| File name: | setup.exe |
| Full analysis: | https://app.any.run/tasks/ce246d4d-7162-410f-bd69-bbb325ee69a9 |
| Verdict: | Malicious activity |
| Analysis date: | June 21, 2025, 17:52:00 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | EB6B766DF4D16131DAC68326A7F92AF8 |
| SHA1: | 3CD29768D94111625B2FDB822AD6A23159744F01 |
| SHA256: | 9F223F9E7562914E580D94DAC4E582D0705B4AEDD1AA8B49FE9CADE59F8A4587 |
| SSDEEP: | 12288:tSUQLpdw6GRg1NHNizch6cIcfbNXytqZZrAttJVVVVVVVVVVVVVVVVVVVOVVVVVB:tSUsdw6GRQSzo3XQOpma |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:04:06 20:31:00+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.24 |
| CodeSize: | 383488 |
| InitializedDataSize: | 168448 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x37d3e |
| OSVersion: | 5.1 |
| ImageVersion: | 10 |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 16.0.31206.173 |
| ProductVersionNumber: | 16.0.31206.173 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | - |
| FileDescription: | Setup |
| FileVersion: | 16.0.31206.173 built by: D16.10 |
| InternalName: | setup.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | setup.exe |
| ProductName: | - |
| ProductVersion: | 16.0.31206.173 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: ClickOnce Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 1200 | C:\WINDOWS\system32\DllHost.exe /Processid:{49F171DD-B51A-40D3-9A6C-52D674CC729D} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2808 | "C:\Users\admin\AppData\Local\Apps\2.0\ZKHX2ZCG.C22\B92ETG4B.MWP\eade..tion_d9abb6dbd638d01c_0001.0000_1815fb6e6d2f4c45\EADesktop.exe" | C:\Users\admin\AppData\Local\Apps\2.0\ZKHX2ZCG.C22\B92ETG4B.MWP\eade..tion_d9abb6dbd638d01c_0001.0000_1815fb6e6d2f4c45\EADesktop.exe | dfsvc.exe | ||||||||||||
User: admin Company: eSSENTIAL Accessibility Inc. Integrity Level: MEDIUM Description: eA Toolbar Version: 1.0.8188.27018 Modules
| |||||||||||||||
| 3716 | "C:\Users\admin\AppData\Local\Temp\setup.exe" | C:\Users\admin\AppData\Local\Temp\setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Setup Version: 16.0.31206.173 built by: D16.10 Modules
| |||||||||||||||
| 5008 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6364 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\intmortgage.jpg" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3716) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3716) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3716) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\PackageMetadata\{2ec93463-b0c3-45e1-8364-327e96aea856}_{60051b8f-4f12-400a-8e50-dd05ebd438d1} |
| Operation: | write | Name: | NonCanonicalData |
Value: | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\PackageMetadata\{2ec93463-b0c3-45e1-8364-327e96aea856}_{60051b8f-4f12-400a-8e50-dd05ebd438d1}\eade..tion_d9abb6dbd638d01c_0001.0000_ff56eed3b765066e |
| Operation: | write | Name: | appid |
Value: 68747470733A2F2F646F776E6C6F61642E657373656E7469616C6163636573736962696C6974792E636F6D2F45414465736B746F702F45414465736B746F702E6170706C69636174696F6E2345414465736B746F702E6170706C69636174696F6E2C2056657273696F6E3D312E302E302E3132322C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D643961626236646264363338643031632C2070726F636573736F724172636869746563747572653D783836 | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\PackageMetadata\{2ec93463-b0c3-45e1-8364-327e96aea856}_{60051b8f-4f12-400a-8e50-dd05ebd438d1}\eade..tion_d9abb6dbd638d01c_0001.0000_ff56eed3b765066e |
| Operation: | write | Name: | {c989bb7a-8385-4715-98cf-a741a8edb823}!ApplicationTrust |
Value: 3C004100700070006C00690063006100740069006F006E00540072007500730074002000760065007200730069006F006E003D002200310022000D000A00460075006C006C004E0061006D0065003D002200680074007400700073003A002F002F0064006F0077006E006C006F00610064002E0065007300730065006E007400690061006C006100630063006500730073006900620069006C006900740079002E0063006F006D002F00450041004400650073006B0074006F0070002F00450041004400650073006B0074006F0070002E006100700070006C00690063006100740069006F006E002300450041004400650073006B0074006F0070002E006100700070006C00690063006100740069006F006E002C002000560065007200730069006F006E003D0031002E0030002E0030002E003100320032002C002000430075006C0074007500720