File name:

New - Trigon Evo - Installer V2.5_95711246.exe

Full analysis: https://app.any.run/tasks/8b39a6dc-3bca-495e-9fc0-a8c8e23f8716
Verdict: Malicious activity
Analysis date: December 30, 2023, 17:26:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

93D16508432C3FF3512EB9DE584F48E6

SHA1:

6ED9FD4D190AFC6C5154730D85CF883FD3AD4D2E

SHA256:

BE5357F63B036DA79D198978CBC5B652EA02B1CCFCB1538352442CDC7F4D5549

SSDEEP:

98304:F7GowcdPyJC8JRlobIlEQBYIXwUOZkj0o14vZGcwhnVx/mp9814L/fKBUe3VBOUu:R/JiB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
      • DownloadHelperTray.exe (PID: 2820)
  • SUSPICIOUS

    • Reads the Internet Settings

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • setup95711246.exe (PID: 2312)
      • OfferInstaller.exe (PID: 2424)
      • cmd.exe (PID: 2484)
      • msiexec.exe (PID: 2896)
      • DownloadHelperTray.exe (PID: 2820)
    • Checks Windows Trust Settings

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • msiexec.exe (PID: 2792)
    • Reads security settings of Internet Explorer

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
    • Reads settings of System Certificates

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
      • DownloadHelperTray.exe (PID: 2820)
    • The process creates files with name similar to system file names

      • setup95711246.exe (PID: 764)
      • msiexec.exe (PID: 2792)
    • Reads the Windows owner or organization settings

      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2792)
    • Adds/modifies Windows certificates

      • setup95711246.exe (PID: 764)
      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • msiexec.exe (PID: 2792)
    • Searches for installed software

      • setup95711246.exe (PID: 764)
    • Executing commands from a ".bat" file

      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2624)
      • cmd.exe (PID: 2664)
    • Get information on the list of running processes

      • cmd.exe (PID: 2624)
      • cmd.exe (PID: 2664)
    • Start notepad (likely ransomware note)

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
    • Starts CMD.EXE for commands execution

      • OfferInstaller.exe (PID: 2424)
      • setup95711246.exe (PID: 764)
    • Changes default file association

      • msiexec.exe (PID: 2792)
  • INFO

    • Drops the executable file immediately after the start

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • msiexec.exe (PID: 2792)
    • Checks supported languages

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • setup95711246.exe (PID: 2312)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2792)
      • msiexec.exe (PID: 2896)
      • DownloadHelperTray.exe (PID: 2820)
    • Reads the computer name

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • setup95711246.exe (PID: 2312)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2792)
      • msiexec.exe (PID: 2896)
      • DownloadHelperTray.exe (PID: 2820)
    • Checks proxy server information

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
    • Reads the machine GUID from the registry

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • setup95711246.exe (PID: 2312)
      • msiexec.exe (PID: 2792)
      • OfferInstaller.exe (PID: 2424)
      • DownloadHelperTray.exe (PID: 2820)
      • msiexec.exe (PID: 2896)
    • Creates files or folders in the user directory

      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2792)
    • Create files in a temporary directory

      • setup95711246.exe (PID: 764)
      • New - Trigon Evo - Installer V2.5_95711246.exe (PID: 2256)
      • setup95711246.exe (PID: 2312)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2896)
      • msiexec.exe (PID: 2792)
    • Process drops legitimate windows executable

      • setup95711246.exe (PID: 764)
      • msiexec.exe (PID: 2792)
    • The process drops C-runtime libraries

      • setup95711246.exe (PID: 764)
    • Reads Environment values

      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
      • msiexec.exe (PID: 2896)
      • DownloadHelperTray.exe (PID: 2820)
    • Reads product name

      • setup95711246.exe (PID: 764)
      • OfferInstaller.exe (PID: 2424)
    • Application launched itself

      • msiexec.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:21 20:16:16+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.22
CodeSize: 4345344
InitializedDataSize: 5646336
UninitializedDataSize: -
EntryPoint: 0x39649e
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Download Manager
FileVersion: 1
InternalName: Download Manager
LegalCopyright: Download Manager
OriginalFileName: Download Manager
ProductName: Download Manager
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
25
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start new - trigon evo - installer v2.5_95711246.exe setup95711246.exe setup95711246.exe no specs offerinstaller.exe cmd.exe no specs tasklist.exe no specs find.exe no specs timeout.exe no specs notepad.exe no specs cmd.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe downloadhelpertray.exe cmd.exe no specs find.exe no specs tasklist.exe no specs timeout.exe no specs tasklist.exe no specs find.exe no specs timeout.exe no specs tasklist.exe no specs find.exe no specs timeout.exe no specs new - trigon evo - installer v2.5_95711246.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
568"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\anyPDF-h20-5.msi" /quietC:\Windows\System32\msiexec.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
604tasklist /FI "PID eq 2424" /fo csv C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
764C:\Users\admin\AppData\Local\setup95711246.exe hhwnd=196904 hreturntoinstaller hextras=id:fe68584c040cd0c-TW-shtluC:\Users\admin\AppData\Local\setup95711246.exe
New - Trigon Evo - Installer V2.5_95711246.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup95711246.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1572"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\link.txtC:\Windows\System32\notepad.exeNew - Trigon Evo - Installer V2.5_95711246.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1600timeout 5C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1880tasklist /FI "PID eq 764" /fo csv C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2040"C:\Users\admin\AppData\Local\Temp\New - Trigon Evo - Installer V2.5_95711246.exe" C:\Users\admin\AppData\Local\Temp\New - Trigon Evo - Installer V2.5_95711246.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Download Manager
Exit code:
3221226540
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\new - trigon evo - installer v2.5_95711246.exe
c:\windows\system32\ntdll.dll
2256"C:\Users\admin\AppData\Local\Temp\New - Trigon Evo - Installer V2.5_95711246.exe" C:\Users\admin\AppData\Local\Temp\New - Trigon Evo - Installer V2.5_95711246.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Download Manager
Exit code:
0
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\new - trigon evo - installer v2.5_95711246.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2312C:\Users\admin\AppData\Local\setup95711246.exe hreadyC:\Users\admin\AppData\Local\setup95711246.exeNew - Trigon Evo - Installer V2.5_95711246.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup95711246.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2424"C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe" C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe
setup95711246.exe
User:
admin
Company:
Adaware
Integrity Level:
HIGH
Description:
OfferInstaller
Exit code:
0
Version:
7.14.2.0
Modules
Images
c:\users\admin\appdata\local\temp\ec05d89197b949eb6957b79472e8723d\offerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
38 070
Read events
37 861
Write events
203
Delete events
6

