| File name: | verni-sber-setup.exe |
| Full analysis: | https://app.any.run/tasks/96b620b4-c963-4de0-9476-778ca8e57d79 |
| Verdict: | Malicious activity |
| Analysis date: | December 18, 2024, 06:35:13 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections |
| MD5: | 96EA5C411C2303963B1D16F1E45C8C7A |
| SHA1: | 11C780277216119181B9C6DBDF51A605BED0C836 |
| SHA256: | B5E76AD13D242B39C9D26DA482AAB4FF02DA7C3AADD3B613E0F0FD89999FD3A6 |
| SSDEEP: | 98304:2rq3Bdwo38mrBlvpuwUQt5Hd0z0JO3fTVQLSJ/I+WxwyKW5/2u:Jn |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:12 07:26:53+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 685056 |
| InitializedDataSize: | 544256 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa83bc |
| OSVersion: | 6.1 |
| ImageVersion: | - |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Sber |
| FileDescription: | Верни Сбер на iPhone Setup |
| FileVersion: | |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | Верни Сбер на iPhone |
| ProductVersion: | 1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 424 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2260 | "powershell.exe" -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\StartApp.ps1" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | verni-sber-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3296 | "C:\Program Files\WindowsApps\sber.installer-ios.release_1.6.74.0_x64__h71rsrpa9hat8\SberIntaller.exe" | C:\Program Files\WindowsApps\sber.installer-ios.release_1.6.74.0_x64__h71rsrpa9hat8\SberIntaller.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Sber Installer iOS Exit code: 0 Version: 1.1.1.0 Modules
| |||||||||||||||
| 5464 | "C:\WINDOWS\system32\explorer.exe" Shell:AppsFolder\sber.installer-ios.release_h71rsrpa9hat8!App | C:\Windows\SysWOW64\explorer.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6088 | C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6180 | "C:\Users\admin\Desktop\verni-sber-setup.exe" | C:\Users\admin\Desktop\verni-sber-setup.exe | explorer.exe | ||||||||||||
User: admin Company: Sber Integrity Level: MEDIUM Description: Верни Сбер на iPhone Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 6216 | "C:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmp" /SL5="$70302,1234887,1230336,C:\Users\admin\Desktop\verni-sber-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmp | — | verni-sber-setup.exe | |||||||||||
User: admin Company: Sber Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 6376 | "C:\Users\admin\Desktop\verni-sber-setup.exe" /SPAWNWND=$502E2 /NOTIFYWND=$70302 | C:\Users\admin\Desktop\verni-sber-setup.exe | verni-sber-setup.tmp | ||||||||||||
User: admin Company: Sber Integrity Level: HIGH Description: Верни Сбер на iPhone Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 6404 | "C:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmp" /SL5="$802A0,1234887,1230336,C:\Users\admin\Desktop\verni-sber-setup.exe" /SPAWNWND=$502E2 /NOTIFYWND=$70302 | C:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmp | verni-sber-setup.exe | ||||||||||||
User: admin Company: Sber Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 6436 | "powershell.exe" -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\CreateShortcut.ps1 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | verni-sber-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | 39B2693BEDF613F0BBCD5CF8054074791EAF78E3 |
Value: | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3 |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E32000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3 |
| Operation: | write | Name: | Blob |
Value: 140000000100000014000000D31E5925A5B93B40B89AB0184F29E241D7ACDA5A03000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E30F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E72000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | 06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D |
Value: | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D |
| Operation: | write | Name: | Blob |
Value: 140000000100000014000000B52027B98360C94738CB77BB2626F0759205DBDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D0F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583 | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3 |
| Operation: | write | Name: | Blob |
Value: 1900000001000000100000008C73F640B93CFBC6C8685903B0ECECBD0F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E703000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E3140000000100000014000000D31E5925A5B93B40B89AB0184F29E241D7ACDA5A2000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D |
