File name:

MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zip

Full analysis: https://app.any.run/tasks/f8fdecfa-8ae0-48b2-b092-4bbba15de67f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 28, 2024, 13:20:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

8C1745CBFF0BAF7E7F9029C390CC4904

SHA1:

26840E122B46E71867AB3C1D730C4F7589814CFB

SHA256:

BDFA8CAA44AE4648F01A992F5926CD77CF0440AF6FFEB87264A7A594FF32667C

SSDEEP:

24576:HuwQpvrZvdowYrIQ+U6m5CQ3jMhMm4EGcV0+TdS:HuwUvrPowYrIK6m5CQTMhMm4EGcV0+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2432)
      • olk.exe (PID: 6260)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4808)
      • MicrosoftEdge_X64_130.0.2849.52.exe (PID: 6996)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • setup.exe (PID: 7148)
    • Starts a Microsoft application from unusual location

      • NewOutlookInstaller.exe (PID: 1952)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeWebview2Setup.exe (PID: 4808)
      • MicrosoftEdge_X64_130.0.2849.52.exe (PID: 6996)
      • olk.exe (PID: 6260)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • setup.exe (PID: 7148)
    • Application launched itself

      • setup.exe (PID: 7148)
      • msedgewebview2.exe (PID: 6972)
      • MicrosoftEdgeUpdate.exe (PID: 5240)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 4376)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2432)
    • Application launched itself

      • msedge.exe (PID: 6804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2024:10:28 13:09:30
ZipCRC: 0xae99b4e4
ZipCompressedSize: 452870
ZipUncompressedSize: 2725888
ZipFileName: NewOutlookInstaller.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
202
Monitored processes
59
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe newoutlookinstaller.exe Delivery Optimization User no specs slui.exe olk.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe microsoftedge_x64_130.0.2849.52.exe setup.exe setup.exe no specs microsoftedgeupdate.exe relaunchnativehost.exe no specs conhost.exe no specs olk.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.25\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1028"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\130.0.2849.52\msedgewebview2.exe" --type=renderer --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Microsoft\Olk\EBWebView" --webview-exe-name=olk.exe --webview-exe-version=1.2024.1018.100 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3772,i,13068168337168214356,17970746898913207643,262144 --enable-features=msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimaryAccountIsShared --disable-features=msEnhancedTrackingPreventionEnabled --variations-seed-version --mojo-platform-channel-handle=3832 /prefetch:1C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\130.0.2849.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
130.0.2849.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\130.0.2849.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\130.0.2849.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3504 --field-trial-handle=2412,i,3102277487503873146,4974247337388239555,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1580"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMjUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMjUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QTdFRjAwMUUtQ0E4OS00MEYyLTkwODItNEM2OTA2MURBNUVEfSIgdXNlcmlkPSJ7MEE0RTY2QTItN0FGMi00MkYxLThFQjgtNTQzMTY0NDc1ODQ1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9IntCNjY5OTc5Ni1DQzg5LTQ0NzgtOTE1OC02QzZEM0FFMUM4QTB9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtBS0szQjRPRjU2cGJmaHcyZEVmZktPdkRLK3hkR0dseEd0azRSNFg0UHBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMzAuMC4yODQ5LjUyIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjY2MDI1MTAxNjIiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2NjAyNTEwMTYyIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNzAwMTAzMjk4MCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvOTkyOWNmZjQtMzQ4Ny00ODA1LTkzZjctODZhY2I4MTNlMjZiP1AxPTE3MzA3MjY1MTcmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9RjY2RE1VVEZhZnpsTnglMmJ5VldGViUyZmpQWEVrTWtySlk3JTJiMyUyYkxSQ0VCcFVhSXY3Wmg1VVVPT2kzUiUyZmw3VklPRHp1emR1bWZWQW1LMXJvS25QY2hxM2l3JTNkJTNkIiBzZXJ2ZXJfaXBfaGludD0iIiBjZG5fY2lkPSItMSIgY2RuX2NjYz0iIiBjZG5fbXNlZGdlX3JlZj0iIiBjZG5fYXp1cmVfcmVmX29yaWdpbl9zaGllbGQ9IiIgY2RuX2NhY2hlPSIiIGNkbl9wM3A9IiIgZG93bmxvYWRlZD0iMTc0OTI1OTA0IiB0b3RhbD0iMTc0OTI1OTA0IiBkb3dubG9hZF90aW1lX21zPSIzNTg4NCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjcwMDEwMzI5ODAiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI2IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI3MDIyMTI1OTE1IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMTk2NzU3IiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI3Mzk1MDEwNTEzIiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iNzE5IiBkb3dubG9hZF90aW1lX21zPSIzOTgzNiIgZG93bmxvYWRlZD0iMTc0OTI1OTA0IiB0b3RhbD0iMTc0OTI1OTA0IiBwYWNrYWdlX2NhY2hlX3Jlc3VsdD0iMCIgaW5zdGFsbF90aW1lX21zPSIzNzI4OCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1880"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3700 --field-trial-handle=2412,i,3102277487503873146,4974247337388239555,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1952"C:\Users\admin\AppData\Local\Temp\Rar$EXb2432.44581\NewOutlookInstaller.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2432.44581\NewOutlookInstaller.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook Installer
Exit code:
0
Version:
1.2024.1018.100
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2432.44581\newoutlookinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1952\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exerelaunchNativeHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2100C:\Users\admin\AppData\Local\Temp\EU5DB.tmp\MicrosoftEdgeUpdate.exe /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU5DB.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\temp\eu5db.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
2124"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.25\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2432"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
19 715
Read events
17 232
Write events
2 415
Delete events
68

