File name:

ishredder-windows.msi

Full analysis: https://app.any.run/tasks/04dba4ad-0d74-40d2-95f5-651fed225bab
Verdict: Malicious activity
Analysis date: December 31, 2023, 10:30:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Protectstar(TM) iShredder 7, Author: Protectstar Inc., Comments: iShredder, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Template: Intel;1033, Last Saved By: Intel;1031, Revision Number: {D7D7E52F-49B3-476D-AAB0-BA32E2594E9D}7.0.2107;{D7D7E52F-49B3-476D-AAB0-BA32E2594E9D}7.0.2107;{84EF3185-4BC8-4114-A3A5-52DF78AE2BDF}, Number of Pages: 200, Number of Characters: 0
MD5:

E0C23E46138A0013B3FD2F210C409C64

SHA1:

3F9282746E08BAC196D02200234085B944621FA2

SHA256:

BD0F7593EF4A126B8DB980A773799B14125A2C798B40772C41C53582B8911EA0

SSDEEP:

98304:uZXZ9ZVZJZ5Z6DXAOw/n9MD6fIZRLtXifrJAIAytVk01Lcv4BBGv11G5l/+c15TJ:CDi4dt0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • DataShredderGUI6.exe (PID: 2440)
      • DataShredderGUI6.exe (PID: 2376)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1288)
      • DataShredderGUI6.exe (PID: 3388)
      • DataShredderGUI6.exe (PID: 3272)
    • Uses REG/REGEDIT.EXE to modify registry

      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
    • Reads the Internet Settings

      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • DataShredderGUI6.exe (PID: 3388)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
      • DataShredderGUI6.exe (PID: 3272)
    • Reads settings of System Certificates

      • DataShredderGUI6.exe (PID: 3388)
      • DataShredderGUI6.exe (PID: 3272)
    • Reads security settings of Internet Explorer

      • DataShredderGUI6.exe (PID: 3388)
      • DataShredderGUI6.exe (PID: 3272)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1288)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 1288)
      • msiexec.exe (PID: 2080)
      • DataShredderGUI6.exe (PID: 2440)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • DataShredderGUI6.exe (PID: 3388)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • msiexec.exe (PID: 2564)
      • msiexec.exe (PID: 1196)
      • DataShredderGUI6.exe (PID: 2376)
      • DataShredderGUI6.exe (PID: 3444)
      • DataShredderGUI6.exe (PID: 3272)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
    • Reads the computer name

      • msiexec.exe (PID: 1288)
      • msiexec.exe (PID: 2080)
      • DataShredderGUI6.exe (PID: 2440)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • DataShredderGUI6.exe (PID: 3388)
      • msiexec.exe (PID: 1196)
      • msiexec.exe (PID: 2564)
      • DataShredderGUI6.exe (PID: 2376)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
      • DataShredderGUI6.exe (PID: 3272)
      • DataShredderGUI6.exe (PID: 3444)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2184)
      • msiexec.exe (PID: 1572)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1288)
      • msiexec.exe (PID: 2080)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • DataShredderGUI6.exe (PID: 3388)
      • msiexec.exe (PID: 2564)
      • msiexec.exe (PID: 1196)
      • DataShredderGUI6.exe (PID: 3272)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2184)
      • msiexec.exe (PID: 1288)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • msiexec.exe (PID: 1572)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
    • Application launched itself

      • msiexec.exe (PID: 1288)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2016)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1288)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • DataShredderGUI6.exe (PID: 3388)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 1288)
      • DataShredderGUI6.exe (PID: 2440)
      • DataShredderGUI6.exe (PID: 3388)
    • Manual execution by a user

      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2548)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 900)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3128)
      • DataShredderGUI6.exe (PID: 3388)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3080)
      • control.exe (PID: 4052)
      • msiexec.exe (PID: 1572)
      • DataShredderGUI6.exe (PID: 3444)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2820)
      • DataShredderGUI6.exe (PID: 3272)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 3012)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 2320)
      • (x64bit.)_v7.0.21.01.09_patch.exe (PID: 552)
    • Checks proxy server information

      • DataShredderGUI6.exe (PID: 3388)
      • DataShredderGUI6.exe (PID: 3272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Pages: 200
RevisionNumber: {05682DB8-1DE5-4EAD-B1E0-075165A16FFF}
Title: Protectstar(TM) iShredder 7
Subject: -
Author: Protectstar Inc.
Keywords: -
Comments: iShredder
Words: 2
ModifyDate: 2021:08:15 08:58:40
LastPrinted: 2021:08:15 08:58:40
Template: Intel;1033,1031
LastModifiedBy: Intel;1031
Characters: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
90
Monitored processes
32
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs datashreddergui6.exe no specs regsvr32.exe regsvr32.exe (x64bit.)_v7.0.21.01.09_patch.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe regedit.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe regedit.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe regedit.exe no specs datashreddergui6.exe control.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs datashreddergui6.exe no specs regsvr32.exe regsvr32.exe datashreddergui6.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe no specs (x64bit.)_v7.0.21.01.09_patch.exe regedit.exe no specs datashreddergui6.exe

