File name:

OCR Recognition Assistant.exe

Full analysis: https://app.any.run/tasks/21660a1b-98d2-4a89-88de-cd120586eccf
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 27, 2024, 06:27:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

096186DA1116602DB0095BD33F00B340

SHA1:

85E8DA243708FA5CAAE9D4BD769FEF6A30578877

SHA256:

B16813C8A8111F24FF992726B9B8D3A21E6B9D5930B536EB3EE547D7083A7F7E

SSDEEP:

49152:aaoE7OTGKJtlJ1lX8fqFHglqu8OBG8JgtYi73TyEPQ7oxgnrQeM:aJGKJtL1liJou88geSaPnrQeM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OCR Recognition Assistant.exe (PID: 5712)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OCR Recognition Assistant.exe (PID: 5712)
    • Process requests binary or script from the Internet

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads security settings of Internet Explorer

      • OCR Recognition Assistant.exe (PID: 5712)
    • There is functionality for taking screenshot (YARA)

      • OCR Recognition Assistant.exe (PID: 5712)
    • Potential Corporate Privacy Violation

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads Internet Explorer settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads Microsoft Outlook installation path

      • OCR Recognition Assistant.exe (PID: 5712)
    • Uses NSLOOKUP.EXE to check DNS info

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks Windows Trust Settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • Starts CMD.EXE for commands execution

      • OCR Recognition Assistant.exe (PID: 5712)
  • INFO

    • Reads the computer name

      • OCR Recognition Assistant.exe (PID: 5712)
    • Sends debugging messages

      • OCR Recognition Assistant.exe (PID: 5712)
    • Disables trace logs

      • OCR Recognition Assistant.exe (PID: 5712)
    • Creates files or folders in the user directory

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads the machine GUID from the registry

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks supported languages

      • OCR Recognition Assistant.exe (PID: 5712)
      • identity_helper.exe (PID: 3848)
    • Create files in a temporary directory

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks proxy server information

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads the software policy settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • The process uses the downloaded file

      • OCR Recognition Assistant.exe (PID: 5712)
    • Application launched itself

      • msedge.exe (PID: 5616)
      • msedge.exe (PID: 6520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:20 06:25:26+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 2519040
InitializedDataSize: 142336
UninitializedDataSize: -
EntryPoint: 0x268e3e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.6.1.0
ProductVersionNumber: 4.6.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: OCR文字识别助手(2024-12-20)
CompanyName: SmartOldFish
FileDescription:
FileVersion: 4.6.1
InternalName: OCR Recognition Assistant.exe
LegalCopyright: Copyright © 2019-2024 OldFish.CN
OriginalFileName: OCR Recognition Assistant.exe
ProductName: OCR助手
ProductVersion: 4.6.1
AssemblyVersion: 4.6.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
52
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ocr recognition assistant.exe nslookup.exe nslookup.exe conhost.exe no specs conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7ff821b75fd8,0x7ff821b75fe4,0x7ff821b75ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=5300 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4116 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2932 --field-trial-handle=2388,i,15699820765503010400,18247214989735170368,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3664"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5168 --field-trial-handle=2388,i,15699820765503010400,18247214989735170368,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4752 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3820"nslookup.exe"C:\Windows\SysWOW64\nslookup.exe
OCR Recognition Assistant.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
nslookup
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3848"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5864 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4052"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6284 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4596\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenslookup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 439
Read events
16 333
Write events
100
Delete events
6

