URL:

https://androiddatahost.com/wp-content/uploads/Amlogic_USB_Burning_Tool_v3.2.8.zip

Full analysis: https://app.any.run/tasks/7ba128ff-f4a4-41cc-8fe0-43fa00f903a1
Verdict: Malicious activity
Analysis date: February 25, 2024, 11:57:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

3456252E45C408D5D3D9E2312BDF3884

SHA1:

906B635B79D177A6F965BD79E5BA2E7E4E763F95

SHA256:

BA270840410E34F0C661B99E7B74419B2977680D360FDEF675EB4F3D1238B75D

SSDEEP:

3:N8FMB4qIbOlAQy/snRXkRJbLVfUn:22B4qIbOlAZuxkR5Vcn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Amlogic USB Burning Tool v3.2.8.exe (PID: 2484)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpinst32.exe (PID: 1404)
      • Amlogic USB Burning Tool v3.2.8.exe (PID: 3308)
      • drvinst.exe (PID: 3528)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3528)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Amlogic USB Burning Tool v3.2.8.exe (PID: 2484)
      • Amlogic USB Burning Tool v3.2.8.exe (PID: 3308)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpinst32.exe (PID: 1404)
      • drvinst.exe (PID: 3528)
    • Process drops legitimate windows executable

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpinst32.exe (PID: 1404)
      • drvinst.exe (PID: 3528)
    • Reads security settings of Internet Explorer

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Reads the Windows owner or organization settings

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Starts CMD.EXE for commands execution

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • The process drops C-runtime libraries

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Drops a system driver (possible attempt to evade defenses)

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Reads the Internet Settings

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3404)
    • Reads settings of System Certificates

      • dpscat.exe (PID: 480)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3528)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 3528)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2348)
    • Adds/modifies Windows certificates

      • dpscat.exe (PID: 480)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2472)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2472)
    • Manual execution by a user

      • WinRAR.exe (PID: 796)
      • Amlogic USB Burning Tool v3.2.8.exe (PID: 3308)
      • explorer.exe (PID: 3992)
      • Aml_Burn_Tool.exe (PID: 572)
    • The process uses the downloaded file

      • iexplore.exe (PID: 2472)
      • WinRAR.exe (PID: 796)
    • Checks supported languages

      • Amlogic USB Burning Tool v3.2.8.exe (PID: 3308)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2432)
      • Amlogic USB Burning Tool v3.2.8.exe (PID: 2484)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpscat.exe (PID: 480)
      • dpinst32.exe (PID: 1404)
      • drvinst.exe (PID: 3528)
    • Create files in a temporary directory

      • Amlogic USB Burning Tool v3.2.8.exe (PID: 3308)
      • Amlogic USB Burning Tool v3.2.8.exe (PID: 2484)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpinst32.exe (PID: 1404)
    • Reads the computer name

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2432)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
      • dpscat.exe (PID: 480)
      • dpinst32.exe (PID: 1404)
      • drvinst.exe (PID: 3528)
    • Creates a software uninstall entry

      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Reads the machine GUID from the registry

      • dpscat.exe (PID: 480)
      • dpinst32.exe (PID: 1404)
      • drvinst.exe (PID: 3528)
    • Creates files in the program directory

      • dpscat.exe (PID: 480)
      • Amlogic USB Burning Tool v3.2.8.tmp (PID: 2244)
    • Reads the software policy settings

