File name:

multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe

Full analysis: https://app.any.run/tasks/19f2ba43-65ad-4f93-b933-0caddf066f89
Verdict: Malicious activity
Analysis date: April 18, 2018, 07:31:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

87482220000A2DEAA0FE79A573534DEC

SHA1:

7536168B5E95781FC693B8729865C5E7DF931278

SHA256:

A7496DF0C5D13DB9B2AAC7EA48749DE0E24734F49F7291A9D59CFD3E652B8848

SSDEEP:

393216:nwMYHKe7CkP4KcLelvEWARoAezyYTWARZx:eW+4KcLelvEWtXHTW+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • dcmdev32.exe (PID: 696)
      • hapint.exe (PID: 1404)
      • dcmdev32.exe (PID: 2996)
      • dchcfg32.exe (PID: 1828)
      • cctk.exe (PID: 2852)
      • hapint.exe (PID: 3196)
      • dcmdev32.exe (PID: 4048)
    • Application loaded dropped or rewritten executable

      • cctk.exe (PID: 2852)
      • dchcfg32.exe (PID: 1828)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe (PID: 2796)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2944)
      • DrvInst.exe (PID: 2752)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 2944)
      • dcmdev32.exe (PID: 2996)
      • DrvInst.exe (PID: 2752)
      • hapint.exe (PID: 1404)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2944)
      • DrvInst.exe (PID: 2752)
      • hapint.exe (PID: 3196)
    • Creates files in the program directory

      • multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe (PID: 2796)
      • cctk.exe (PID: 2852)
    • Application launched itself

      • taskmgr.exe (PID: 3288)
  • INFO

    • Dropped object may contain URL's

      • dcmdev32.exe (PID: 2996)
      • DrvInst.exe (PID: 2944)
      • DrvInst.exe (PID: 2752)
      • hapint.exe (PID: 1404)
      • multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:06:11 09:11:18+02:00
PEType: PE32
LinkerVersion: 10
CodeSize: 4475904
InitializedDataSize: 1582080
UninitializedDataSize: -
EntryPoint: 0x307062
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 3.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Dell Inc.
FileDescription: SCE
FileVersion: 003.000.000.000
InternalName: DUPFramework.exe
LegalCopyright: (c) Dell Inc. All rights reserved.
OriginalFileName: DUPFramework.exe
ProductName: SCE
ProductVersion: 003.000.000.000

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 11-Jun-2013 07:11:18
Detected languages:
  • English - United States
Debug artifacts:
  • C:\svn\trunk\dtk1_tksrc\DupFramework\DupFramework\bin\Release\DupFramework.pdb
CompanyName: Dell Inc.
FileDescription: SCE
FileVersion: 003.000.000.000
InternalName: DUPFramework.exe
LegalCopyright: (c) Dell Inc. All rights reserved.
OriginalFilename: DUPFramework.exe
ProductName: SCE
ProductVersion: 003.000.000.000

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 11-Jun-2013 07:11:18
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00444B0C
0x00444C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.92515
.rdata
0x00446000
0x000E0918
0x000E0A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.59414
.data
0x00527000
0x00017CB8
0x0000DE00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.48273
.idata
0x0053F000
0x00006614
0x00006800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.00514
.didat
0x00546000
0x000002B8
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.344416
.rsrc
0x00547000
0x0004C14C
0x0004C200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.26087
.reloc
0x00594000
0x00040CF5
0x00040E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.24155

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.12493
1342
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.02695
308
Latin 1 / Western European
English - United States
RT_CURSOR
3
2.74274
180
Latin 1 / Western European
English - United States
RT_CURSOR
4
2.34038
308
Latin 1 / Western European
English - United States
RT_CURSOR
5
2.34004
308
Latin 1 / Western European
English - United States
RT_CURSOR
6
2.51649
308
Latin 1 / Western European
English - United States
RT_CURSOR
7
2.45401
308
Latin 1 / Western European
English - United States
RT_CURSOR
8
2.34864
308
Latin 1 / Western European
English - United States
RT_CURSOR
9
3.24207
572
Latin 1 / Western European
English - United States
RT_STRING
10
3.25884
686
Latin 1 / Western European
English - United States
RT_STRING