| Operation: | write | Name: | Blob |
Value: 190000000100000010000000D9BD0F3B903E1E1B55E8A8E9BBC0E3360F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D140000000100000014000000B52027B98360C94738CB77BB2626F0759205DBDA200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583 | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583 | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3 |
| Operation: | write | Name: | Blob |
Value: 0F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E703000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E32000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B | |||
| (PID) Process: | (6636) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D |
| Operation: | write | Name: | Blob |
Value: 0F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6404 | verni-sber-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\is-DRA90.tmp | text | |
MD5:945B14063D5800823CEAC4EB942AED5A | SHA256:90A88D4A0BA3EE3CFDB0BDFAB1AD27FF2739E79273E99F567A4E3B0629A2017E | |||
| 6404 | verni-sber-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\SberCA-Root-Ext.cer | binary | |
MD5:F28FCA37783CB84CF4FDF515E0355A88 | SHA256:E77059CD24606A8A24043100EC7E23DB917BFC85054EE08B79CA71B43B8F4690 | |||
| 6404 | verni-sber-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\InstallApp.ps1 | text | |
MD5:945B14063D5800823CEAC4EB942AED5A | SHA256:90A88D4A0BA3EE3CFDB0BDFAB1AD27FF2739E79273E99F567A4E3B0629A2017E | |||
| 6404 | verni-sber-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\is-LC9OQ.tmp | binary | |
MD5:5521C0073F736F41E3BA6DA6FA825B71 | SHA256:D305AAFCEC0B4230276FB2E423054EDE5041ED74B436A689CB291F35E76D4E32 | |||
| 6180 | verni-sber-setup.exe | C:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmp | executable | |
MD5:EEE1E8103A35EAB4B7783E0FB868B50C | SHA256:77A896946A17831DC8B2943BEDC8B1DFE7ACB78556FA61945AE79C8E2055EC55 | |||
| 6376 | verni-sber-setup.exe | C:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmp | executable | |
MD5:EEE1E8103A35EAB4B7783E0FB868B50C | SHA256:77A896946A17831DC8B2943BEDC8B1DFE7ACB78556FA61945AE79C8E2055EC55 | |||
| 6404 | verni-sber-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\YourAppInstaller.appinstaller | xml | |
MD5:D5508C12A9968806E24C41F230189781 | SHA256:7BB8E93D92138E6560D3E7DD57D42126896E7D5A0070E03EC4FCC92075DF282D | |||
| 6636 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5pculs2f.4t4.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6636 | powershell.exe | C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\error_message_16 | text | |
MD5:907B09CA7EB5EC985131FED38FB5C3CA | SHA256:5DF2DFF167BC98968596C241C06CFB79E7B5821868242767C0E4098EEB139EF8 | |||
| 6636 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_eogl3bad.jrb.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.106:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 1.01 Kb | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 973 b | whitelisted |
5356 | svchost.exe | GET | 200 | 194.54.14.168:80 | http://www.sberbank.ru/sberca/cdp/sberca-root-ext.crl | RU | text | 1.18 Kb | whitelisted |
5340 | svchost.exe | GET | 200 | 2.16.164.106:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 1.01 Kb | whitelisted |
5356 | svchost.exe | GET | 200 | 194.54.14.168:80 | http://www.sberbank.ru/sberca/cdp/sberca-ext.crl | RU | binary | 10.7 Mb | whitelisted |
5356 | svchost.exe | GET | 200 | 194.54.14.168:80 | http://www.sberbank.ru/sberca/cdp/sberca-ext-web.crl | RU | text | 2.44 Kb | whitelisted |
3688 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | US | binary | 471 b | whitelisted |
6012 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | NL | binary | 408 b | whitelisted |
5356 | svchost.exe | GET | 200 | 84.252.147.198:80 | http://sberca.sber.ru/sberca/cdp/sberca-ext.crl | RU | binary | 10.7 Mb | unknown |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | US | binary | 312 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.164.106:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5340 | svchost.exe | 2.16.164.106:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5340 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.23.209.140:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
1176 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
cdn.sberbank.ru |
| whitelisted |
www.sberbank.ru |
| whitelisted |