File name:

Transcreen.exe

Full analysis: https://app.any.run/tasks/455d02f9-da8b-4a63-aa0b-2f29264c3f09
Verdict: Malicious activity
Analysis date: April 03, 2025, 11:53:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

403C228AEF7CB2C632F01A4A8AE93A3C

SHA1:

4D45070F27FB074BC7EB06E10A2B29F4314F171E

SHA256:

A949A34CAD96CA7E72A56D8BC87A4D570988746DB07C6873610DE0BEDD6ABC5A

SSDEEP:

98304:gC/VJfDUHcKwQkYkK+wV+mgkYkK+wV+m3f10JCnL6ePmzC07FzNcX1+SiM2ksXZy:42Lww3UecGIhL4Jehofd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Transcreen.exe (PID: 3132)
      • TranscreenSoftware.exe (PID: 6540)
      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 2564)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 3896)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 4212)
    • Process drops legitimate windows executable

      • TranscreenSoftware.exe (PID: 6540)
    • Reads security settings of Internet Explorer

      • Transcreen.exe (PID: 3132)
      • TranscreenSoftware.exe (PID: 6540)
      • InstallDeviceDriver.exe (PID: 6660)
      • devcon.exe (PID: 4996)
      • InstallDeviceDriver.exe (PID: 684)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 3896)
      • InstallDeviceDriver.exe (PID: 2332)
    • Drops a system driver (possible attempt to evade defenses)

      • TranscreenSoftware.exe (PID: 6540)
      • drvinst.exe (PID: 2564)
      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 4572)
      • devcon.exe (PID: 3896)
      • drvinst.exe (PID: 4212)
    • There is functionality for taking screenshot (YARA)

      • TranscreenSoftware.exe (PID: 6540)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 2564)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 4212)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 4212)
    • Executes as Windows Service

      • WUDFHost.exe (PID: 1748)
    • Creates/Modifies COM task schedule object

      • drvinst.exe (PID: 4212)
  • INFO

    • Reads the computer name

      • Transcreen.exe (PID: 3132)
      • InstallDeviceDriver.exe (PID: 6660)
      • TranscreenSoftware.exe (PID: 6540)
      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 2564)
      • InstallDeviceDriver.exe (PID: 684)
      • InstallDeviceDriver.exe (PID: 2332)
      • devcon.exe (PID: 3896)
      • devcon.exe (PID: 6112)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 4212)
    • The sample compiled with english language support

      • Transcreen.exe (PID: 3132)
      • TranscreenSoftware.exe (PID: 6540)
      • devcon.exe (PID: 3896)
      • drvinst.exe (PID: 4572)
      • drvinst.exe (PID: 4212)
    • The sample compiled with chinese language support

      • Transcreen.exe (PID: 3132)
      • TranscreenSoftware.exe (PID: 6540)
      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2432)
      • drvinst.exe (PID: 2564)
      • drvinst.exe (PID: 5164)
      • devcon.exe (PID: 6112)
      • drvinst.exe (PID: 4040)
    • Creates files or folders in the user directory

      • Transcreen.exe (PID: 3132)
      • TranscreenSoftware.exe (PID: 6540)
      • InstallDeviceDriver.exe (PID: 6660)
    • The sample compiled with russian language support

      • TranscreenSoftware.exe (PID: 6540)
    • Checks supported languages

      • TranscreenSoftware.exe (PID: 6540)
      • Transcreen.exe (PID: 3132)
      • InstallDeviceDriver.exe (PID: 6660)
      • devcon.exe (PID: 5260)
      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2564)
      • drvinst.exe (PID: 2432)
      • InstallDeviceDriver.exe (PID: 684)
      • InstallDeviceDriver.exe (PID: 2332)
      • devcon.exe (PID: 4380)
      • devcon.exe (PID: 3896)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 2656)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 4212)
    • Process checks computer location settings

      • Transcreen.exe (PID: 3132)
      • InstallDeviceDriver.exe (PID: 6660)
      • TranscreenSoftware.exe (PID: 6540)
      • InstallDeviceDriver.exe (PID: 2332)
      • InstallDeviceDriver.exe (PID: 684)
    • Reads the software policy settings

      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2564)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 3896)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • slui.exe (PID: 668)
      • drvinst.exe (PID: 4212)
    • Reads the machine GUID from the registry

      • devcon.exe (PID: 4996)
      • drvinst.exe (PID: 2564)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 3896)
      • drvinst.exe (PID: 5164)
      • drvinst.exe (PID: 4572)
      • drvinst.exe (PID: 4212)
    • Create files in a temporary directory

