General Info

File name

Brute53.rar

Full analysis
https://app.any.run/tasks/b6257330-90d1-427a-b74b-c7782dc5592d
Verdict
Malicious activity
Analysis date
12/6/2018, 09:43:34
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-rar
File info:
RAR archive data, v5
MD5

2255555bf63fb6a34668ee4d759e9dcd

SHA1

f94d347b5ec4dbb68d9816de0e7384c878057e30

SHA256

995c9c17c515b96081b4404d874922173ac305742807437f8913bb3215d0dab5

SSDEEP

3072:GG39hxHOWdwsc2h/El89SApGn3Sx0JdmjBJ115:b9eivc2zInixe8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
240 seconds
Additional time used
180 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes the autorun value in the registry
  • reg.exe (PID: 2664)
Application was dropped or rewritten from another process
  • 53Brute.exe (PID: 3488)
Application launched itself
  • Skype.exe (PID: 2100)
  • Skype.exe (PID: 2332)
  • Skype.exe (PID: 3416)
Uses REG.EXE to modify Windows registry
  • Skype.exe (PID: 3416)
Creates files in the user directory
  • Skype.exe (PID: 3416)
  • Skype.exe (PID: 2100)
  • Skype.exe (PID: 2332)
  • 53Brute.exe (PID: 3488)
Modifies the open verb of a shell class
  • Skype.exe (PID: 3416)
Reads CPU info
  • Skype.exe (PID: 3416)
Executable content was dropped or overwritten
  • WinRAR.exe (PID: 3588)
Starts Internet Explorer
  • 53Brute.exe (PID: 3488)
Reads internet explorer settings
  • iexplore.exe (PID: 2212)
Reads settings of System Certificates
  • Skype.exe (PID: 3416)
Dropped object may contain Bitcoin addresses
  • Skype.exe (PID: 3416)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2212)
Creates files in the user directory
  • iexplore.exe (PID: 2212)
Changes internet zones settings
  • iexplore.exe (PID: 3720)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.rar
|   RAR compressed archive (v5.0) (61.5%)
.rar
|   RAR compressed archive (gen) (38.4%)

Screenshots

Processes

Total processes
46
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start winrar.exe 53brute.exe no specs iexplore.exe iexplore.exe skype.exe skype.exe reg.exe skype.exe no specs reg.exe no specs skype.exe skype.exe no specs skype.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3588
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Brute53.rar"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
3488
CMD
"C:\Users\admin\Desktop\53Brute.exe"
Path
C:\Users\admin\Desktop\53Brute.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
53.com
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\53brute.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\program files\microsoft\skype for desktop\skype.exe

PID
3720
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
53Brute.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll

PID
2212
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3720 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msimtf.dll
c:\windows\system32\t2embed.dll
c:\windows\system32\jscript.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll

PID
3416
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" -- "skype:live:35e62eee147b8752?chat"
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
53Brute.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keytar\build\release\keytar.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\electron-ssid\build\release\electron-ssid.node
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptnet.dll

PID
2640
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
2664
CMD
C:\Windows\system32\reg.exe ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Skype for Desktop" /t REG_SZ /d "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" /f
Path
C:\Windows\system32\reg.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2332
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=CE58E52EB02A37A9671D123AFE651EA3 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=CE58E52EB02A37A9671D123AFE651EA3 --renderer-client-id=3 --mojo-platform-channel-handle=1544 /prefetch:1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\release\spellchecker.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keyboard-layout\build\release\keyboard-layout-manager.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\slimcore.node
c:\windows\system32\pdh.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\skypert.dll
c:\windows\system32\avrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\npmproxy.dll

PID
2588
CMD
C:\Windows\system32\reg.exe QUERY HKCU\Software\Microsoft\Skype /v RestartForUpdate
Path
C:\Windows\system32\reg.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2736
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\systemroot\system32\ntdll.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
2100
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=BF97EED422B53FE7A97ECF7E1781CEEA --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=1 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=BF97EED422B53FE7A97ECF7E1781CEEA --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\release\spellchecker.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keyboard-layout\build\release\keyboard-layout-manager.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\slimcore.node
c:\windows\system32\pdh.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\skypert.dll
c:\windows\system32\avrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\npmproxy.dll

PID
3272
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

Registry activity

Total events
862
Read events
798
Write events
64
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3588
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\Desktop\Brute53.rar
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3588
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{1D008CC9-F933-11E8-834A-5254004A04AF}
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E2070C000400060008002C0011003A01
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E2070C000400060008002C0011004A01
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C000400060008002C001100F601
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C000400060008002C0011002502
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C000400060008002C0011008302
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3416
Skype.exe
write
HKEY_CLASSES_ROOT\skype
URL Protocol
3416
Skype.exe
write
HKEY_CLASSES_ROOT\skype
URL:skype
3416
Skype.exe
write
HKEY_CLASSES_ROOT\skype\shell\open\command
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" -- "%1"
3416
Skype.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2664
reg.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Skype for Desktop
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe

