File name:

verni-sber-setup.exe

Full analysis: https://app.any.run/tasks/96b620b4-c963-4de0-9476-778ca8e57d79
Verdict: Malicious activity
Analysis date: December 18, 2024, 06:35:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

96EA5C411C2303963B1D16F1E45C8C7A

SHA1:

11C780277216119181B9C6DBDF51A605BED0C836

SHA256:

B5E76AD13D242B39C9D26DA482AAB4FF02DA7C3AADD3B613E0F0FD89999FD3A6

SSDEEP:

98304:2rq3Bdwo38mrBlvpuwUQt5Hd0z0JO3fTVQLSJ/I+WxwyKW5/2u:Jn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 6636)
      • powershell.exe (PID: 6436)
      • powershell.exe (PID: 2260)
    • Changes powershell execution policy (Bypass)

      • verni-sber-setup.tmp (PID: 6404)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • verni-sber-setup.exe (PID: 6180)
      • verni-sber-setup.exe (PID: 6376)
      • verni-sber-setup.tmp (PID: 6404)
    • Reads security settings of Internet Explorer

      • verni-sber-setup.tmp (PID: 6216)
    • Reads the Windows owner or organization settings

      • verni-sber-setup.tmp (PID: 6404)
    • Starts POWERSHELL.EXE for commands execution

      • verni-sber-setup.tmp (PID: 6404)
    • The process executes Powershell scripts

      • verni-sber-setup.tmp (PID: 6404)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 6436)
    • Reads settings of System Certificates

      • SberIntaller.exe (PID: 3296)
    • Reads the Internet Settings

      • SberIntaller.exe (PID: 3296)
    • Adds/modifies Windows certificates

      • powershell.exe (PID: 6636)
  • INFO

    • Process checks computer location settings

      • verni-sber-setup.tmp (PID: 6216)
    • Create files in a temporary directory

      • verni-sber-setup.exe (PID: 6180)
      • verni-sber-setup.exe (PID: 6376)
      • verni-sber-setup.tmp (PID: 6404)
    • Checks supported languages

      • verni-sber-setup.exe (PID: 6376)
      • verni-sber-setup.tmp (PID: 6216)
      • verni-sber-setup.exe (PID: 6180)
      • verni-sber-setup.tmp (PID: 6404)
      • SberIntaller.exe (PID: 3296)
    • Reads the computer name

      • verni-sber-setup.tmp (PID: 6216)
      • verni-sber-setup.exe (PID: 6376)
      • verni-sber-setup.tmp (PID: 6404)
      • SberIntaller.exe (PID: 3296)
    • The process uses the downloaded file

      • powershell.exe (PID: 6636)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 6636)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 6636)
    • Manual execution by a user

      • SberIntaller.exe (PID: 3296)
    • Creates files or folders in the user directory

      • SberIntaller.exe (PID: 3296)
    • Reads the software policy settings

      • SberIntaller.exe (PID: 3296)
    • Creates files in the program directory

      • SberIntaller.exe (PID: 3296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 544256
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Sber
FileDescription: Верни Сбер на iPhone Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Верни Сбер на iPhone
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
14
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start verni-sber-setup.exe verni-sber-setup.tmp no specs verni-sber-setup.exe verni-sber-setup.tmp powershell.exe no specs conhost.exe no specs Delivery Optimization User no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs explorer.exe no specs explorer.exe no specs sberintaller.exe

