File name:

Transcreen.exe

Full analysis: https://app.any.run/tasks/5155c1cc-3f3e-42a3-8062-2e63089129b6
Verdict: Malicious activity
Analysis date: April 04, 2025, 11:11:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

403C228AEF7CB2C632F01A4A8AE93A3C

SHA1:

4D45070F27FB074BC7EB06E10A2B29F4314F171E

SHA256:

A949A34CAD96CA7E72A56D8BC87A4D570988746DB07C6873610DE0BEDD6ABC5A

SSDEEP:

98304:gC/VJfDUHcKwQkYkK+wV+mgkYkK+wV+m3f10JCnL6ePmzC07FzNcX1+SiM2ksXZy:42Lww3UecGIhL4Jehofd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Transcreen.exe (PID: 7500)
      • TranscreenSoftware.exe (PID: 7608)
    • Executable content was dropped or overwritten

      • Transcreen.exe (PID: 7500)
      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 7344)
      • drvinst.exe (PID: 900)
      • devcon.exe (PID: 8124)
      • devcon.exe (PID: 8140)
      • drvinst.exe (PID: 7176)
      • TranscreenSoftware.exe (PID: 7608)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 7452)
    • Reads security settings of Internet Explorer

      • Transcreen.exe (PID: 7500)
      • InstallDeviceDriver.exe (PID: 8060)
      • TranscreenSoftware.exe (PID: 7608)
      • devcon.exe (PID: 4688)
      • InstallDeviceDriver.exe (PID: 3676)
      • devcon.exe (PID: 8140)
      • InstallDeviceDriver.exe (PID: 720)
      • devcon.exe (PID: 8124)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 7344)
      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 900)
      • devcon.exe (PID: 8124)
      • drvinst.exe (PID: 7176)
      • TranscreenSoftware.exe (PID: 7608)
      • drvinst.exe (PID: 7452)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7344)
      • drvinst.exe (PID: 900)
      • drvinst.exe (PID: 7176)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 7452)
      • drvinst.exe (PID: 5244)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 900)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 7452)
    • Executes as Windows Service

      • WUDFHost.exe (PID: 5960)
    • Creates/Modifies COM task schedule object

      • drvinst.exe (PID: 7452)
    • There is functionality for taking screenshot (YARA)

      • TranscreenSoftware.exe (PID: 7608)
  • INFO

    • Reads the computer name

      • Transcreen.exe (PID: 7500)
      • TranscreenSoftware.exe (PID: 7608)
      • InstallDeviceDriver.exe (PID: 8060)
      • drvinst.exe (PID: 7344)
      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 900)
      • InstallDeviceDriver.exe (PID: 3676)
      • InstallDeviceDriver.exe (PID: 720)
      • devcon.exe (PID: 8124)
      • devcon.exe (PID: 8140)
      • drvinst.exe (PID: 7176)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 7452)
      • identity_helper.exe (PID: 8624)
      • identity_helper.exe (PID: 6660)
    • The sample compiled with chinese language support

      • Transcreen.exe (PID: 7500)
      • TranscreenSoftware.exe (PID: 7608)
      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 7344)
      • drvinst.exe (PID: 900)
      • devcon.exe (PID: 8140)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5244)
    • The sample compiled with english language support

      • TranscreenSoftware.exe (PID: 7608)
      • Transcreen.exe (PID: 7500)
      • devcon.exe (PID: 8124)
      • drvinst.exe (PID: 7176)
      • drvinst.exe (PID: 7452)
    • Creates files or folders in the user directory

      • Transcreen.exe (PID: 7500)
      • InstallDeviceDriver.exe (PID: 8060)
      • TranscreenSoftware.exe (PID: 7608)
    • The sample compiled with russian language support

      • Transcreen.exe (PID: 7500)
      • TranscreenSoftware.exe (PID: 7608)
    • Process checks computer location settings

      • Transcreen.exe (PID: 7500)
      • TranscreenSoftware.exe (PID: 7608)
      • InstallDeviceDriver.exe (PID: 8060)
      • InstallDeviceDriver.exe (PID: 3676)
      • InstallDeviceDriver.exe (PID: 720)
    • Checks supported languages

      • Transcreen.exe (PID: 7500)
      • InstallDeviceDriver.exe (PID: 8060)
      • devcon.exe (PID: 8152)
      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 7344)
      • drvinst.exe (PID: 900)
      • InstallDeviceDriver.exe (PID: 3676)
      • devcon.exe (PID: 8124)
      • devcon.exe (PID: 7316)
      • InstallDeviceDriver.exe (PID: 720)
      • devcon.exe (PID: 7324)
      • devcon.exe (PID: 8140)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 7176)
      • TranscreenSoftware.exe (PID: 7608)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 7452)
      • identity_helper.exe (PID: 8624)
      • identity_helper.exe (PID: 6660)
    • Reads the software policy settings

      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 7344)
      • devcon.exe (PID: 8140)
      • devcon.exe (PID: 8124)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 7176)
      • drvinst.exe (PID: 7452)
    • Reads the machine GUID from the registry

      • devcon.exe (PID: 4688)
      • drvinst.exe (PID: 7344)
      • devcon.exe (PID: 8140)
      • devcon.exe (PID: 8124)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 7176)
      • drvinst.exe (PID: 7452)
    • Create files in a temporary directory

      • devcon.exe (PID: 4688)
      • devcon.exe (PID: 8124)
      • devcon.exe (PID: 8140)
    • Application launched itself

