File name:

OCR Recognition Assistant.exe

Full analysis: https://app.any.run/tasks/21660a1b-98d2-4a89-88de-cd120586eccf
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 27, 2024, 06:27:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

096186DA1116602DB0095BD33F00B340

SHA1:

85E8DA243708FA5CAAE9D4BD769FEF6A30578877

SHA256:

B16813C8A8111F24FF992726B9B8D3A21E6B9D5930B536EB3EE547D7083A7F7E

SSDEEP:

49152:aaoE7OTGKJtlJ1lX8fqFHglqu8OBG8JgtYi73TyEPQ7oxgnrQeM:aJGKJtL1liJou88geSaPnrQeM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OCR Recognition Assistant.exe (PID: 5712)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • OCR Recognition Assistant.exe (PID: 5712)
    • Uses NSLOOKUP.EXE to check DNS info

      • OCR Recognition Assistant.exe (PID: 5712)
    • Executable content was dropped or overwritten

      • OCR Recognition Assistant.exe (PID: 5712)
    • Process requests binary or script from the Internet

      • OCR Recognition Assistant.exe (PID: 5712)
    • There is functionality for taking screenshot (YARA)

      • OCR Recognition Assistant.exe (PID: 5712)
    • Potential Corporate Privacy Violation

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads Internet Explorer settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads Microsoft Outlook installation path

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks Windows Trust Settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • Starts CMD.EXE for commands execution

      • OCR Recognition Assistant.exe (PID: 5712)
  • INFO

    • Sends debugging messages

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads the computer name

      • OCR Recognition Assistant.exe (PID: 5712)
    • Disables trace logs

      • OCR Recognition Assistant.exe (PID: 5712)
    • Creates files or folders in the user directory

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads the machine GUID from the registry

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks supported languages

      • OCR Recognition Assistant.exe (PID: 5712)
      • identity_helper.exe (PID: 3848)
    • Create files in a temporary directory

      • OCR Recognition Assistant.exe (PID: 5712)
    • Reads the software policy settings

      • OCR Recognition Assistant.exe (PID: 5712)
    • Checks proxy server information

      • OCR Recognition Assistant.exe (PID: 5712)
    • The process uses the downloaded file

      • OCR Recognition Assistant.exe (PID: 5712)
    • Application launched itself

      • msedge.exe (PID: 5616)
      • msedge.exe (PID: 6520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:20 06:25:26+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 2519040
InitializedDataSize: 142336
UninitializedDataSize: -
EntryPoint: 0x268e3e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.6.1.0
ProductVersionNumber: 4.6.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: OCR文字识别助手(2024-12-20)
CompanyName: SmartOldFish
FileDescription:
FileVersion: 4.6.1
InternalName: OCR Recognition Assistant.exe
LegalCopyright: Copyright © 2019-2024 OldFish.CN
OriginalFileName: OCR Recognition Assistant.exe
ProductName: OCR助手
ProductVersion: 4.6.1
AssemblyVersion: 4.6.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
52
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ocr recognition assistant.exe nslookup.exe nslookup.exe conhost.exe no specs conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs nslookup.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7ff821b75fd8,0x7ff821b75fe4,0x7ff821b75ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=5300 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4116 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2932 --field-trial-handle=2388,i,15699820765503010400,18247214989735170368,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3664"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5168 --field-trial-handle=2388,i,15699820765503010400,18247214989735170368,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4752 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3820"nslookup.exe"C:\Windows\SysWOW64\nslookup.exe
OCR Recognition Assistant.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
nslookup
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3848"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5864 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4052"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6284 --field-trial-handle=2356,i,6959267296490060470,17849715688318418440,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4596\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenslookup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 439
Read events
16 333
Write events
100
Delete events
6