Process information

PID
CMD
Path
Indicators
Parent process
424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2260"powershell.exe" -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\StartApp.ps1"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeverni-sber-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3296"C:\Program Files\WindowsApps\sber.installer-ios.release_1.6.74.0_x64__h71rsrpa9hat8\SberIntaller.exe" C:\Program Files\WindowsApps\sber.installer-ios.release_1.6.74.0_x64__h71rsrpa9hat8\SberIntaller.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Sber Installer iOS
Exit code:
0
Version:
1.1.1.0
Modules
Images
c:\program files\windowsapps\sber.installer-ios.release_1.6.74.0_x64__h71rsrpa9hat8\sberintaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5464"C:\WINDOWS\system32\explorer.exe" Shell:AppsFolder\sber.installer-ios.release_h71rsrpa9hat8!App C:\Windows\SysWOW64\explorer.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcp_win.dll
c:\windows\syswow64\ucrtbase.dll
6088C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\twinapi.dll
6180"C:\Users\admin\Desktop\verni-sber-setup.exe" C:\Users\admin\Desktop\verni-sber-setup.exe
explorer.exe
User:
admin
Company:
Sber
Integrity Level:
MEDIUM
Description:
Верни Сбер на iPhone Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\verni-sber-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6216"C:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmp" /SL5="$70302,1234887,1230336,C:\Users\admin\Desktop\verni-sber-setup.exe" C:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmpverni-sber-setup.exe
User:
admin
Company:
Sber
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-lab6s.tmp\verni-sber-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6376"C:\Users\admin\Desktop\verni-sber-setup.exe" /SPAWNWND=$502E2 /NOTIFYWND=$70302 C:\Users\admin\Desktop\verni-sber-setup.exe
verni-sber-setup.tmp
User:
admin
Company:
Sber
Integrity Level:
HIGH
Description:
Верни Сбер на iPhone Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\verni-sber-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6404"C:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmp" /SL5="$802A0,1234887,1230336,C:\Users\admin\Desktop\verni-sber-setup.exe" /SPAWNWND=$502E2 /NOTIFYWND=$70302 C:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmp
verni-sber-setup.exe
User:
admin
Company:
Sber
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-n96hg.tmp\verni-sber-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6436"powershell.exe" -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\CreateShortcut.ps1C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeverni-sber-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
30 770
Read events
30 721
Write events
23
Delete events
26