065003D006E00650075007400720061006C002C0020005000750062006C00690063004B006500790054006F006B0065006E003D0064003900610062006200360064006200640036003300380064003000310063002C002000700072006F0063006500730073006F0072004100720063006800690074006500630074007500720065003D007800380036002F00450041004400650073006B0074006F0070002E006500780065002C002000560065007200730069006F006E003D0031002E0030002E0030002E003100320032002C002000430075006C0074007500720065003D006E00650075007400720061006C002C0020005000750062006C00690063004B006500790054006F006B0065006E003D0064003900610062006200360064006200640036003300380064003000310063002C002000700072006F0063006500730073006F0072004100720063006800690074006500630074007500720065003D007800380036002C00200074007900700065003D00770069006E003300320022000D000A00540072007500730074006500640054006F00520075006E003D002200740072007500650022000D000A0050006500720073006900730074003D002200740072007500650022003E000D000A003C00440065006600610075006C0074004700720061006E0074003E000D000A003C0050006F006C00690063007900530074006100740065006D0065006E0074002000760065007200730069006F006E003D002200310022003E000D000A003C005000650072006D0069007300730069006F006E005300650074002000760065007200730069006F006E003D002200310022000D000A0063006C006100730073003D002200530079007300740065006D002E00530065006300750072006900740079002E004E0061006D00650064005000650072006D0069007300730069006F006E0053006500740022000D000A004E0061006D0065003D0022004C006F00630061006C0049006E007400720061006E006500740022000D000A004400650073006300720069007000740069006F006E003D002200440065006600610075006C0074002000720069006700680074007300200067006900760065006E00200074006F0020006100700070006C00690063006100740069006F006E00730020006F006E00200074006800650020006C006F00630061006C00200069006E007400720061006E006500740022000D000A0055006E0072006500730074007200690063007400650064003D002200740072007500650022000D000A00490044003D00220043007500730074006F006D0022000D000A00530061006D00650053006900740065003D002200730069007400650022000D000A0078006D006C006E0073003A00610073006D00760031003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A00610073006D002E007600310022000D000A0078006D006C006E0073003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A00610073006D002E007600320022000D000A0078006D006C006E0073003A00610073006D00760032003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A00610073006D002E007600320022000D000A0078006D006C006E0073003A007800730069003D00220068007400740070003A002F002F007700770077002E00770033002E006F00720067002F0032003000300031002F0058004D004C0053006300680065006D0061002D0069006E007300740061006E006300650022000D000A0078006D006C006E0073003A0063006F002E00760031003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A0063006C00690063006B006F006E00630065002E007600310022000D000A0078006D006C006E0073003A00610073006D00760033003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A00610073006D002E007600330022000D000A0078006D006C006E0073003A0064007300690067003D00220068007400740070003A002F002F007700770077002E00770033002E006F00720067002F0032003000300030002F00300039002F0078006D006C006400730069006700230022000D000A0078006D006C006E0073003A0063006F002E00760032003D002200750072006E003A0073006300680065006D00610073002D006D006900630072006F0073006F00660074002D0063006F006D003A0063006C00690063006B006F006E00630065002E007600320022003E000D000A003C0049005000650072006D0069007300730069006F006E00200063006C006100730073003D002200530079007300740065006D002E004E00650074002E005700650062005000650072006D0069007300730069006F006E002C002000530079007300740065006D002C002000560065007200730069006F006E003D0032002E0030002E0030002E0030002C002000430075006C0074007500720065003D006E00650075007400720061006C002C0020005000750062006C00690063004B006500790054006F006B0065006E003D00620037003700610035006300350036003100390033003400650030003800390022000D000A00760065007200730069006F006E003D002200310022003E000D000A003C0043006F006E006E006500630074004100630063006500730073003E000D000A003C0055005200490020007500720069003D00220028006800740074007000730029003A002F002F0064006F0077006E006C006F00610064005C002E0065007300730065006E007400690061006C006100630063006500730073006900620069006C006900740079005C002E0063006F006D002F002E002A0022002F003E000D000A003C002F0043006F006E006E006500630074004100630063