Files activity

Executable files
2
Suspicious files
6
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
3588
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRa3588.35293\BruteEngine.dll
executable
MD5: 42602cac4048d5bdae2172af59fcd1fd
SHA256: b3c0e88c2a4bff739f863335d4c03ea2e221b82c4d2bca908456f72e5e08bd05
3588
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRa3588.35293\53Brute.exe
executable
MD5: 1c68894915b67c5ee4c43ca1b76a0ef5
SHA256: 2d22e0232f87f6173bd3c5a516c937ccb40a969f9485978701fb9dfb99f4b89e
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
text
MD5: 79099fadf7ac10846873ffff45ec4927
SHA256: 1eaca4d7e38738e7f66217162d8dd30d5147f5c81beb5ff8cd5524e3c7741117
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
binary
MD5: e6d925afc3267fc91bb4419e0154c898
SHA256: f48c3b45498718a09f9e142bc36a499ce26bb058ae7631f9452b9f6cacb1428b
3272
Skype.exe
C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\operation_log.txt
text
MD5: 87ecf58813f5d8e7d0901c3b0c0fb550
SHA256: 46ec0535eda1022d8dff3f59f7617d73a9f4723c4d67128a1a7c09d4756f5965
2100
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-1-2147483647.blog
binary
MD5: df8f2e4fe0b814e3b7f4047aa1b235fa
SHA256: c34724b2a8df144a8ec8ba99cd2a4c77d4fc9f09323465cadf65e80d691c8b14
2332
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-3994466069.blog
––
MD5:  ––
SHA256:  ––
3416
Skype.exe
C:\Users\admin\AppData\Local\Temp\4d1ef3a4-90af-4852-921a-a6a832759bac.tmp.ico
image
MD5: e946d0929470b5e6006fe9bce06171d2
SHA256: 5d9c38bd132dfae94c31b1acffe170c6b8c8988c53557b89caaf8870df34c8c9
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
text
MD5: 0d8db3d43bcb9f490169188e803314de
SHA256: 1a5cbd55803117484fa35a69d5535f9b6d9fb7d3272a585084c9f4b2fa3c4ac3
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old~RF142336.TMP
text
MD5: 0d8db3d43bcb9f490169188e803314de
SHA256: 1a5cbd55803117484fa35a69d5535f9b6d9fb7d3272a585084c9f4b2fa3c4ac3
2736
Skype.exe
C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\operation_log.txt
text
MD5: 966cf7cd748ef6841f6f46bb76bcf315
SHA256: ba663581cc0344d39cd804dcf6b553b7311c1070742f916df2ea9627aa0b3a4e
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000020.ldb
binary
MD5: 293e0f9b607cd2b0cdd018cf9d0cda80
SHA256: c5d2e32e6b4104d72815c2dd3ff491dc500a1bbd78fc2e2a44c211d340de6d9b
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
text
MD5: 7f39b22308b34b4138a09991ec4d41c5
SHA256: 31c4d714afbfab8d23ae08f061f6a5f1e46a26b0ab20795eac7d2134a55cceb6
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old~RF14176e.TMP
text
MD5: 7f39b22308b34b4138a09991ec4d41c5
SHA256: 31c4d714afbfab8d23ae08f061f6a5f1e46a26b0ab20795eac7d2134a55cceb6
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
text
MD5: 1c29859a4e69a8db5e0fbaf1b368de82
SHA256: 191250cb423c1fa15ea09cb70e6db462c0070d82053d09b3c25ba02180a9da88
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\bullet[1]
image
MD5: 0c4c086dd852704e8eeb8ff83e3b73d1
SHA256: 1cb3b6ea56c5b5decf5e1d487ad51dbb2f62e6a6c78f23c1c81fda1b64f8db16
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\background_gradient[1]
image
MD5: 20f0110ed5e4e0d5384a496e4880139b
SHA256: 1471693be91e53c2640fe7baeecbc624530b088444222d93f2815dfce1865d5b
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\info_48[1]
image
MD5: 49e0ef03e74704089a60c437085db89e
SHA256: caa140523ba00994536b33618654e379216261babaae726164a0f74157bb11ff
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\httpErrorPagesScripts[1]
text
MD5: e7ca76a3c9ee0564471671d500e3f0f3
SHA256: 58268ca71a28973b756a48bbd7c9dc2f6b87b62ae343e582ce067c725275b63c
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\errorPageStrings[1]
text
MD5: 1a0563f7fb85a678771450b131ed66fd
SHA256: eb5678de9d8f29ca6893d4e6ca79bd5ab4f312813820fe4997b009a2b1a1654c
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\ErrorPageTemplate[1]
text
MD5: f4fe1cb77e758e1ba56b8a8ec20417c5
SHA256: 8d018639281b33da8eb3ce0b21d11e1d414e59024c3689f92be8904eb5779b5f
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\unknownprotocol[1]
html
MD5: 378016e69253a0565eb7266fd032879e
SHA256: aa50a4a6a101c48addb7555f0c4ccc3eae62ffd49d2a47fb4b10c3efdfecabea