      • dpscat.exe (PID: 480)
      • drvinst.exe (PID: 3528)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 3528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
16
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe explorer.exe no specs winrar.exe no specs amlogic usb burning tool v3.2.8.exe amlogic usb burning tool v3.2.8.tmp no specs amlogic usb burning tool v3.2.8.exe amlogic usb burning tool v3.2.8.tmp cmd.exe no specs taskkill.exe no specs dpscat.exe dpinst32.exe drvinst.exe vssvc.exe no specs aml_burn_tool.exe no specs aml_tool_updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
480"C:\Amlogic\Aml_Burn_Tool\V3\Driver\dpscat.exe"C:\Amlogic\Aml_Burn_Tool\V3\Driver\dpscat.exe
Amlogic USB Burning Tool v3.2.8.tmp
User:
admin
Company:
http://libusb-win32.sourceforge.net
Integrity Level:
HIGH
Description:
Inf catalog and signing tool
Exit code:
0
Version:
3.0.6.0
Modules
Images
c:\amlogic\aml_burn_tool\v3\driver\dpscat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
572"C:\Amlogic\Aml_Burn_Tool\V3\Aml_Burn_Tool.exe" C:\Amlogic\Aml_Burn_Tool\V3\Aml_Burn_Tool.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
796"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8.zip" C:\Users\admin\Downloads\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
896.\amlogic_tool_update\Aml_tool_updater.exe hideC:\Amlogic\Aml_Burn_Tool\V3\amlogic_tool_update\Aml_tool_updater.exeAml_Burn_Tool.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
1404"C:\Amlogic\Aml_Burn_Tool\V3\Driver\dpinst32.exe"C:\Amlogic\Aml_Burn_Tool\V3\Driver\dpinst32.exe
Amlogic USB Burning Tool v3.2.8.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\amlogic\aml_burn_tool\v3\driver\dpinst32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2244"C:\Users\admin\AppData\Local\Temp\is-U4EDL.tmp\Amlogic USB Burning Tool v3.2.8.tmp" /SL5="$70238,39316483,437760,C:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Amlogic USB Burning Tool v3.2.8.exe" /SPAWNWND=$80244 /NOTIFYWND=$D0216 C:\Users\admin\AppData\Local\Temp\is-U4EDL.tmp\Amlogic USB Burning Tool v3.2.8.tmp
Amlogic USB Burning Tool v3.2.8.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u4edl.tmp\amlogic usb burning tool v3.2.8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2348C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2432"C:\Users\admin\AppData\Local\Temp\is-6DUI5.tmp\Amlogic USB Burning Tool v3.2.8.tmp" /SL5="$D0216,39316483,437760,C:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Amlogic USB Burning Tool v3.2.8.exe" C:\Users\admin\AppData\Local\Temp\is-6DUI5.tmp\Amlogic USB Burning Tool v3.2.8.tmpAmlogic USB Burning Tool v3.2.8.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6dui5.tmp\amlogic usb burning tool v3.2.8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2472"C:\Program Files\Internet Explorer\iexplore.exe" "https://androiddatahost.com/wp-content/uploads/Amlogic_USB_Burning_Tool_v3.2.8.zip"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2484"C:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Amlogic USB Burning Tool v3.2.8.exe" /SPAWNWND=$80244 /NOTIFYWND=$D0216 C:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Amlogic USB Burning Tool v3.2.8.exe
Amlogic USB Burning Tool v3.2.8.tmp
User:
admin
Company:
Amlogic, Inc.
Integrity Level:
HIGH
Description:
V3_Aml_Burn_Tool Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\amlogic_usb_burning_tool_v3.2.8\amlogic usb burning tool v3.2.8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
35 139
Read events
34 904
Write events
193
Delete events
42

Modification events

(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31090657
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31090657
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2472) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
314
Suspicious files
105
Text files
25
Unknown types
28