Modification events

(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:39B2693BEDF613F0BBCD5CF8054074791EAF78E3
Value:
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3
Operation:writeName:Blob
Value:
03000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E32000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3
Operation:writeName:Blob
Value:
140000000100000014000000D31E5925A5B93B40B89AB0184F29E241D7ACDA5A03000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E30F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E72000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D
Value:
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D
Operation:writeName:Blob
Value:
140000000100000014000000B52027B98360C94738CB77BB2626F0759205DBDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D0F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3
Operation:writeName:Blob
Value:
1900000001000000100000008C73F640B93CFBC6C8685903B0ECECBD0F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E703000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E3140000000100000014000000D31E5925A5B93B40B89AB0184F29E241D7ACDA5A2000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D
Operation:writeName:Blob
Value:
190000000100000010000000D9BD0F3B903E1E1B55E8A8E9BBC0E3360F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D140000000100000014000000B52027B98360C94738CB77BB2626F0759205DBDA200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D
Operation:writeName:Blob
Value:
03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\39B2693BEDF613F0BBCD5CF8054074791EAF78E3
Operation:writeName:Blob
Value:
0F000000010000002000000086DBDE7C0E483E0920424E9761DB9851CFF39CE4852667E2DF026E8EF4FBC1E703000000010000001400000039B2693BEDF613F0BBCD5CF8054074791EAF78E32000000001000000C6050000308205C2308203AAA003020102020900DCC5BB8DF06A87B5300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3230313032393134353134335A170D3430313032343134353134335A3044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F742045787430820222300D06092A864886F70D01010105000382020F003082020A0282020100D5C1542AC30BEE6BB680EF526FFCB6470041C8E51D41141C616083E2237AFF7B90C98C6B62667DB3CA6AC348FE1D0632CFFDAB441DF6F34855594D9C5C6519243A2030DDE7F119E95C7AD184BFD2A7E44E34831C0B540D5B52F641F194B017B827FEB8532C065F713638987F5A6C2E4D106F57CD8077B7497E20EA0EE8E0176B3863FC369FBB5F134E2941D97B0163E87CBAF774B919B435975609B033AB6424873F01E27FC17EA0F2F3340B2E892B6DD9026A176300A565153BF4A9C1684D62DDCAA75DC36FD4A9AFA9C6AE5D8C40E73D6D631373F71CB9F3E9DEC6650C754EE3EEFA062F641B51726D4C49E88DF9744121A0D2F3A6FB74BE1B82C0299007A9D64337B6C99DF6CABA5C20880C472CA1A787DFC2A942D2E4D808E087B7F313FD17A1848EEDE9446273941F23F7FFB4F51E6ED6CFB2518408EBB90884A0DB766E5849922A7228C3B2FD67D60D84E0F7B75B2BB5468913D15E0CEE49B9B189A9AC88CCA6DB76187D2E3735582F622C46249489AF50761F26EFC73285947BC83DAF2994166E1D86B53C823D040FA7BAA8CB066F371A58A829CEF262B8B2B475288153C49992D1BDA622872BD9E9BEB3E80C641BC25FBB638086135A962F2D55D3A6F53F8EF222149E8347F62AD86238F52A0235EF4FD19F4E60452015C0DC85F35DFCEFF173C3C6C830F088C538C14E4C46F26DFDA59DA31A9DC7CFCBFD08879CD90203010001A381B63081B3301D0603551D0E04160414D31E5925A5B93B40B89AB0184F29E241D7ACDA5A30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300F0603551D130101FF040530030101FF300B0603551D0F040403020186300D06092A864886F70D01010B050003820201007AE3A48A3C0D767A609656DFB309B0D243B1A04C210C7735AD5572394E7DC3953A8C4617757CE0518C57DAAADE92EB459BC2E73DE605232649B643AA5CC900E510040FA55B29C108A70E335743D48B7D331B17E96B7326481EEC4071203875716EFCB535E62FE46BA562C8DA0D18B6DF28AB7E968A4FFBE0947C46A0B40C35E7ED789885A15B71D70E1DB35243A363B8FDEADF58CD2D01F2DFCEBF8A07FB53B975647ECA6A11FCC4C1B0EBE25C032DE59DEC611A89EC8F3F0B437DE85EF598D0D15A84DEC6613581F4DEF1D7D0A859A0DCBAFA7FAE7D5B8913B51C70EA73E29616CF0994A9204B4EA6B50FA7C6F24AC9DD268EC3F74D2DE7C9F39D8D64F081D1B15FA9FF9893B12B18B368D6044DC784765BF4897A65A3B9A7C368E866DE4AC4341D6704F981EF5814D1C33D956C22425C24407A6B50AEF529A61DAECDEE710B2687E2D8410F0879997E6593BFB6DA8EC546324F8DCAD61CDB984FDBA4FD26D560FA5BB1120A31E9B60E86677CF8DEBB22F8910E95A85C99EBAC1E3B33F25A16A6F2723E7BD4031D58882FCFF37C4E9BBCD28E3B0D99B383CA9A808199CEEE8082A8ED672E1EE1BEEF1AE115DC489513C6E3AC4A2145DCC1E5B37FE78694CFF9B854364A556B73391A357784D1C4A01E69C4D1093F2281C63BD45FC97F160A8D2759D5C6AA61EE195CA2F52F19FEE3450F20F69A1E4C58651AAA1E0A7D6AC39B
(PID) Process:(6636) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06984B07BD806E6AB86BAB47D2FF4B0DAC83A37D
Operation:writeName:Blob
Value:
0F0000000100000020000000A019C5C7E116BE750D9635204408A4568ECE7157BEACA27C814A9BC33A419DDA03000000010000001400000006984B07BD806E6AB86BAB47D2FF4B0DAC83A37D200000000100000069060000308206653082044DA003020102021061E9DC84E3C4310C6509F9F7262D1D2A300D06092A864886F70D01010B05003044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874301E170D3232303232343135333431355A170D3332303232323135333431355A3043310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613117301506035504030C0E536265724341204578742057656230820222300D06092A864886F70D01010105000382020F003082020A0282020100A351633B5F223BBC07E28842A59F3BA38826C48E13BACC77BD3C3EF5DA62E20B343A2145AE704EF1BB10BDD139F9210BDCCBDC24A5656DEAAB17B0603477B4ECCF27F431DDA2D440A4389D7B045C0F343379C4E70C57D7ABCD43DDEBC9B253E768CD517F16759FC35D570A73FBFB227A468168F95A72EA20016611DFED9CC7DAB771FC98F43423313D77FB04D41B715C36F427A8A9719A9FBF3EE4D7C2A088399FC7DCD2D85F8D7AECC32492128C5EC2DF2EB1BC9A46FD84B7C8D1AA6E4629DE6218F59F0C600583129735FC951AADA3BF4EA83EBE9C394E99E4D9D067E35B2E2AF02A5946DFD6E985CC401E466D1C8D5B4FB26B0D385F2617194A38443A28E43B87C01081348938663688D00FFEB449D06EA2F8FA93FD5DF7FF3470F9228DE84B0F8524D8E3028D82EB3D526F4D12542A0F3AF2485657811C90964BD1BC49877A889BBC03AB4A29895FD15B0EED31F53CBFA9297D3C6DB4FB649CB7E82B6267684BA66CB3C907523F526EA0AF6DF520461C6235F99B0DB116356378A79CBF10A5BA72DC5C3832E698342051333802BA59AA8DB026CBDC4477B11C0486872C4CCBD4F1691493E506CDEF985B56532E2A6106A18CFC3C176F0D9EE08D1F525481A58903627C4BE57D845A4B24BD0E964EB6269313374B7D341B662498A2A038B7BF7C2A5E7D0F3A4D14D0B0DC29691C7AF9B501953848C969D0CD93E82A33284B0203010001A38201523082014E300F0603551D130101FF040530030101FF301D0603551D0E04160414B52027B98360C94738CB77BB2626F0759205DBDA30740603551D23046D306B8014D31E5925A5B93B40B89AB0184F29E241D7ACDA5AA148A4463044310B3009060355040613025255311B3019060355040A0C125362657262616E6B206F66205275737369613118301606035504030C0F53626572434120526F6F7420457874820900DCC5BB8DF06A87B5300B0603551D0F04040302018630460603551D1F043F303D303BA039A0378635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6364702F7362657263612D726F6F742D6578742E63726C305106082B0601050507010104453043304106082B060105050730028635687474703A2F2F7777772E7362657262616E6B2E72752F7362657263612F6169612F7362657263612D726F6F742D6578742E637274300D06092A864886F70D01010B05000382020100B0D5BBF22E94277F3FAD321BF38CE403957F791ECA390E00FF97275C24B466CBFD1718F75B5815A00554B158EA095A60EA65B4AE313917C00D908EEF794A830F32CAB4DA98F56081E4E13B5535BA29DFE2C23990A3FBEB43AE32189C12ED4A1AC86D116784907F19E387E59D762538F6E8E004BF305757B05257BFBF4C63410CCF1E8424CE88C1A0B2289BE65A25E160A39BFA52F7B2819069F0ED7122FAB8F62DCDE2E1512AB164685710BAA96990A6548429111E8E1838A5A7AB5164F0998E3A698A8E68667541391E9923BAB81E821D35201F46DC572F1530BDB19D780F45F5C575D7484175F99B5ACC21BA274DAFBE3909298FD13CBE2BD362F81A695EAE70B053D128C10AE04F9ABE275B54BA6CE5C22C3D797B15AA93FA76446D6ACF5361DD07679085E2777E1B74CF50DD118B070CE8D79A0D247A949CB835A31D7F3F294F5492A6FD224EC6651D898D71497D7D323D7E3FEDF45FB7C8F8213BD10AF3848AE3BC3CB28C112FEEACD085921E469F314F37A21F549AAB7B7FC2815C5B10F271CD3BC0055BDB0F846C738CCAF2CD95CA4644759F82389512206C8417C2A9E12F930902143A8BA610A7CEDF3246953B3099BA3A5AC9456CCA02976CEDC8123931B11CAA625EA4BAE713FE1DA670AE19A793AFDA872FE3D33E5789CADF0148ACA90C9767D27D80C648925169F7F14DC88FCB9EDA252649E25F5CE1458C3583