Modification events

(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
9
Suspicious files
258
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Widget\Microsoft.ApplicationInsights.dllexecutable
MD5:5B2672BDD65C18C6ECF1A24EAFD7122A
SHA256:03DF131138A32F5DF9591BBDA9A512FFC9528A4E16D5683751EB24A1B015A0CE
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Local\Temp\tmp7C28.tmpcompressed
MD5:50BDA8FC4A2C05245C94BC4D2ADD3E7F
SHA256:7D60CEA128C1C095E286A9F360CEF779E2366D66DFD8126D0EB2BD6751B1B135
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Local\Temp\tmp7C28.tmp.tmptext
MD5:643F1D222647911C78A7BAD295867E8F
SHA256:9340E209D5F5E8C7BEE958009099741D68388A64BB3190C6FDAC51C94C3B185F
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\serverGroup.dattext
MD5:5FDD2A47E10CDB9891479F411CFC8DC7
SHA256:BBCFA93A5683093315875E23CB118552818718DA9FFF805C942DAFABE28472ED
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\ico\阿里.icoimage
MD5:5532D49C800891B82815F5AD3D446E65
SHA256:359BA97F797B1E19AE0525BF67E66E2E2D7E6CF384FE709583AD5111EFB2A1B3
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\guide.dattext
MD5:20797233BFA3CB2F5D0C1B08ACA66005
SHA256:E3FA6F498A8FE35F578F934E2C3BA0ECFB3EF23E6C411DDBCA1435F8E19F54A2
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013binary
MD5:105BDB059BD2A82F76F07190F7C3C100
SHA256:A263171A70D14EAFEEDED4E4D7DEFA53C8809862A89839A031C64E01C8EA00B8
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225Fbinary
MD5:FA561D6502881F082B20239E87F55BFF
SHA256:795584D5FDDB735F9E119DE0087030FD5E36858CAC8FD8665D09FBA6DDEB3AE2
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\ico\不限.icoimage
MD5:55E0C158921C7B3F33552A460B3AE640
SHA256:2B297974DF909CEC3AECC7702AEA3232A52C148D30BB3BE99CC37BCA0D721AAC
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\plug.dattext
MD5:6B411B248DB5F3081A2B72F5FCF3DDE9
SHA256:475826A837AFCAEC3A5E38D385CD0A9D3EA8E6BF8AADDDD557214B2697188C2C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
60
TCP/UDP connections
77
DNS requests
86
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.13:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.13:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
5712
OCR Recognition Assistant.exe
HEAD
200
81.70.191.231:80
http://cdn.oldfish.cn/lang/en-US.lang?t=638709064640967648
CN
unknown
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://cdn.oldfish.cn/ext/Microsoft.ApplicationInsights.txt?t=638709064624716354
CN
compressed
132 Kb
unknown
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://cdn.oldfish.cn/site.json?t=638708776640967648&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064643312122&lang=
CN
binary
218 b
unknown
5712
OCR Recognition Assistant.exe
GET
200
82.156.94.48:80
http://scm-file-new-1301864755.cos.ap-beijing.myqcloud.com/cdn/update/UpdateFile.exe?t=781
CN
executable
25.9 Kb
whitelisted
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://cdn.oldfish.cn/lang/en-US.lang?t=638709064640967648&t=843
CN
compressed
17.8 Kb
unknown
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://ocr.oldfish.cn/code.ashx?op=config&type=TransCache&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064680153321&lang=English
CN
binary
8.39 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.13:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.13:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
unknown
5064
SearchApp.exe
2.21.110.146:443
AKAMAI-AS
DE
unknown
5712
OCR Recognition Assistant.exe
81.70.191.231:80
cdn.oldfish.cn
Shenzhen Tencent Computer Systems Company Limited
CN
unknown
5712
OCR Recognition Assistant.exe
203.107.6.88:123
ntp.aliyun.com
whitelisted
5712
OCR Recognition Assistant.exe
82.156.94.48:80
scm-file-new-1301864755.cos.ap-beijing.myqcloud.com
Shenzhen Tencent Computer Systems Company Limited
CN
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 23.216.77.13
  • 23.216.77.25
whitelisted
www.microsoft.com
  • 2.23.181.156
  • 95.101.149.131
whitelisted
ntp.aliyun.com
  • 203.107.6.88
whitelisted
cdn.oldfish.cn
  • 81.70.191.231
unknown
ocr.oldfish.cn
  • 81.70.191.231
unknown
2.100.168.192.in-addr.arpa
whitelisted
119.29.29.29
unknown
114.114.114.114
unknown

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO Tencent Cloud Storage Domain in DNS Lookup (myqcloud .com)
5712
OCR Recognition Assistant.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
5712
OCR Recognition Assistant.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
5712
OCR Recognition Assistant.exe
Misc activity
ET INFO Observed Tencent Cloud Storage Domain (myqcloud .com in TLS SNI)
No debug info