Imports

ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IMM32.dll
KERNEL32.dll
MSIMG32.dll
OLEACC.dll
OLEAUT32.dll
SHELL32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
15
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start multiplatform_201603101209_wol_enabled_deepsleep_disabled.exe cmd.exe no specs hapint.exe dcmdev32.exe no specs dcmdev32.exe drvinst.exe drvinst.exe dchcfg32.exe no specs cctk.exe no specs hapint.exe no specs dcmdev32.exe no specs rundll32.exe no specs taskmgr.exe no specs taskmgr.exe multiplatform_201603101209_wol_enabled_deepsleep_disabled.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696dcmdev32.exe remove root\dcdbasC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\x86\HAPI\dcmdev32.exehapint.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
WDM Driver Manager
Exit code:
0
Version:
7.4.0 (BLD_3999)
Modules
Images
c:\programdata\dell\drivers\multiplatform_201603101209_wol_enabled_deepsleep_disabled\x86\hapi\dcmdev32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1284C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1352"C:\Windows\system32\taskmgr.exe" /1C:\Windows\system32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1404x86\HAPI\hapint.exe -i -q -k CCTK-SCE -p "hapint.exe"C:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\x86\HAPI\hapint.exe
cmd.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Hapi Installer
Exit code:
0
Version:
7.4.0 (BLD_3999)
Modules
Images
c:\programdata\dell\drivers\multiplatform_201603101209_wol_enabled_deepsleep_disabled\x86\hapi\hapint.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
1828dchcfg32.exe command=getsupportedsystypesC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\x86\HAPI\dchcfg32.exehapint.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
HAPI Config Utility
Exit code:
0
Version:
7.4.0 (BLD_3999)
Modules
Images
c:\programdata\dell\drivers\multiplatform_201603101209_wol_enabled_deepsleep_disabled\x86\hapi\dchcfg32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2480"C:\Users\admin\AppData\Local\Temp\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe" C:\Users\admin\AppData\Local\Temp\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeexplorer.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
MEDIUM
Description:
SCE
Exit code:
3221226540
Version:
003.000.000.000
Modules
Images
c:\users\admin\appdata\local\temp\multiplatform_201603101209_wol_enabled_deepsleep_disabled.exe
c:\systemroot\system32\ntdll.dll
2536cmd /c ""C:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\applyconfig.bat" -l="C:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\SCE756.tmp""C:\Windows\system32\cmd.exemultiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2752DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "dcdbas32.inf:Standard:dcdbas:7.4.0.453:root\dcdbas" "6dfcb1ac3" "000004E4" "000005CC" "000005DC"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2796"C:\Users\admin\AppData\Local\Temp\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe" C:\Users\admin\AppData\Local\Temp\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exe
explorer.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
SCE
Exit code:
0
Version:
003.000.000.000
Modules
Images
c:\users\admin\appdata\local\temp\multiplatform_201603101209_wol_enabled_deepsleep_disabled.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2852x86\cctk.exe -i config.ini -l "C:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\SCE756.tmp" C:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\x86\cctk.execmd.exe
User:
admin
Company:
Dell
Integrity Level:
HIGH
Description:
Client Configuration Toolkit
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\programdata\dell\drivers\multiplatform_201603101209_wol_enabled_deepsleep_disabled\x86\cctk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
237
Read events
170
Write events
60
Delete events
7

Modification events

(PID) Process:(1404) hapint.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hapiTemp
Operation:delete keyName:
Value:
(PID) Process:(2796) multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2796) multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2996) dcmdev32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.app.log
Value:
4096
(PID) Process:(2996) dcmdev32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(2996) dcmdev32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\91\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2944) DrvInst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2752) DrvInst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2752) DrvInst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles
Operation:writeName:%SystemPath%\system32\DRIVERS\dcdbas32.sys
Value:
5
(PID) Process:(2752) DrvInst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\root#dcdbas
Operation:writeName:Service
Value:
dcdbas
Executable files
52
Suspicious files
19
Text files
131
Unknown types
7

Dropped files

PID
Process
Filename
Type
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\config.inibinary
MD5:
SHA256:
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\applyconfig.battext
MD5:0B97AF703C6687CE7DD301B730867AEB
SHA256:500461F07C86054911306C7A60C9925C31E841CC4AF46CA2663DAFC3D18AD91F
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\mup.xmlxml
MD5:51B31D6FC0D180E8AB1672BAAA20A0D9
SHA256:9C491BB41C54E432414C5E44808990C1468F7D8A59136F271F6C2265AE40E833
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\package.xmlxml
MD5:
SHA256:
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\cctk.exeexecutable
MD5:9E4C0DA7CB87508021B01069A423BD90
SHA256:E94B9C8E662A38A133C3B7AA495D6B1171AEADB7DA609B6317BEF5040CDEE946
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\HAPI\dcdbas32.catcat
MD5:FA41524D28D7BA53D33DA20AD51DBEC8
SHA256:BD5D823B2F5A3A5E11F47960BCB413FC3212A99D32230C449984EEC1689FED40
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\HAPI\dchipm32.dllexecutable
MD5:73C41AC6BFE62CDE70D38EBD40176158
SHA256:D4461455AAD71465D545B0A6F6024267ED99C836D749E08F22A8AC507A619EFC
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\HAPI\dchbas32.dllexecutable
MD5:2AF7D9625C4E2B31D7CEF6B8BC4662C5
SHA256:AB5E1594B4257DE879353BDB0DA641D4F802DE1C40DAD34982F91696568EED9C
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\HAPI\dchcfg32.exeexecutable
MD5:744CBA7ACB954719036D2FFBFE8DC281
SHA256:B0A231AD70F03814EC3D05E99D3BAE2B8400D74CF2243D6FE6FB65284D713D5D
2796multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled.exeC:\ProgramData\dell\drivers\multiplatform_201603101209_WOL_enabled_DEEPSLEEP_disabled\X86\HAPI\dchcfl32.dllexecutable
MD5:4BFB09DB0371D71E10F545D35DDD2D11
SHA256:792502F3C1F161E7D6EDDBC4A054E87495C35B45C71267FF318892E0296A58FB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info