File name:

Shift - Manuals_6c9gy.exe

Full analysis: https://app.any.run/tasks/edeadd17-994b-4660-a775-ff828345fc3f
Verdict: Malicious activity
Analysis date: October 24, 2024, 17:59:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

1D97281DCDA538D182723659233B7B34

SHA1:

EBDAE63EDD07B3931B7D63A1AC726C262C81241E

SHA256:

AB9AA06A205112AD6A0C3C0BE642B4481F86316A783DCAE37DC2FE712815BC63

SSDEEP:

98304:8+cD4dnHwICNdt3uurGpkbO/uC6XsQpZX5vEVpyQn6hHzwOeNO4SPvsm6Puq/Gpk:saBT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
      • Shift - Manuals_6c9gy.exe (PID: 6440)
      • Shift - Manuals_6c9gy.exe (PID: 6268)
      • Shift - Manuals_6c9gy.tmp (PID: 3156)
      • Shift Setup_6c9gy.exe (PID: 3964)
      • Shift Setup_6c9gy.tmp (PID: 6288)
      • shift.exe (PID: 5232)
    • Reads the Windows owner or organization settings

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • There is functionality for taking screenshot (YARA)

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Uses TASKKILL.EXE to kill process

      • Shift Setup_6c9gy.tmp (PID: 6288)
    • Process drops legitimate windows executable

      • Shift Setup_6c9gy.tmp (PID: 6288)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 6888)
    • Application launched itself

      • shift.exe (PID: 5232)
    • Executes application which crashes

      • Shift Setup_6c9gy.tmp (PID: 6288)
  • INFO

    • Checks supported languages

      • Shift - Manuals_6c9gy.exe (PID: 6440)
      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Create files in a temporary directory

      • Shift - Manuals_6c9gy.exe (PID: 6440)
      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Reads the computer name

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Reads the software policy settings

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Reads the machine GUID from the registry

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
    • Checks proxy server information