Modification events

(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5712) OCR Recognition Assistant.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OCR Recognition Assistant_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
9
Suspicious files
258
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\ico\百度.icoimage
MD5:978D975CE4D8881BCB6F3FF15106016F
SHA256:2E8E7EFB45141FB5D0879411570B76C09D0F7E54777325F643340775A80F10D1
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\localGroup.dattext
MD5:2570967EF13BCE537CD06B228C8F1816
SHA256:B5405CB84A1B1CFB47AF3D6F7E100E714609C4E3E45D4E9DF9779E9016F01584
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225Fbinary
MD5:FA561D6502881F082B20239E87F55BFF
SHA256:795584D5FDDB735F9E119DE0087030FD5E36858CAC8FD8665D09FBA6DDEB3AE2
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013binary
MD5:F0525C800CC5976C3B486F75CF97BF36
SHA256:6BF97DFF0ACA3671743304113B8AE3F40DE8EB4A0E25AF67C136E87F0E13344C
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225Fbinary
MD5:EBBBEAE85BC38A47702DE931E1544C03
SHA256:8B0B0CC38B84AC135A1A6DF1B40030CC8220EABA3B0C93314D5A9F467A334A3A
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013binary
MD5:105BDB059BD2A82F76F07190F7C3C100
SHA256:A263171A70D14EAFEEDED4E4D7DEFA53C8809862A89839A031C64E01C8EA00B8
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\ico\腾讯.icoimage
MD5:3C3AB779C36E3AF9DB287E251090F89A
SHA256:17B8E903CFF07651956CF660BD6B1CECBDCD5D85D1DEF43E356A4DE5086675AA
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Widget\Microsoft.ApplicationInsights.dllexecutable
MD5:5B2672BDD65C18C6ECF1A24EAFD7122A
SHA256:03DF131138A32F5DF9591BBDA9A512FFC9528A4E16D5683751EB24A1B015A0CE
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Local\Temp\tmp7C28.tmpcompressed
MD5:50BDA8FC4A2C05245C94BC4D2ADD3E7F
SHA256:7D60CEA128C1C095E286A9F360CEF779E2366D66DFD8126D0EB2BD6751B1B135
5712OCR Recognition Assistant.exeC:\Users\admin\AppData\Roaming\OCR\Cache\ico\不限.icoimage
MD5:55E0C158921C7B3F33552A460B3AE640
SHA256:2B297974DF909CEC3AECC7702AEA3232A52C148D30BB3BE99CC37BCA0D721AAC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
60
TCP/UDP connections
77
DNS requests
86
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.13:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.13:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://cdn.oldfish.cn/ext/Microsoft.ApplicationInsights.txt?t=638709064624716354
unknown
unknown
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5712
OCR Recognition Assistant.exe
HEAD
200
81.70.191.231:80
http://cdn.oldfish.cn/lang/en-US.lang?t=638709064640967648
unknown
unknown
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://ocr.oldfish.cn/code.ashx?op=config&type=TransCache&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064680153321&lang=English
unknown
unknown
5712
OCR Recognition Assistant.exe
GET
200
82.156.94.48:80
http://scm-file-new-1301864755.cos.ap-beijing.myqcloud.com/cdn/update/update.xml?t=638708776709248257&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064700465344&lang=English
unknown
whitelisted
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://ocr.oldfish.cn/code.ashx?op=configs&type=serverGroup,localGroup,localImage&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064700312942&lang=English
unknown
unknown
5712
OCR Recognition Assistant.exe
GET
200
81.70.191.231:80
http://ocr.oldfish.cn/code.ashx?op=health&mac=DESKTOP-JGLLJLD-admin&uid=e5431d1d03b156b9b18f8dd8d0921bfc&ver=2024-12-20%2000:00:00&tick=638709064643312122&lang=
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.13:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.13:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
unknown
5064
SearchApp.exe
2.21.110.146:443
AKAMAI-AS
DE
unknown
5712
OCR Recognition Assistant.exe
81.70.191.231:80
cdn.oldfish.cn
Shenzhen Tencent Computer Systems Company Limited
CN
unknown
5712
OCR Recognition Assistant.exe
203.107.6.88:123
ntp.aliyun.com
whitelisted
5712
OCR Recognition Assistant.exe
82.156.94.48:80
scm-file-new-1301864755.cos.ap-beijing.myqcloud.com
Shenzhen Tencent Computer Systems Company Limited
CN
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 23.216.77.13
  • 23.216.77.25
whitelisted
www.microsoft.com
  • 2.23.181.156
  • 95.101.149.131
whitelisted
ntp.aliyun.com
  • 203.107.6.88
whitelisted
cdn.oldfish.cn
  • 81.70.191.231
unknown
ocr.oldfish.cn
  • 81.70.191.231
unknown
2.100.168.192.in-addr.arpa
whitelisted
119.29.29.29
unknown
114.114.114.114
unknown

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO Tencent Cloud Storage Domain in DNS Lookup (myqcloud .com)
5712
OCR Recognition Assistant.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
5712
OCR Recognition Assistant.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
5712
OCR Recognition Assistant.exe
Misc activity
ET INFO Observed Tencent Cloud Storage Domain (myqcloud .com in TLS SNI)
No debug info