Modification events

(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2256) New - Trigon Evo - Installer V2.5_95711246.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(764) setup95711246.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\ServiceHide.dll
Executable files
264
Suspicious files
27
Text files
31
Unknown types
0

Dropped files

PID
Process
Filename
Type
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:796CCF08742FC45EFE8E933FEBBD76B0
SHA256:41DB918D69A9BA73188F0ACC0E1382DD3A236F58422F9FCAF517279F2699581F
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:45234056DB1DBB30E2809FE1BE5086A4
SHA256:A696F6354DE2BC8B4A390C06EF26D0985962D241D48D37209B385DA93267CE8C
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\869CC3B84BEE922ABCE8CDCAA964F3D9_6F32A0985879EB33E63263938C358721binary
MD5:488B2A6F8793C460657A19497540DE63
SHA256:16FD85BAF8C907140594F2DDCBD5DE7769D3517F888C0EFF31F4248BC866026D
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:D618736B4E00185FC8BAD7242FA6ED2A
SHA256:7F895FBE7D7C483FDD9113F5F999AC4DAF3576B12F2A819F725B2BE0A17573E9
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\service[1].htmtext
MD5:A5F78E37E0E45D83EFAF2D50AD8C662A
SHA256:99C5F27547A226560345BFBE24D7E9DC759F540F83E76F1C9AB3109C8B86B720
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\geo[1].htmtext
MD5:DF39CF970D8CAD0392B163044D17D49B
SHA256:3F738E1C2B286B549628ADD9A525778E55DC8679E02B171FFD3FE7E0D9FE934E
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\Local\setup95711246.exeexecutable
MD5:29D3A70CEC060614E1691E64162A6C1E
SHA256:CC70B093A19610E9752794D757AEC9EF07CA862EA9267EC6F9CC92B2AA882C72
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
2256New - Trigon Evo - Installer V2.5_95711246.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\869CC3B84BEE922ABCE8CDCAA964F3D9_6F32A0985879EB33E63263938C358721binary
MD5:00F96F3439547D18D63A94700FEEEDEE
SHA256:ED652FA8808D0771127AEADEBD0E4CCB1DF124BEBAA280E397D80BC00EF74EA8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
35
DNS requests
19
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7c5cced82a00ccfd
unknown
compressed
4.66 Kb
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/s/gts1d4/BLyg_-h63RA/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEACRI2vGqzWlEof0zfA2Du0%3D
unknown
binary
471 b
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/s/gts1d4/tPVfSrt3g1k/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDASJ2qLaCI5xAFjJiGxx93
unknown
binary
472 b
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?702dc622b44086d9
unknown
compressed
65.2 Kb
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
GET
200
69.192.161.44:80
http://x2.c.lencr.org/
unknown
binary
300 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
35.190.60.70:443
www.dlsft.com
GOOGLE
US
whitelisted
2256
New - Trigon Evo - Installer V2.5_95711246.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
216.58.212.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
764
setup95711246.exe
104.17.8.52:443
flow.lavasoft.com
CLOUDFLARENET
shared
764
setup95711246.exe
104.18.68.73:443
sos.adaware.com
CLOUDFLARENET
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
188.114.97.3:443
filedm.com
CLOUDFLARENET
NL
unknown
2256
New - Trigon Evo - Installer V2.5_95711246.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
www.dlsft.com
  • 35.190.60.70
unknown
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.pki.goog
  • 216.58.212.131
whitelisted
www.google.com
  • 142.250.186.164
whitelisted
flow.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
sos.adaware.com
  • 104.18.68.73
  • 104.18.67.73
whitelisted
dlsft.com
  • 35.190.60.70
unknown
filedm.com
  • 188.114.97.3
  • 188.114.96.3
malicious
x1.c.lencr.org
  • 69.192.161.44
whitelisted
x2.c.lencr.org
  • 69.192.161.44
whitelisted

Threats

Found threats are available for the paid subscriptions
7 ETPRO signatures available at the full report
Process
Message
setup95711246.exe
Error: File not found - sciterwrapper:console.tis
setup95711246.exe
at sciter:init-script.tis
setup95711246.exe
setup95711246.exe
setup95711246.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
setup95711246.exe
setup95711246.exe
setup95711246.exe
at sciter:init-script.tis
setup95711246.exe
Error: File not found - sciterwrapper:console.tis
setup95711246.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'