      • Shift - Manuals_6c9gy.tmp (PID: 6132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 421888
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 122.10.0.0
ProductVersionNumber: 122.10.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shift
FileDescription: Shift Setup
FileVersion: 122.10.0
LegalCopyright: Copyright Shift. All rights reserved.
OriginalFileName:
ProductName: Shift
ProductVersion: 122.10.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
24
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start shift - manuals_6c9gy.exe THREAT shift - manuals_6c9gy.tmp shift - manuals_6c9gy.exe shift - manuals_6c9gy.tmp shift setup_6c9gy.exe shift setup_6c9gy.tmp taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs shift.exe shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs werfault.exe shift.exe no specs werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --mojo-platform-channel-handle=3656 --field-trial-handle=2216,i,11868408719757380689,15899854383889998574,262144 --variations-seed-version /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exe
shift.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Exit code:
0
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2056"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=gpu-process --no-pre-read-main-dll --start-stack-profiler --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2212 --field-trial-handle=2216,i,11868408719757380689,15899854383889998574,262144 --variations-seed-version /prefetch:2C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2132"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --start-stack-profiler --mojo-platform-channel-handle=2372 --field-trial-handle=2216,i,11868408719757380689,15899854383889998574,262144 --variations-seed-version /prefetch:3C:\Users\admin\AppData\Local\Shift\chromium\shift.exe
shift.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2796"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --mojo-platform-channel-handle=2620 --field-trial-handle=2216,i,11868408719757380689,15899854383889998574,262144 --variations-seed-version /prefetch:8C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
2928\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3156"C:\Users\admin\AppData\Local\Temp\is-Q8IHU.tmp\Shift - Manuals_6c9gy.tmp" /SL5="$80212,1423803,1164800,C:\Users\admin\AppData\Local\Temp\Shift - Manuals_6c9gy.exe" /PDATA=eyJtZXNzYWdlIjoiTm8gUmVjb3JkIEZvdW5kIiwiaW5zdGFsbF90aW1lIjoxNzI5NzkyNzcxLCJkaXN0aW5jdF9pZCI6IjFEQ0UyQUIwLThFNUMtNDk1Qi04RjNFLTc0NTNBQzIxRTUyOSIsImRlZmF1bHRfYnJvd3NlciI6Ik1TRWRnZUhUTSIsImluaXRpYWxfdmVyc2lvbiI6IjEyMi4xMC4wLjExMDEiLCJhdHRyaWJ1dGlvbl9rZXkiOiI2YzlneSJ9 /SPLITS=eyJzcGxpdCI6ImEiLCJzcGxpdDIiOiJhIiwibm9fc3BsaXQiOmZhbHNlLCJsb2NhbF9zcGxpdF90ZXN0cyI6eyJzcGxpdF9icng1NzBfY2xvc2VfYXBwX2RpYWxvZyI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9fSwic2VydmVyX3NpZGVfc3BsaXRfdGVzdHMiOnsic3BsaXRfc3QxMjMyX3JlbmFtZV9zaG9ydGN1dHNfc2hpZnRfYnJvd3NlciI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9LCJzcGxpdF9zdDEzOTFfZG9udF9pbXBvcnRfaGlzdG9yeSI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9fSwiYXR0cmlidXRpb25fc3BsaXRfdGVzdHMiOnt9LCJlbmNvZGVkX3NwbGl0cyI6IjI1NiJ9 /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-Q8IHU.tmp\Shift - Manuals_6c9gy.tmp
Shift - Manuals_6c9gy.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-q8ihu.tmp\shift - manuals_6c9gy.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3864"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --no-pre-read-main-dll --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4356 --field-trial-handle=2216,i,11868408719757380689,15899854383889998574,262144 --variations-seed-version /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
3964"C:\Users\admin\AppData\Local\Temp\Shift Setup_6c9gy.exe" /PDATA=eyJtZXNzYWdlIjoiTm8gUmVjb3JkIEZvdW5kIiwiaW5zdGFsbF90aW1lIjoxNzI5NzkyNzcxLCJkaXN0aW5jdF9pZCI6IjFEQ0UyQUIwLThFNUMtNDk1Qi04RjNFLTc0NTNBQzIxRTUyOSIsImRlZmF1bHRfYnJvd3NlciI6Ik1TRWRnZUhUTSIsImluaXRpYWxfdmVyc2lvbiI6IjEyMi4xMC4wLjExMDEiLCJhdHRyaWJ1dGlvbl9rZXkiOiI2YzlneSJ9 /SPLITS=eyJzcGxpdCI6ImEiLCJzcGxpdDIiOiJhIiwibm9fc3BsaXQiOmZhbHNlLCJsb2NhbF9zcGxpdF90ZXN0cyI6eyJzcGxpdF9icng1NzBfY2xvc2VfYXBwX2RpYWxvZyI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9fSwic2VydmVyX3NpZGVfc3BsaXRfdGVzdHMiOnsic3BsaXRfc3QxMjMyX3JlbmFtZV9zaG9ydGN1dHNfc2hpZnRfYnJvd3NlciI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9LCJzcGxpdF9zdDEzOTFfZG9udF9pbXBvcnRfaGlzdG9yeSI6eyJ2YWx1ZSI6InZhcmlhdGlvbiJ9fSwiYXR0cmlidXRpb25fc3BsaXRfdGVzdHMiOnt9LCJlbmNvZGVkX3NwbGl0cyI6IjI1NiJ9C:\Users\admin\AppData\Local\Temp\Shift Setup_6c9gy.exe
Shift - Manuals_6c9gy.tmp
User:
admin
Company:
Shift Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Shift Setup
Version:
122.10.0
Modules
Images
c:\users\admin\appdata\local\temp\shift setup_6c9gy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4004"C:\Windows\System32\taskkill.exe" /f /im shift.exeC:\Windows\SysWOW64\taskkill.exeShift Setup_6c9gy.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5232"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --start-maximizedC:\Users\admin\AppData\Local\Shift\chromium\shift.exe
Shift Setup_6c9gy.tmp
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift
Version:
122.10.0.1101
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\local\shift\chromium\122.10.0.1101\shift_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
12 374
Read events
12 289
Write events
85
Delete events
0

