File name:

MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zip

Full analysis: https://app.any.run/tasks/f8fdecfa-8ae0-48b2-b092-4bbba15de67f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 28, 2024, 13:20:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

8C1745CBFF0BAF7E7F9029C390CC4904

SHA1:

26840E122B46E71867AB3C1D730C4F7589814CFB

SHA256:

BDFA8CAA44AE4648F01A992F5926CD77CF0440AF6FFEB87264A7A594FF32667C

SSDEEP:

24576:HuwQpvrZvdowYrIQ+U6m5CQ3jMhMm4EGcV0+TdS:HuwUvrPowYrIK6m5CQTMhMm4EGcV0+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • NewOutlookInstaller.exe (PID: 1952)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Process drops legitimate windows executable

      • olk.exe (PID: 6260)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4808)
      • WinRAR.exe (PID: 2432)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdge_X64_130.0.2849.52.exe (PID: 6996)
      • setup.exe (PID: 7148)
    • Executable content was dropped or overwritten

      • olk.exe (PID: 6260)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4808)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdge_X64_130.0.2849.52.exe (PID: 6996)
      • setup.exe (PID: 7148)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 4376)
    • Application launched itself

      • setup.exe (PID: 7148)
      • MicrosoftEdgeUpdate.exe (PID: 5240)
      • msedgewebview2.exe (PID: 6972)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2432)
    • Application launched itself

      • msedge.exe (PID: 6804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2024:10:28 13:09:30
ZipCRC: 0xae99b4e4
ZipCompressedSize: 452870
ZipUncompressedSize: 2725888
ZipFileName: NewOutlookInstaller.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
202
Monitored processes
59
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe newoutlookinstaller.exe Delivery Optimization User no specs slui.exe olk.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe microsoftedge_x64_130.0.2849.52.exe setup.exe setup.exe no specs microsoftedgeupdate.exe relaunchnativehost.exe no specs conhost.exe no specs olk.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.25\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1028"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\130.0.2849.52\msedgewebview2.exe" --type=renderer --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Microsoft\Olk\EBWebView" --webview-exe-name=olk.exe --webview-exe-version=1.2024.1018.100 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3772,i,13068168337168214356,17970746898913207643,262144 --enable-features=msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimaryAccountIsShared --disable-features=msEnhancedTrackingPreventionEnabled --variations-seed-version --mojo-platform-channel-handle=3832 /prefetch:1C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\130.0.2849.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
130.0.2849.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\130.0.2849.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\130.0.2849.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3504 --field-trial-handle=2412,i,3102277487503873146,4974247337388239555,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1580"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMjUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMjUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QTdFRjAwMUUtQ0E4OS00MEYyLTkwODItNEM2OTA2MURBNUVEfSIgdXNlcmlkPSJ7MEE0RTY2QTItN0FGMi00MkYxLThFQjgtNTQzMTY0NDc1ODQ1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9IntCNjY5OTc5Ni1DQzg5LTQ0NzgtOTE1OC02QzZEM0FFMUM4QTB9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtBS0szQjRPRjU2cGJmaHcyZEVmZktPdkRLK3hkR0dseEd0azRSNFg0UHBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMzAuMC4yODQ5LjUyIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjY2MDI1MTAxNjIiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2NjAyNTEwMTYyIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNzAwMTAzMjk4MCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvOTkyOWNmZjQtMzQ4Ny00ODA1LTkzZjctODZhY2I4MTNlMjZiP1AxPTE3MzA3MjY1MTcmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9RjY2RE1VVEZhZnpsTnglMmJ5VldGViUyZmpQWEVrTWtySlk3JTJiMyUyYkxSQ0VCcFVhSXY3Wmg1VVVPT2kzUiUyZmw3VklPRHp1emR1bWZWQW1LMXJvS25QY2hxM2l3JTNkJTNkIiBzZXJ2ZXJfaXBfaGludD0iIiBjZG5fY2lkPSItMSIgY2RuX2NjYz0iIiBjZG5fbXNlZGdlX3JlZj0iIiBjZG5fYXp1cmVfcmVmX29yaWdpbl9zaGllbGQ9IiIgY2RuX2NhY2hlPSIiIGNkbl9wM3A9IiIgZG93bmxvYWRlZD0iMTc0OTI1OTA0IiB0b3RhbD0iMTc0OTI1OTA0IiBkb3dubG9hZF90aW1lX21zPSIzNTg4NCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjcwMDEwMzI5ODAiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI2IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI3MDIyMTI1OTE1IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMTk2NzU3IiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI3Mzk1MDEwNTEzIiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iNzE5IiBkb3dubG9hZF90aW1lX21zPSIzOTgzNiIgZG93bmxvYWRlZD0iMTc0OTI1OTA0IiB0b3RhbD0iMTc0OTI1OTA0IiBwYWNrYWdlX2NhY2hlX3Jlc3VsdD0iMCIgaW5zdGFsbF90aW1lX21zPSIzNzI4OCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1880"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3700 --field-trial-handle=2412,i,3102277487503873146,4974247337388239555,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1952"C:\Users\admin\AppData\Local\Temp\Rar$EXb2432.44581\NewOutlookInstaller.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2432.44581\NewOutlookInstaller.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook Installer
Exit code:
0
Version:
1.2024.1018.100
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2432.44581\newoutlookinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1952\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exerelaunchNativeHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2100C:\Users\admin\AppData\Local\Temp\EU5DB.tmp\MicrosoftEdgeUpdate.exe /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU5DB.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\temp\eu5db.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
2124"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.25\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2432"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
19 715
Read events
17 232
Write events
2 415
Delete events
68

