File name:

anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe

Full analysis: https://app.any.run/tasks/3396a5de-610a-4efb-878f-b4b2e2de072d
Verdict: Malicious activity
Analysis date: January 21, 2025, 15:47:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
vobfus
worm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

97B492D8761A506200B32B82976DC39E

SHA1:

30BA3CAB153655194A152F66E82BAD4EB2181DBC

SHA256:

B79655CDE5913F66922B65571F53EFCD4FCB0864AC71E3EC78957012E429E873

SSDEEP:

49152:Q7HecD4dnbibBloVRpjf8iDVhaRZ2z9weAFO45/9yRTaktKoaQ/kR4EuwznulmQI:c+cD4dnJpj8iDeRIz5AFOecRTRwo7AIY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • VOBFUS mutex has been found

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Changes the autorun value in the registry

      • rundll32.exe (PID: 2744)
    • Registers / Runs the DLL via REGSVR32.EXE

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6284)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6512)
      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
      • rundll32.exe (PID: 2744)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
    • Reads security settings of Internet Explorer

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
    • Reads the Windows owner or organization settings

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Drops a system driver (possible attempt to evade defenses)

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
      • rundll32.exe (PID: 2744)
    • Uses RUNDLL32.EXE to load library

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Creates or modifies Windows services

      • rundll32.exe (PID: 2744)
      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • The process drops C-runtime libraries

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Process drops legitimate windows executable

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
  • INFO

    • Reads the computer name

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Create files in a temporary directory

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6284)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6512)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Checks supported languages

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6284)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6512)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
      • TextInputHost.exe (PID: 6900)
    • Detects InnoSetup installer (YARA)

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6284)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6512)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
    • Process checks computer location settings

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
    • Reads the software policy settings

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
    • Compiled with Borland Delphi (YARA)

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6320)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6512)
      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe (PID: 6284)
    • The process uses the downloaded file

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
      • runonce.exe (PID: 4528)
    • The sample compiled with english language support

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Creates files in the program directory

      • anvi-folder-locker-free-1.2.1370.0-installer.exe (PID: 6204)
    • Reads the machine GUID from the registry

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
    • Checks proxy server information

      • anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp (PID: 6552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 12.11.2371.8174
ProductVersionNumber: 12.11.2371.8174
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: FH Manager
FileVersion: 12.11.2371.8174
LegalCopyright: ©2023 FH Manager
OriginalFileName:
ProductName: FH Manager
ProductVersion: 12.11.2371.8174
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
19
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp no specs anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exe anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp #VOBFUS anvi-folder-locker-free-1.2.1370.0-installer.exe rundll32.exe runonce.exe no specs grpconv.exe no specs fltmc.exe no specs conhost.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe rundll32.exe no specs textinputhost.exe no specs startmenuexperiencehost.exe no specs tiworker.exe no specs searchapp.exe mobsync.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2744"C:\WINDOWS\system32\RUNDLL32.EXE" SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 C:\Users\admin\AppData\Local\Temp\nsnEB4F.tmp\drivers\amd64\AnviFPFltd.infC:\Windows\System32\rundll32.exe
anvi-folder-locker-free-1.2.1370.0-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
2828 /s "C:\Program Files (x86)\Anvisoft\Anvi Folder Locker\x64\PwdHelper64.dll"C:\Windows\System32\regsvr32.exe
regsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4164"C:\Windows\System32\grpconv.exe" -oC:\Windows\System32\grpconv.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4188"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wincorlib.dll
4320\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exefltMC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4528"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\System32\runonce.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
4672regsvr32 /s "C:\Program Files (x86)\Anvisoft\Anvi Folder Locker\x64\PwdHelper64.dll"C:\Windows\SysWOW64\regsvr32.exeanvi-folder-locker-free-1.2.1370.0-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4672C:\WINDOWS\System32\mobsync.exe -EmbeddingC:\Windows\System32\mobsync.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Sync Center
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mobsync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4724regsvr32 /s "C:\Program Files (x86)\Common Files\Anvisoft\CommonComponent\1.0\CommonComponent.dll"C:\Windows\SysWOW64\regsvr32.exeanvi-folder-locker-free-1.2.1370.0-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4740C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
13 660
Read events
13 546
Write events
112
Delete events
2