Modification events

(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_44c13dfa53d66e6c13b3eb06323d900cebfe7e6e.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1952) NewOutlookInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewOutlookInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
215
Suspicious files
192
Text files
67
Unknown types
11

Dropped files

PID
Process
Filename
Type
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.kj7mt6bu8o6m9jpwtt505uryf.tmpcat
MD5:46A4B4D928B657A04C17945461C35702
SHA256:880E212C890DCDD4EE70A87F33401A7D7B5BC8B4000F5E7DD1EF036D58BBD7D4
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.2v_smz4x9muiwprt8u4oyjx7.tmpbinary
MD5:1289BEEBB2B6AC39710605163E661971
SHA256:713C36316184F568CB26857EB0D109421E1B7A1B9F666772BF6CE04BDAAFF2F4
6260olk.exeC:\Users\admin\AppData\Local\Microsoft\Olk\HostAnomaly.txtbinary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.7ulo402wd_atf3nzasw_cq5wh.tmpxml
MD5:F2AB865D10E299FFD2B7F67502903208
SHA256:A66FF57269CAE160394D40840F2CD3057D1378302B003A56B9914408D6F2D950
1952NewOutlookInstaller.exeC:\Users\admin\AppData\Local\Temp\APPX.jqpkgjs3kb_4j0d1uflc1fzhf.tmpxml
MD5:B1DB429B82C6B6959D18C7174BA2411E
SHA256:8AE68CF6C4C2518D440BC3155D0C0DBC5B001FC232185C6A1162835205A8308B
2432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2432.44581\NewOutlookInstaller.exeexecutable
MD5:0B9820ECC88383016B7FF530A6777294
SHA256:D89BFA433590D35313BC40CFDD257ACC84331D1F95CDA24A47C22C23AF78C724
6260olk.exeC:\Users\admin\AppData\Local\Packages\Microsoft.OutlookForWindows_8wekyb3d8bbwe\AC\INetCache\D2T9M6R2\MicrosoftEdgeWebview2Setup[1].exeexecutable
MD5:A05C87DD1C5BEF14C7C75F48BF4D01EA
SHA256:274E12D01E0CAE083202DF4A809C1C153B02CB3CA121C19C43B0AAA1C3A53A40
4376svchost.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr.dbbinary
MD5:BEB4AFA94AC560A3F6189D51C65CF0AB
SHA256:E9E1A5CA10066D2D55B20D231AE0A7E5194A53FA9A46AF422E0D4166EB229CA9
6260olk.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:F2DFA672CD8D9723FF1835907E549FE3
SHA256:9115C9EA4DBEA033AEF335C73CE6AED60E96AB92DC03E551962893D93AF36338
6260olk.exeC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\172d17f9fcdee3eb203600899f21f6d8a880e6ca.tbresbinary
MD5:FE681DC5868D70FB50CA5FD154D6714A
SHA256:F96A1981EC161EB2708F798E282CF82B1BF8B63CA58C1B24942333931D60D499
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
80
DNS requests
82
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6260
olk.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1396
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6028
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6028
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6636
svchost.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
4376
svchost.exe
HEAD
200
217.20.57.19:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9929cff4-3487-4805-93f7-86acb813e26b?P1=1730726517&P2=404&P3=2&P4=F66DMUTFafzlNx%2byVWFV%2fjPXEkMkrJY7%2b3%2bLRCEBpUaIv7Zh5UUOOi3R%2fl7VIODzuzdumfVAmK1roKnPchq3iw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
92.123.104.34:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4700
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.164.9
  • 2.16.164.114
  • 2.16.164.24
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.125.143
whitelisted
www.bing.com
  • 92.123.104.34
  • 92.123.104.54
  • 92.123.104.33
  • 92.123.104.53
  • 92.123.104.52
  • 92.123.104.38
  • 92.123.104.49
  • 92.123.104.32
  • 92.123.104.44
  • 2.23.209.154
  • 2.23.209.142
  • 2.23.209.136
  • 2.23.209.141
  • 2.23.209.144
  • 2.23.209.143
  • 2.23.209.140
  • 2.23.209.158
  • 2.23.209.149
  • 2.23.209.189
  • 2.23.209.130
  • 2.23.209.192
  • 2.23.209.133
  • 2.23.209.135
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.75
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.73
  • 40.126.31.67
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 69.192.162.125
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
4376
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.Storage] No database could be opened
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.SQLiteDB] Failed to open database file: (14) unable to open database file
olk.exe
2024-10-28 13:21:52.800 T#6416 <E> [EventsSDK.SQLiteDB] Failed to open database file: (14) unable to open database file
olk.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
olk.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 4bb4d6f7cafc4e9292f972dca2dcde42:CE6D0EF4-950E-48DD-B5D7-06F7D4887510: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:19EAD621-F5F2-4FE1-B7E9-152671A8374E: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:A3712CBC-C3D3-4F1D-BEF6-54E036E1CC31: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:A30E2887-769F-446E-87F3-C7D538429260: Database is not open
olk.exe
2024-10-28 13:23:16.472 T#6416 <E> [EventsSDK.Storage] Failed to store event 224536c9e699462d8d769a0fc697c463:54C8DF46-89DF-433B-BBA6-CB735514D59E: Database is not open