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\ProtectStar\DataShredder\DataShredderShellExt.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
552"C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe" C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\(x64bit.)_v7.0.21.01.09_patch.exe
c:\windows\system32\ntdll.dll
900"C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe" C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\desktop\(x64bit.)_v7.0.21.01.09_patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
984"C:\Windows\system32\MsiExec.exe" /Z "C:\Program Files\ProtectStar\DataShredder\DataShredderShellExt.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1196C:\Windows\system32\MsiExec.exe -Embedding D010711122C447D46D18DCA5E952E26E CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1288C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1572"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\ishredder-windows.msi" C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2016C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2080C:\Windows\system32\MsiExec.exe -Embedding C92474A88581BA033C4391B263D0031B CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2184"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\ishredder-windows.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
38 466
Read events
37 755
Write events
552
Delete events
159

Modification events

(PID) Process:(2184) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
73
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
Executable files
25
Suspicious files
44
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
1288msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1288msiexec.exeC:\Windows\Installer\e2c8a.msi
MD5:
SHA256:
2184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI172E.tmpexecutable
MD5:612E28BA3A3B49EA7453E0866082638E
SHA256:27011F19145E33D9770CDF53E860A0CDD9A98933612D7A99619039CEC722CCFB
2184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIFC42.tmpexecutable
MD5:612E28BA3A3B49EA7453E0866082638E
SHA256:27011F19145E33D9770CDF53E860A0CDD9A98933612D7A99619039CEC722CCFB
1288msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFACA35129DAA0E768.TMPbinary
MD5:4D96CEA4DFBBFF7EB571B0C528DCF7F3
SHA256:8AFC7DFD06553C3C7D07A6FF34E1583639D6EDB975DFC884B865C85418F4F9CC
1288msiexec.exeC:\Windows\Installer\MSI31F8.tmpbinary
MD5:08A7ECBC7C9425B9B9641D09B4FD0153
SHA256:8B76C3D06588C07C6E57148D0E2BBA74C1472BCE183BAEC77AC8AAC3A10A5286
1288msiexec.exeC:\Windows\Installer\e2c8d.msi
MD5:
SHA256:
1288msiexec.exeC:\Program Files\ProtectStar\DataShredder\AppIco.icoimage
MD5:7A94D4D9F4FB1E38B3113AB4A7EFD803
SHA256:0F5A59CF93408DE7C6F1E968F35BC13DFF26658AF1605516F5A06FD6D3433AEC
1288msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:DE211DB5A94888A9AC70E85B262709DA
SHA256:25ED927584188FB16888F77AF781E6D1C9D0E5FB101CBA56EA1E39666F990029
1288msiexec.exeC:\Windows\Installer\e2c8b.ipibinary
MD5:9F527763AA4CDD1C63D8656371C94CF5
SHA256:12B6930CCC50AA14FB167E6FEF5E62D283E7396290069C0578A1E7CB80749B95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
10
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3388
DataShredderGUI6.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?65b8d6cb9b90a22f
unknown
compressed
65.2 Kb
unknown
3388
DataShredderGUI6.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?127d542563002f94
unknown
compressed
4.66 Kb
unknown
3388
DataShredderGUI6.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3388
DataShredderGUI6.exe
GET
200
184.24.77.45:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNUJFKAFSI3aY62xPtxREpHnw%3D%3D
unknown
binary
503 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?503c317279212ca4
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3388
DataShredderGUI6.exe
217.160.175.246:443
www.protectstar.com
IONOS SE
DE
unknown
3388
DataShredderGUI6.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3388
DataShredderGUI6.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
3388
DataShredderGUI6.exe
184.24.77.45:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3272
DataShredderGUI6.exe
217.160.175.246:443
www.protectstar.com
IONOS SE
DE
unknown

DNS requests

Domain
IP
Reputation
www.protectstar.com
  • 217.160.175.246
unknown
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
r3.o.lencr.org
  • 184.24.77.45
  • 184.24.77.79
  • 184.24.77.48
  • 184.24.77.47
  • 184.24.77.75
  • 184.24.77.80
  • 184.24.77.83
  • 184.24.77.52
  • 184.24.77.67
shared

Threats

No threats detected
No debug info