      • msedge.exe (PID: 1388)
      • msedge.exe (PID: 9024)
      • msedge.exe (PID: 4652)
    • Manual execution by a user

      • msedge.exe (PID: 4652)
    • Reads Environment values

      • identity_helper.exe (PID: 8624)
      • identity_helper.exe (PID: 6660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:20 09:34:23+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.25
CodeSize: 129536
InitializedDataSize: 8240128
UninitializedDataSize: -
EntryPoint: 0xb125
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.6.6.5
ProductVersionNumber: 2.6.6.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: TranscreenSoft
FileDescription: TranscreenSoftClient
FileVersion: 2.6.6.5
InternalName: TranscreenSoft
LegalCopyright: -
OriginalFileName: -
ProductName: TranscreenSoft
ProductVersion: 2.6.6.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
215
Monitored processes
79
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start transcreen.exe transcreensoftware.exe sppextcomobj.exe no specs slui.exe no specs installdevicedriver.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe conhost.exe no specs drvinst.exe drvinst.exe installdevicedriver.exe no specs conhost.exe no specs installdevicedriver.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe conhost.exe no specs devcon.exe conhost.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe wudfhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs transcreen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
720"C:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exe" INSTALL_EXPANSION_SCREEN_DRIVERC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeTranscreenSoftware.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\installdevicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
900DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:ed86ca119389ada1:tff_virtaudio:1.0.0.4:*tff_virtaudio," "4a5756487" "00000000000001C8"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1116"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4064 --field-trial-handle=2520,i,10828110924832436046,7889519252033937801,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3448 --field-trial-handle=2520,i,10828110924832436046,7889519252033937801,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3520 --field-trial-handle=2520,i,10828110924832436046,7889519252033937801,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2716 --field-trial-handle=2324,i,6204333449941406488,6256635661989347672,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5360 --field-trial-handle=2324,i,6204333449941406488,6256635661989347672,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://transcreen.app/privacy_en.htmlC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeTranscreenSoftware.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2284"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2572 --field-trial-handle=2324,i,6204333449941406488,6256635661989347672,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2340"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5360 --field-trial-handle=2520,i,10828110924832436046,7889519252033937801,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
34 075
Read events
32 673
Write events
1 387
Delete events
15

Modification events

(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FriendlyName
Value:
Microphone (2- Realtek AC'97 Audio)
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointId
Value:
{0.0.1.00000000}.{05b02c95-c55a-499c-a533-120810b973df}
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointGuid
Value:
{05B02C95-C55A-499C-A533-120810B973DF}
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:WaveInId
Value:
0
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:ClassManagerFlags
Value:
2
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FriendlyName
Value:
Line In (2- Realtek AC'97 Audio)
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(7608) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
Executable files
111
Suspicious files
358
Text files
399
Unknown types
0

Dropped files

PID
Process
Filename
Type
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libfaad2_dll.dllexecutable
MD5:2BF68E570BC02A7D24E44CF56B55AACD
SHA256:5647CB3D12A8651ECE1F2853D1CAA1EE7C9098A8E2E907FEBE638F57D9C37959
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\SDL2.dllexecutable
MD5:AE58662A16410481B477B78B8D47460B
SHA256:A23D944BEA101C574875C13883088798CFDA712DE969DD14F529E870A0DE87DA
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\TranscreenSoftware.exeexecutable
MD5:1B97F95CDB8324539AE016B333102054
SHA256:1B689E127C0CE9E069C8E831B6F75302F11AD2684B83C9EEA3189DB2B80C9130
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeexecutable
MD5:D7E3652C4408E90791A2F49EBA2FC680
SHA256:85C91B8E29D3C0BD06D6E94BED3ACD319BAB7D31F469E534F6312C231ACA239E
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\avutil-52.dllexecutable
MD5:D5648A89F14CE039C901BC41304FA944
SHA256:9BEC277E396D7BC10F668694937471E5C2661B0D7B54ED2B27115212B77E8D5C
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\tff_samplerate.dllexecutable
MD5:8C981E0219F4F86261F60E3830A2DDD8
SHA256:C00A295BCB68572AD674CB4D021B1D1D06C076B22D42A78FEDAD612A9D629C8B
7608TranscreenSoftware.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\SysSet.initext
MD5:7254238FE4826939CCFA25D8D831F4BD
SHA256:B6DB9560B997490B3FD2543A9EB429F87A2D0A221EE4FD3A322BB3ADFA19866A
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\TFFPowerpoint.exeexecutable
MD5:9D576A59B70D86BDE2879080614A0749
SHA256:9EE57C36B770A266794F3904CF5B213766C06D86DDF8463E09C7EF399449A81D
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers.zipcompressed
MD5:68597C18F392476C906D9FAE27F6D359
SHA256:8C5CB49B4CAEC794D4FBA0B0782C5E2EC756042AEFDDE0C97FD729885CA68146
7500Transcreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libx264-146.dllexecutable
MD5:BB927B4A2DAF63516AFB2D73805949E7
SHA256:907534D4B1007FB660C21F17AF0F110AB768F42ABCED223825C4DD31A5653FFA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
58
DNS requests
52
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1764
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1764
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
255.255.255.255:6889
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
whitelisted
client.wns.windows.com
  • 20.7.2.167
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.131
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.130
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
transcreen.app
  • 34.94.79.9
unknown

Threats

No threats detected
No debug info