Modification events

(PID) Process:(3156) Shift - Manuals_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
540C0000923DDE873E26DB01
(PID) Process:(3156) Shift - Manuals_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
86219971A9C58D56FBE55E3A532035B20A49F7784F6B53DF942B765FBC3B14D0
(PID) Process:(3156) Shift - Manuals_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:pv
Value:
122.10.0.1101
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:EnterpriseProduct<{95fcf903-63b1-44bd-ab77-358a5bd30aae}_is1>
Value:
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationDescription
Value:
Shift Browser
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationName
Value:
Shift Browser
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.htm
Value:
ShiftHTML
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.html
Value:
ShiftHTML
(PID) Process:(6288) Shift Setup_6c9gy.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.pdf
Value:
ShiftHTML
Executable files
41
Suspicious files
279
Text files
221
Unknown types
22

Dropped files

PID
Process
Filename
Type
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\is-5LP4Q.tmp
MD5:
SHA256:
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\Shift Setup.exe
MD5:
SHA256:
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup.exe
MD5:
SHA256:
3156Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup_6c9gy.exe
MD5:
SHA256:
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\min-hover.bmpimage
MD5:C94A77553F2C392D5F1FE2F08E30EFB2
SHA256:8DAA69B6252F6F773CEB6D7090664B933537478731473E1B54CAF67791C2D336
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
6440Shift - Manuals_6c9gy.exeC:\Users\admin\AppData\Local\Temp\is-SD20B.tmp\Shift - Manuals_6c9gy.tmpexecutable
MD5:DCC68F0398F463E769AF814DF6B43957
SHA256:422AC90AC13C75B3ABD15A8F9FCBBF8463BBC4D0AA6190396DA86F0E62CAE1C2
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\shift.pngimage
MD5:0423D0589E58341B5B64C6099F4123B7
SHA256:A1D2C48437058F24A5EA85C323469473AC4430198770794522A32C28783AADB7
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\shift.bmpimage
MD5:6C091E46C4B50CBE372A0826B8D38331
SHA256:385B8FD4363F4A13469B1E9BCF21365FF7BBD9DD4CD90E52B290FC89DDE1927C
6132Shift - Manuals_6c9gy.tmpC:\Users\admin\AppData\Local\Temp\is-5FLMI.tmp\min-pressed.bmpimage
MD5:4B549427F8B753A01272BEC3A658E7BA
SHA256:FE03E30C13229D50685E3387F4F271BEFE57DFA74BE890D09C089FB3688469A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
100
DNS requests
77
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.167:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1500
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6384
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1500
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2620
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7456
WerFault.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7456
WerFault.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1764
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6132
Shift - Manuals_6c9gy.tmp
3.138.77.61:443
attribution.shiftapis.com
AMAZON-02
US
unknown
6132
Shift - Manuals_6c9gy.tmp
3.140.172.47:443
updates.shiftapis.com
AMAZON-02
US
unknown
6132
Shift - Manuals_6c9gy.tmp
172.67.4.202:443
downloads.tryshift.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.176
  • 2.23.209.158
  • 2.23.209.141
  • 2.23.209.149
  • 2.23.209.144
  • 2.23.209.160
  • 2.23.209.150
  • 2.23.209.148
  • 2.16.110.203
  • 2.16.110.136
  • 2.16.110.193
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.110
whitelisted
attribution.shiftapis.com
  • 3.138.77.61
  • 18.223.47.71
  • 18.116.167.69
unknown
updates.shiftapis.com
  • 3.140.172.47
  • 3.131.25.94
  • 3.16.72.53
unknown
downloads.tryshift.com
  • 172.67.4.202
  • 104.22.76.241
  • 104.22.77.241
unknown
login.live.com
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.0
  • 40.126.31.71
  • 20.190.159.68
whitelisted
th.bing.com
  • 2.16.110.179
  • 2.16.110.170
  • 2.16.110.161
  • 2.16.110.186
  • 2.16.110.168
  • 2.16.110.145
  • 2.16.110.184
  • 2.16.110.121
  • 2.16.110.136
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted

Threats

PID
Process
Class
Message
2132
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
2132
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
Process
Message
shift.exe
[1024/180020.010:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\Shift\User Data\Crashpad: The system cannot find the path specified. (0x3)