Modification events

(PID) Process:(4528) runonce.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:GrpConv
Value:
grpconv -o
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:FSFilter Activity Monitor
Value:
020000000100000002000000
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd
Operation:writeName:DebugFlags
Value:
0
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd
Operation:writeName:SupportedFeatures
Value:
3
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd\Instances
Operation:writeName:DefaultInstance
Value:
AnviFPFltd Instance
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd\Instances\AnviFPFltd Instance
Operation:writeName:Altitude
Value:
370030
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd\Instances\AnviFPFltd Instance
Operation:writeName:Flags
Value:
0
(PID) Process:(2744) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:GrpConv
Value:
grpconv -o
(PID) Process:(6204) anvi-folder-locker-free-1.2.1370.0-installer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AnviFPFltd
Operation:writeName:AppData
Value:
\??\C:\ProgramData\Anvisoft\Anvi Folder Locker\AppData.dat
(PID) Process:(4528) runonce.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
59
Suspicious files
39
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
6284anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exeC:\Users\admin\AppData\Local\Temp\is-53IHA.tmp\anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpexecutable
MD5:B1CCD4AA1F291484F869A1ED445A042C
SHA256:2B7951FDA6A71B45E02C65DC4B33EFBDF43189C0DA1AD8585D594B398893954E
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6204anvi-folder-locker-free-1.2.1370.0-installer.exeC:\Users\admin\AppData\Local\Temp\nsnEB4F.tmp\modern-wizard.bmpimage
MD5:4171EA1FBA20033D7E55226D5AD9C2E0
SHA256:381E0EF99DD0022E4F150C1080B2F14E41D4F74AA1A948ABCCD6D7EAEA1EAF07
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\mainlogo.pngbinary
MD5:1858299389B7DB4097C9DB5AA9CDEAB3
SHA256:BFD3E0ED67CABC38999F4626B919D95E960740D2DC6121183F9D1F3221CE36B8
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\is-4P8T9.tmpbinary
MD5:1858299389B7DB4097C9DB5AA9CDEAB3
SHA256:BFD3E0ED67CABC38999F4626B919D95E960740D2DC6121183F9D1F3221CE36B8
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\is-O2BHD.tmpimage
MD5:9FD278B8F33757D6BF36E0A86CFA4C1F
SHA256:70D1A84C73E28667AA56263CD31CC6145AECB1A834FCD9AF1D7623D56497F0AC
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\no.pngimage
MD5:D7ACCCA386FED204C44CD619E68214F4
SHA256:7447EC5A3A1AE0017EDF59C6A217F57C20B65474B14D502984093492C7975F74
6552anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpC:\Users\admin\AppData\Local\Temp\is-1EJFA.tmp\anvi-folder-locker-free-1.2.1370.0-installer.exeexecutable
MD5:13802ED2A5379554F1DE4FD425606E21
SHA256:904565D95478CFE9ABABD4385E65633A91215887AF48C64F8312AE1FC6CB22A9
6204anvi-folder-locker-free-1.2.1370.0-installer.exeC:\Program Files (x86)\Anvisoft\Anvi Folder Locker\AFLService.exeexecutable
MD5:128C1852AED4F8DEB89FC7C6BFE14B7D
SHA256:1FEF775EC94ED806E832CF9412C6984080DCB5EA0C3D122FCF055F12F05AFD38
6512anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.exeC:\Users\admin\AppData\Local\Temp\is-SGCDS.tmp\anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmpexecutable
MD5:B1CCD4AA1F291484F869A1ED445A042C
SHA256:2B7951FDA6A71B45E02C65DC4B33EFBDF43189C0DA1AD8585D594B398893954E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
28
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5628
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.21.65.154:443
www.bing.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6552
anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp
143.204.102.42:443
d3419h2vl8o3m4.cloudfront.net
AMAZON-02
US
whitelisted
6552
anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp
151.101.1.91:443
sc.filehippo.net
FASTLY
US
whitelisted
4
System
192.168.100.255:137
whitelisted
6552
anvi-folder-locker-free-1.2.1370.0-installer_b-w2m61.tmp
151.101.65.91:443
sc.filehippo.net
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.21.65.154
  • 2.21.65.132
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.73
  • 20.190.159.23
  • 40.126.31.71
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
d3419h2vl8o3m4.cloudfront.net
  • 143.204.102.42
  • 143.204.102.39
  • 143.204.102.148
  • 143.204.102.153
whitelisted
sc.filehippo.net
  • 151.101.1.91
  • 151.101.65.91
  • 151.101.129.91
  • 151.101.193.91
unknown
dl5.filehippo.com
  • 151.101.65.91
  • 151.101.129.91
  • 151.101.1.91
  • 151.101.193.91
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
Process
Message
regsvr32.exe
regsvr32.exe