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\telegram[1].css
text
MD5: 8fe3b35433275e6759d9804c626e40c1
SHA256: 0f94ea057599252447ad881f452bd8035abde39a994fa579f92c9fe60ed09852
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\css[1].txt
text
MD5: e3ada4565626b4a5edb4b42a5c8ae586
SHA256: 7647ad188834bb8656c770434bbc23b956118eca436bfaca76da68cbad9f4bad
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\bootstrap.min[1].css
text
MD5: c2656e265ef58a9cc9f4b70b15da5fb9
SHA256: f1d083ffaa644c708f11db29707aa57c19246e6d32643b03fee3f82c17b224b3
3416
Skype.exe
C:\Users\admin\AppData\Local\Temp\98bb7db7-25d7-4a59-afd1-69697ef158e1.tmp.ico
image
MD5: 75a3d7765f2f4f8712775b10e1d18003
SHA256: 28854f198091126b6e3a57fe312a3b77c1074cd0b111aed6f7604a2467f52166
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b916037c1e115fe0.customDestinations-ms
binary
MD5: ff17e86faafb072686d650443c84a7d6
SHA256: 3ad89cb552952707f86d8bdf449fbc9e6486943d07985f49009c477595a659cb
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b916037c1e115fe0.customDestinations-ms~RF1413b5.TMP
binary
MD5: ff17e86faafb072686d650443c84a7d6
SHA256: 3ad89cb552952707f86d8bdf449fbc9e6486943d07985f49009c477595a659cb
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SGZBWIGLQMZGMXZRT4HY.temp
––
MD5:  ––
SHA256:  ––
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\brute_engin[1].htm
html
MD5: 478ac7edb25bf1d9761d5490e5a1a5b7
SHA256: 26079ceb496df25048ec2c3145658e332637e63caaf2a691d67407f7488915fb
2212
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: d1e8465946b44d06fa9d040300089bb1
SHA256: da0721f76f4f5d04b9018cf96186889e6fe763aaec80c7bd9a435a2d2387fb20
2212
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\brute_engin[1].txt
––
MD5:  ––
SHA256:  ––
3720
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[3].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
3720
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
3720
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
––
MD5:  ––
SHA256:  ––
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000023.ldb
binary
MD5: eb6bc3545f9d92d5ca3ee2641306de35
SHA256: fa23d7f6c6c06aeb5e5655b839eaf7ad96cc35a767eabd8c42cdb183c5148eb9
3416
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000021.log
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
16
DNS requests
14
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3720 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3720 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
2212 iexplore.exe 149.154.167.99:443 Telegram Messenger LLP GB unknown
2212 iexplore.exe 172.217.168.42:443 Google Inc. US whitelisted
3416 Skype.exe 13.90.95.57:443 Microsoft Corporation US whitelisted
3416 Skype.exe 23.101.156.198:443 Microsoft Corporation US whitelisted
2212 iexplore.exe 216.58.215.227:443 Google Inc. US whitelisted
2212 iexplore.exe 172.217.168.14:443 Google Inc. US whitelisted
3416 Skype.exe 152.199.19.160:443 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3416 Skype.exe 157.55.135.132:443 Microsoft Corporation US whitelisted
3416 Skype.exe 216.58.215.234:443 Google Inc. US whitelisted
3416 Skype.exe 40.79.33.178:443 Microsoft Corporation US whitelisted
3416 Skype.exe 52.114.32.8:443 Microsoft Corporation JP whitelisted
3416 Skype.exe 13.107.3.128:443 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
t.me 149.154.167.99
unknown
fonts.googleapis.com 172.217.168.42
whitelisted
telegram.org 149.154.167.99
whitelisted
get.skype.com 13.90.95.57
whitelisted
a.config.skype.com 23.101.156.198
whitelisted
fonts.gstatic.com 216.58.215.227
whitelisted
www.google-analytics.com 172.217.168.14
whitelisted
endpoint920510.azureedge.net 152.199.19.160
unknown
login.live.com 157.55.135.132
157.55.135.130
157.55.134.140
whitelisted
www.googleapis.com 216.58.215.234
172.217.168.10
172.217.168.42
whitelisted
avatar.skype.com 40.79.33.178
unknown
browser.pipe.aria.microsoft.com 52.114.32.8
whitelisted
config.edge.skype.com 13.107.3.128
whitelisted

Threats

No threats detected.

Debug output strings

Process Message
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332
Skype.exe [2640:2748:1206/084429.137:VERBOSE1:crash_service.cc(341)] client end. pid = 2332