      • devcon.exe (PID: 4996)
      • devcon.exe (PID: 6112)
      • devcon.exe (PID: 3896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:20 09:34:23+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.25
CodeSize: 129536
InitializedDataSize: 8240128
UninitializedDataSize: -
EntryPoint: 0xb125
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.6.6.5
ProductVersionNumber: 2.6.6.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: TranscreenSoft
FileDescription: TranscreenSoftClient
FileVersion: 2.6.6.5
InternalName: TranscreenSoft
LegalCopyright: -
OriginalFileName: -
ProductName: TranscreenSoft
ProductVersion: 2.6.6.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
31
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start transcreen.exe sppextcomobj.exe no specs slui.exe transcreensoftware.exe installdevicedriver.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe conhost.exe no specs drvinst.exe drvinst.exe installdevicedriver.exe no specs conhost.exe no specs installdevicedriver.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe conhost.exe no specs devcon.exe conhost.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe wudfhost.exe no specs slui.exe no specs transcreen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
684"C:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exe" INSTALL_EXPANSION_SCREEN_DRIVERC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeTranscreenSoftware.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\installdevicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1748"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-ba644c27-4e15-4a59-83c9-4ab7b3b4ee82 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-bf24a8e3-4123-4e0d-ac1b-3f408098d212 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-46fe0e65-6646-4979-b2d7-0f6e58f68a48 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-3b316c1e-6b5a-447e-ae95-18fab008d989 -LifetimeId:86aa8c12-ce94-4b07-8ddd-c88cffe7d96c -DeviceGroupId:DisplayProxy10Group -HostArg:0C:\Windows\System32\WUDFHost.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Driver Foundation - User-mode Driver Framework Host Process
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wudfhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\devobj.dll
2136"C:\Users\admin\AppData\Local\Temp\Transcreen.exe" C:\Users\admin\AppData\Local\Temp\Transcreen.exeexplorer.exe
User:
admin
Company:
TranscreenSoft
Integrity Level:
MEDIUM
Description:
TranscreenSoftClient
Exit code:
3221226540
Version:
2.6.6.5
Modules
Images
c:\users\admin\appdata\local\temp\transcreen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2192\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2332"C:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exe" INSTALL_VIRTUAL_CAMERAC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeTranscreenSoftware.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\installdevicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2432DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:ed86ca119389ada1:tff_virtaudio:1.0.0.4:*tff_virtaudio," "4a5756487" "00000000000001F8"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2564DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{a169752c-9392-9d48-a009-d1845fbbfbf4}\tff_virtaudio.inf" "9" "4a5756487" "00000000000001D4" "WinSta0\Default" "00000000000001BC" "208" "c:\users\admin\appdata\roaming\transcreen\software\drivers\tffaudio\x64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2656"C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\vmonitor\x64\devcon.exe" -remove hid\vid_1b36&pid_0d11C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\vmonitor\x64\devcon.exeInstallDeviceDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.14393.0 (rs1_release.160715-1616)
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\drivers\vmonitor\x64\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2984\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
27 946
Read events
26 575
Write events
1 356
Delete events
15

Modification events

(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FriendlyName
Value:
Microphone (2- Realtek AC'97 Audio)
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointId
Value:
{0.0.1.00000000}.{05b02c95-c55a-499c-a533-120810b973df}
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointGuid
Value:
{05B02C95-C55A-499C-A533-120810B973DF}
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:WaveInId
Value:
0
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:ClassManagerFlags
Value:
2
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FriendlyName
Value:
Line In (2- Realtek AC'97 Audio)
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(6540) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
Executable files
99
Suspicious files
40
Text files
333
Unknown types
1

Dropped files

PID
Process
Filename
Type
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers.zipcompressed
MD5:68597C18F392476C906D9FAE27F6D359
SHA256:8C5CB49B4CAEC794D4FBA0B0782C5E2EC756042AEFDDE0C97FD729885CA68146
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\DuiLib.dllexecutable
MD5:A8DDB82951F36BFBFF49E196CADFF84B
SHA256:FE2BFBFF86ED209C516D92894B805D3803FE7F3CB993BD06DD4371F1EFB097CD
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeexecutable
MD5:D7E3652C4408E90791A2F49EBA2FC680
SHA256:85C91B8E29D3C0BD06D6E94BED3ACD319BAB7D31F469E534F6312C231ACA239E
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libgcc_s_dw2-1.dllexecutable
MD5:97E7F6F9D7F92F54B6FC06B8B1397117
SHA256:F240698B514FA954E2A75D239FC784FFB8B931CD05E43F585017469F12A45084
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\ImgRes.zipcompressed
MD5:01E62BC1D9D81E51ADCE3A5CC867239E
SHA256:1B9A19C44CBEE93AB2FAC983C5706D51A186089FA18D0BFC92B17ACD48C74567
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libVMonitor.dllexecutable
MD5:91EC8074D3F068EA6EDD027D9351717D
SHA256:2D11EE5AFAC02EA89DF4C35DC1C6A928FEEE2ADF06E8B714CED3D557E8E02C14
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\SoftTranscreen.zipcompressed
MD5:C892A2A2E819FD0E89F1ABA50418EA8A
SHA256:17406FEF8408782D44A03A534CBF2E01BB15CA424825DD4347090BA3B9CCC356
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\wz264.dllexecutable
MD5:7FCD1553756FD96779A417FE4FFBC769
SHA256:988CD8B51E3EC088FBC6B6A1613688C7D9F053C401BDF5055311E1B26929743C
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\TFFPowerpoint.exeexecutable
MD5:9D576A59B70D86BDE2879080614A0749
SHA256:9EE57C36B770A266794F3904CF5B213766C06D86DDF8463E09C7EF399449A81D
3132Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libx264-146.dllexecutable
MD5:BB927B4A2DAF63516AFB2D73805949E7
SHA256:907534D4B1007FB660C21F17AF0F110AB768F42ABCED223825C4DD31A5653FFA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
30
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.216.77.31:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1760
SIHClient.exe
GET
200
104.85.1.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1760
SIHClient.exe
GET
200
104.85.1.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
23.216.77.31:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
20.198.162.76:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
1760
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1760
SIHClient.exe
104.85.1.163:80
www.microsoft.com
AKAMAI-AS
NL
whitelisted
255.255.255.255:6889
unknown
1760
SIHClient.exe
13.85.23.206:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.110
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.31
  • 23.216.77.25
  • 23.216.77.29
  • 23.216.77.22
  • 23.216.77.21
  • 23.216.77.35
  • 23.216.77.26
  • 23.216.77.27
  • 23.216.77.28
whitelisted
client.wns.windows.com
  • 20.198.162.76
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 104.85.1.163
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.131
  • 20.190.160.22
  • 20.190.160.64
  • 40.126.32.136
  • 20.190.160.65
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 69.192.162.125
whitelisted

Threats

No threats detected
No debug info