Dropped files

PID
Process
Filename
Type
2472iexplore.exeC:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8.zip
MD5:
SHA256:
796WinRAR.exeC:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Amlogic USB Burning Tool v3.2.8.exe
MD5:
SHA256:
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Amlogic_USB_Burning_Tool_v3.2.8[1].zipcompressed
MD5:6F1BCD8FA77636379BE94C38FB98DED1
SHA256:D90B33BD8BF4145C882F0FBACECEDBADFEF0D21294C1FB83EA32632A35127BE1
796WinRAR.exeC:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Credits.txttext
MD5:C9C67CDA7CEDABD44683EB2FFCF12AB4
SHA256:364A909CACB9C079536A559C2FD29C39CB4BCEE4CE3899C646530B0D27D39FDC
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562binary
MD5:D91B219996FCDD46EA10EE6DF8449465
SHA256:549A91DDCD00C104F7D60241FCD169DAF49AC93D772B173DDC4F4144B3F277B0
2472iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{0CD3D2CF-D3D5-11EE-AE0A-12A9866C77DE}.datbinary
MD5:3B1CC27BDEA3EE4C140646AE7C3777D9
SHA256:8A4F32A6E5DCC825CBE3375D242865E4A4F3B8E75A7A18704F7B6FC5548EC04F
796WinRAR.exeC:\Users\admin\Downloads\Amlogic_USB_Burning_Tool_v3.2.8\Driver\Download.urlbinary
MD5:4FD87762C9B9E79C86764CC0C68FDBCB
SHA256:B29061450E51F38F5CF31CEF5C9C4F958867344542D7CA8F2D8DEA80D0490A15
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C39CA9F3C1E29A95E83D140288CD78AA_C95EAF222F8C552B8A51D84B0A749002der
MD5:B6F16CB64A54A4154886A53EA410A9FC
SHA256:60009B5AC4C70C0F51B75132D93E8F59455D9EB50AC7E515A275A79962EA5E3A
2472iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFA03EF3E8F5C53DFA.TMPbinary
MD5:BFFF9A47F1A95E1D7096883F8817D48B
SHA256:ABA26A46DCBE3FCBF5510AF87E5F880A4622296DBA8A874B79B146DFEF04BB54
3308Amlogic USB Burning Tool v3.2.8.exeC:\Users\admin\AppData\Local\Temp\is-6DUI5.tmp\Amlogic USB Burning Tool v3.2.8.tmpexecutable
MD5:23D2B5F3A53654CE94ECBA0307EDAC73
SHA256:C82E73DD92B231437393BEB67DDE15E99163C3F1EF457809FE8C4A61CBFF91B6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
17
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?927e0d673a39dd41
unknown
unknown
3348
iexplore.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQUwPiEZQ6%2FsVZNPaFToNfxx8ZwqAQUfAwyH6fZMH%2FEfWijYqihzqsHWycCAQc%3D
unknown
binary
2.05 Kb
unknown
3348
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d362edf7b65e9a48
unknown
unknown
2472
iexplore.exe
GET
304
23.32.238.217:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18014fff35250a83
unknown
unknown
2472
iexplore.exe
GET
304
23.32.238.217:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76ad697231f9b13b
unknown
unknown
1080
svchost.exe
GET
200
23.32.238.217:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0754c686571bd23f
unknown
compressed
65.2 Kb
unknown
2472
iexplore.exe
GET
304
23.32.238.217:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9aee5c2adfb08fdb
unknown
unknown
3348
iexplore.exe
GET
200
192.124.249.23:80
http://ocsp.starfieldtech.com//MEowSDBGMEQwQjAJBgUrDgMCGgUABBT1ZqtwV0O1KcYi0gdzcFkHM%2BuArAQUJUWBaFAmOD07LSy%2BzWrZtj2zZmMCCQDmZP4f8TnvHA%3D%3D
unknown
binary
2.10 Kb
unknown
2472
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3348
iexplore.exe
192.124.249.38:443
androiddatahost.com
SUCURI-SEC
US
unknown
3348
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3348
iexplore.exe
192.124.249.23:80
ocsp.starfieldtech.com
SUCURI-SEC
US
unknown
2472
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
2472
iexplore.exe
23.32.238.217:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2472
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1080
svchost.exe
23.32.238.217:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
androiddatahost.com
  • 192.124.249.38
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
  • 23.32.238.217
  • 23.32.238.232
  • 23.32.238.242
  • 23.32.238.234
  • 23.32.238.218
  • 23.32.238.235
  • 23.32.238.227
  • 23.32.238.240
  • 23.32.238.219
whitelisted
ocsp.starfieldtech.com
  • 192.124.249.23
  • 192.124.249.41
  • 192.124.249.24
  • 192.124.249.36
  • 192.124.249.22
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
Process
Message
dpscat.exe
Copyright(c) 2012 Travis Lee Robinson. (DUAL BSD/GPL)
dpscat.exe
Portions Copyright(c) Pete Batard. (LGPL)
dpscat.exe
dpscat.exe
Actual section to install: libusbDevice_WinUSB.NTx86
dpscat.exe
Found Hwid: USB\VID_1B8E&PID_C004
dpscat.exe
Catalog file 'android_winusb.cat' created..
dpscat.exe
Hash calculated for: .\x86\winusbcoinstaller2.dll
dpscat.exe
Using PE guid..
dpscat.exe
Hash added..
dpscat.exe
Hash calculated for: .\x86\wdfcoinstaller01009.dll