Modification events

(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
215
Suspicious files
192
Text files
67
Unknown types
11

Dropped files

PID
Process
Filename
Type
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.jqpkgjs3kb_4j0d1uflc1fzhf.tmpxml
MD5:B1DB429B82C6B6959D18C7174BA2411E
SHA256:8AE68CF6C4C2518D440BC3155D0C0DBC5B001FC232185C6A1162835205A8308B
6260olk.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:8D3676F56B301A70FC2BAF8F32F99BBD
SHA256:CAA1A57CC60A43D5835D35E217C010F062757E7B13DEE424E9E33AB0A4AAE4EA
6260olk.exeC:\Users\admin\AppData\Local\Microsoft\Olk\updated.txttext
MD5:0F81D52E06CAAA4860887488D18271C7
SHA256:27EB5E51506C911F6FC4BB345C0D9DB6F60415FCEAB7C18E1E9B862637415777
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.kj7mt6bu8o6m9jpwtt505uryf.tmpcat
MD5:46A4B4D928B657A04C17945461C35702
SHA256:880E212C890DCDD4EE70A87F33401A7D7B5BC8B4000F5E7DD1EF036D58BBD7D4
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.7ulo402wd_atf3nzasw_cq5wh.tmpxml
MD5:F2AB865D10E299FFD2B7F67502903208
SHA256:A66FF57269CAE160394D40840F2CD3057D1378302B003A56B9914408D6F2D950
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.2v_smz4x9muiwprt8u4oyjx7.tmpbinary
MD5:1289BEEBB2B6AC39710605163E661971
SHA256:713C36316184F568CB26857EB0D109421E1B7A1B9F666772BF6CE04BDAAFF2F4
4376svchost.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr.dbbinary
MD5:BEB4AFA94AC560A3F6189D51C65CF0AB
SHA256:E9E1A5CA10066D2D55B20D231AE0A7E5194A53FA9A46AF422E0D4166EB229CA9
6260olk.exeC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\c42590c0eae48feb76108a99cdf439a1efbefcca.tbresbinary
MD5:5BE18595186A48F3ED0C56F93FF5D59C
SHA256:7D32F17AD3E0CCCB1DA7E77D762ED61932370D8FF00593B3158FA8F16C29F8B9
6260olk.exeC:\Users\admin\AppData\Local\Microsoft\Olk\HostAnomaly.txtbinary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
6260olk.exeC:\Users\admin\AppData\Local\Temp\.sestext
MD5:40A998B12AF396563D8FDF9971C0DB65
SHA256:F53B61C11D1624ACEA6641F44EF91D71F7DFF8D0138567C160D396B850C65907
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
80
DNS requests
82
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1396
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6028
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6028
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6636
svchost.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6636
svchost.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
4376
svchost.exe
HEAD
200
217.20.57.19:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9929cff4-3487-4805-93f7-86acb813e26b?P1=1730726517&P2=404&P3=2&P4=F66DMUTFafzlNx%2byVWFV%2fjPXEkMkrJY7%2b3%2bLRCEBpUaIv7Zh5UUOOi3R%2fl7VIODzuzdumfVAmK1roKnPchq3iw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
92.123.104.34:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4700
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.164.9
  • 2.16.164.114
  • 2.16.164.24
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.125.143
whitelisted
www.bing.com
  • 92.123.104.34
  • 92.123.104.54
  • 92.123.104.33
  • 92.123.104.53
  • 92.123.104.52
  • 92.123.104.38
  • 92.123.104.49
  • 92.123.104.32
  • 92.123.104.44
  • 2.23.209.154
  • 2.23.209.142
  • 2.23.209.136
  • 2.23.209.141
  • 2.23.209.144
  • 2.23.209.143
  • 2.23.209.140
  • 2.23.209.158
  • 2.23.209.149
  • 2.23.209.189
  • 2.23.209.130
  • 2.23.209.192
  • 2.23.209.133
  • 2.23.209.135
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.75
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.73
  • 40.126.31.67
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 69.192.162.125
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
4376
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.Storage] No database could be opened
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.SQLiteDB] Failed to open database file: (14) unable to open database file
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.SQLiteDB] Failed to open database file: (14) unable to open database file
olk.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
olk.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 4bb4d6f7cafc4e9292f972dca2dcde42:CE6D0EF4-950E-48DD-B5D7-06F7D4887510: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:19EAD621-F5F2-4FE1-B7E9-152671A8374E: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:A3712CBC-C3D3-4F1D-BEF6-54E036E1CC31: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:A30E2887-769F-446E-87F3-C7D538429260: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:54C8DF46-89DF-433B-BBA6-CB735514D59E: Database is not open