Executable files
3
Suspicious files
9
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
6404verni-sber-setup.tmpC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\is-DRA90.tmptext
MD5:945B14063D5800823CEAC4EB942AED5A
SHA256:90A88D4A0BA3EE3CFDB0BDFAB1AD27FF2739E79273E99F567A4E3B0629A2017E
6404verni-sber-setup.tmpC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\SberCA-Root-Ext.cerbinary
MD5:F28FCA37783CB84CF4FDF515E0355A88
SHA256:E77059CD24606A8A24043100EC7E23DB917BFC85054EE08B79CA71B43B8F4690
6404verni-sber-setup.tmpC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\InstallApp.ps1text
MD5:945B14063D5800823CEAC4EB942AED5A
SHA256:90A88D4A0BA3EE3CFDB0BDFAB1AD27FF2739E79273E99F567A4E3B0629A2017E
6404verni-sber-setup.tmpC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\is-LC9OQ.tmpbinary
MD5:5521C0073F736F41E3BA6DA6FA825B71
SHA256:D305AAFCEC0B4230276FB2E423054EDE5041ED74B436A689CB291F35E76D4E32
6180verni-sber-setup.exeC:\Users\admin\AppData\Local\Temp\is-LAB6S.tmp\verni-sber-setup.tmpexecutable
MD5:EEE1E8103A35EAB4B7783E0FB868B50C
SHA256:77A896946A17831DC8B2943BEDC8B1DFE7ACB78556FA61945AE79C8E2055EC55
6376verni-sber-setup.exeC:\Users\admin\AppData\Local\Temp\is-N96HG.tmp\verni-sber-setup.tmpexecutable
MD5:EEE1E8103A35EAB4B7783E0FB868B50C
SHA256:77A896946A17831DC8B2943BEDC8B1DFE7ACB78556FA61945AE79C8E2055EC55
6404verni-sber-setup.tmpC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\YourAppInstaller.appinstallerxml
MD5:D5508C12A9968806E24C41F230189781
SHA256:7BB8E93D92138E6560D3E7DD57D42126896E7D5A0070E03EC4FCC92075DF282D
6636powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5pculs2f.4t4.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6636powershell.exeC:\Users\admin\AppData\Local\Temp\is-NDJ12.tmp\error_message_16text
MD5:907B09CA7EB5EC985131FED38FB5C3CA
SHA256:5DF2DFF167BC98968596C241C06CFB79E7B5821868242767C0E4098EEB139EF8
6636powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_eogl3bad.jrb.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
55
DNS requests
35
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
5356
svchost.exe
GET
200
194.54.14.168:80
http://www.sberbank.ru/sberca/cdp/sberca-root-ext.crl
RU
text
1.18 Kb
whitelisted
5340
svchost.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
5356
svchost.exe
GET
200
194.54.14.168:80
http://www.sberbank.ru/sberca/cdp/sberca-ext.crl
RU
binary
10.7 Mb
whitelisted
5356
svchost.exe
GET
200
194.54.14.168:80
http://www.sberbank.ru/sberca/cdp/sberca-ext-web.crl
RU
text
2.44 Kb
whitelisted
3688
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
6012
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
5356
svchost.exe
GET
200
84.252.147.198:80
http://sberca.sber.ru/sberca/cdp/sberca-ext.crl
RU
binary
10.7 Mb
unknown
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
312 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5340
svchost.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5340
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.185
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.149
  • 2.23.209.187
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
cdn.sberbank.ru
  • 151.236.71.248
whitelisted
www.sberbank.ru
  • 194.54.14.168
whitelisted

Threats

No threats detected
No debug info