006500730073003E000D000A003C002F0049005000650072006D0069007300730069006F006E003E000D000A003C002F005000650072006D0069007300730069006F006E005300650074003E000D000A003C002F0050006F006C00690063007900530074006100740065006D0065006E0074003E000D000A003C002F00440065006600610075006C0074004700720061006E0074003E000D000A003C004500780074007200610049006E0066006F00200044006100740061003D00220030003000300031003000300030003000300030004600460046004600460046004600460030003100300030003000300030003000300030003000300030003000300030003000430030003200300030003000300030003000350037003500330037003900370033003700340036003500360044003200450035003700360039003600450036003400360046003700370037003300320045003400360036004600370032003600440037003300320043003200300035003600360035003700320037003300360039003600460036004500330044003300340032004500330030003200450033003000320045003300300032004300320030003400330037003500360043003700340037003500370032003600350033004400360045003600350037003500370034003700320036003100360043003200430032003000350030003700350036003200360043003600390036003300340042003600350037003900350034003600460036004200360035003600450033004400360032003300370033003700360031003300350036003300330035003300360033003100330039003300330033003400360035003300300033003800330039003000350030003100300030003000300030003000330030003500330037003900370033003700340036003500360044003200450035003300360035003600330037003500370032003600390037003400370039003200450035003000360046003600430036003900360033003700390032004500340031003700300037003000360043003600390036003300360031003700340036003900360046003600450035003400370032003700350037003300370034003400350037003800370034003700320036003100340039003600450036003600360046003000310030003000300030003000300031003800370032003600350037003100370035003600350037003300370034003700330035003300360038003600350036004300360043003400390036004500370034003600350036003700370032003600310037003400360039003600460036004500300030003000310030003200300030003000300030003000300031003000420022002F003E000D000A003C002F004100700070006C00690063006100740069006F006E00540072007500730074003E000D000A000000 | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Marks\eade...exe_d9abb6dbd638d01c_0001.0000_none_f75b652084fe1125 |
| Operation: | write | Name: | identity |
Value: 45414465736B746F702E6578652C2056657273696F6E3D312E302E302E3132322C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D643961626236646264363338643031632C2070726F636573736F724172636869746563747572653D7838362C20747970653D77696E3332 | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Marks\eade...exe_d9abb6dbd638d01c_0001.0000_none_f75b652084fe1125 |
| Operation: | write | Name: | lock!01000000dd1e1800bc00000064080000000000000000000076980751d5e2db01 |
Value: 30303030303062632C30316462653264353334316262373866 | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Marks\eade...exe_d9abb6dbd638d01c_0001.0000_none_f75b652084fe1125 |
| Operation: | delete value | Name: | lock!01000000dd1e1800bc00000064080000000000000000000076980751d5e2db01 |
Value: 〰〰〰换〬搱敢搲㌵ㄴ扢㠷 | |||
| (PID) Process: | (188) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\PackageMetadata\{2ec93463-b0c3-45e1-8364-327e96aea856}_{3f471841-eef2-47d6-89c0-d028f03a4ad5} |
| Operation: | write | Name: | NonCanonicalData |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3716 | setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\EADesktop[1].htm | html | |
MD5:F5D40B7259645010F9A248858AD14178 | SHA256:7F5007068D2B56EA9735E2490D60CFF2E72CAE312024AC1F6C91158EBA47D05D | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5F26A2159BA21EA573A1C5E3DE2CF211_4A6B0B65ADF516E1B3A0ED47954EE7B9 | binary | |
MD5:F37AD53F6C090F5CEDD076D3DA5739BD | SHA256:2FEAEA2A2584BEB92F345E676F4EBF4BE7304B4B21CF948AF7722DB90FFD8682 | |||
| 3716 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_3AD253ACA02D44EA5FD30683B8A5B5FA | binary | |
MD5:6BD3EBEC4E65C7770306BA84A7B29BAC | SHA256:900A59015CF1B3148505E4D2BA3975DF4F68948CC24A6E98A19D47219B58780F | |||
| 3716 | setup.exe | C:\Users\admin\AppData\Local\Temp\VSD59B8.tmp\install.log | binary | |
MD5:DC8130BA254FB374147A4458EE3ED446 | SHA256:9EBC12F3B9A2342F109E12774D3BBD0F26B0230B1E39E612E6E7ECDEFED26843 | |||
