FBCAEEA3E539B33AF1087D320469F41E6B4F645
6756msiexec.exeC:\Program Files (x86)\CUEcards 2000\CUEcards.exeexecutable
MD5:D2B46CAE43E6549FC063F23C46CC8C26
SHA256:83A4173A606245E50BA0B15B6DB7F496FCCD69769F2BC85CD1284FEF0FAA747B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
145
TCP/UDP connections
476
DNS requests
675
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7104
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7000
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1104
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4880
firefox.exe
POST
200
184.24.77.83:80
http://r11.o.lencr.org/
unknown
unknown
4880
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4880
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4880
firefox.exe
POST
200
184.24.77.83:80
http://r11.o.lencr.org/
unknown
unknown
4880
firefox.exe
POST
200
184.24.77.83:80
http://r11.o.lencr.org/
unknown
unknown
4880
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/wr2
unknown
unknown
4880
firefox.exe
POST
200
184.24.77.67:80
http://r10.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2876
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1048
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2876
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1104
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1104
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
7104
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
7104
backgroundTaskHost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.110
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.73
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
www.microsoft.com
  • 23.218.209.163
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info