| 3716 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D1BEC81CCAFDC823A062FF26A89A6B6D_E2F5EC841220A22A9FDD0E430BA22379 | binary | |
MD5:5C57ABA64EFA1CF815EC55FB0418F71F | SHA256:D4BC540644B263B249D834063301E16E07E64E503CA11EA21EA8186FFFC16AF0 | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\Local\Temp\Deployment\Y2QWYOLE.D15\KKMQEH01.KCG\EADesktop.exe.manifest | xml | |
MD5:490944D3E47BA0879D989C85F3B2E29D | SHA256:6171A1E1360005502EFB46EACCE06C5FFCAA463835EBE7FCEB9207CCE7F6CAAD | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_0A36A03C09DCEEA388C024E3D20B14B7 | binary | |
MD5:C05449C23117BD44D6BA1E643D1A2948 | SHA256:0AD966098B8472C81F5929AC4F147FE154E433C1A0AFC8F9A4AD99741413A1D9 | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_E6095CD2AECC9011BCD0D7B421356B17 | binary | |
MD5:1C705BC182E341E4D1452C5312B701A0 | SHA256:A99EF0654CFF489D524B97DD9EB2D93CC7C458A85B25F411885C4D596F053087 | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D7833C286363AD25C70511661A83D581_86E0F9C0EA22F8B2F763A4B3D6971BBF | binary | |
MD5:41D0C9604DE16798B6140A5E51FF9A71 | SHA256:DA36497FC22DAA0A2B276E02490B0A6AA2E443CEAD6BDFA400EBD979EB70D94D | |||
| 188 | dfsvc.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5F26A2159BA21EA573A1C5E3DE2CF211_4A6B0B65ADF516E1B3A0ED47954EE7B9 | binary | |
MD5:D7DDAD4EE0313B1E17F2229D9D3DA7FB | SHA256:F44BA66DE1CC70E6B8B59FF85418BA4F1087488F2EB92918B75CDD94599AD889 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3716 | setup.exe | GET | 301 | 13.32.27.39:80 | http://download.essentialaccessibility.com/EADesktop/EADesktop.application | unknown | — | — | unknown |
3716 | setup.exe | GET | 200 | 18.245.38.41:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEk8qlS4%2B0YpYvbhdG8DOXyc%3D | unknown | — | — | whitelisted |
3716 | setup.exe | GET | 200 | 143.204.99.128:80 | http://ocsp.r2m04.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTihuFvpmFDw5hOcIp918Jm5B3CQgQUH1KSYVaCVH%2BBZtgdPQqqMlyH3QgCEA1%2FCYl9GRzgS4dxKCLonDg%3D | unknown | — | — | unknown |
— | — | GET | 301 | 13.32.27.39:80 | http://download.essentialaccessibility.com/EADesktop/EADesktop.application | unknown | — | — | unknown |
— | — | GET | 301 | 13.32.27.39:80 | http://download.essentialaccessibility.com/EADesktop/EADesktop.application | unknown | — | — | unknown |
188 | dfsvc.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEDAPb6zdZph0fKlGNqd4Lbk%3D | unknown | — | — | whitelisted |
188 | dfsvc.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
188 | dfsvc.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSmEJ7s5DLYqQ4%2FaFKR54j1BHqdkgQUGqH4YRkgD8NBd0UojtE1XwYSBFUCEQCQOX%2Ba0ko6E%2FK9kV8IOKlD | unknown | — | — | whitelisted |
188 | dfsvc.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEB2iSDBvmyYY0ILgln0z02o%3D | unknown | — | — | whitelisted |
188 | dfsvc.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ5suEceKjAJbxseAmHFkQ9FrhTWQQUDuE6qFM6MdWKvsG7rWcaA4WtNA4CEE1gepVlRyS5Gaxc13vNStU%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5116 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3716 | setup.exe | 13.32.27.39:80 | download.essentialaccessibility.com | AMAZON-02 | US | unknown |
3716 | setup.exe | 13.32.27.39:443 | download.essentialaccessibility.com | AMAZON-02 | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3716 | setup.exe | 18.245.38.41:80 | ocsp.rootca1.amazontrust.com | — | US | whitelisted |
3716 | setup.exe | 143.204.99.128:80 | ocsp.r2m04.amazontrust.com | AMAZON-02 | US | unknown |
— | — | 13.32.27.39:80 | download.essentialaccessibility.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
download.essentialaccessibility.com |
| unknown |
ocsp.rootca1.amazontrust.com |
| whitelisted |
ocsp.r2m04.amazontrust.com |
| unknown |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
Process | Message |
|---|---|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741772
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\win32\isoreg_direct.cpp, line 1127
|
EADesktop.exe | Called SetProcessDpiAwarenessContext
|
EADesktop.exe | Returned value of setdpiaware... True
|
EADesktop.exe | RESTART: OnStartUpC:\Users\admin\AppData\Local\Apps\2.0\ZKHX2ZCG.C22\B92ETG4B.MWP\eade..tion_d9abb6dbd638d01c_0001.0000_1815fb6e6d2f4c45\EADesktop.exe
|