File name:

WinUSBDisplay_Windows_V3.1.5.75.exe

Full analysis: https://app.any.run/tasks/43b7afb9-0c68-4385-a80a-9e89cfe5c33c
Verdict: Malicious activity
Analysis date: June 19, 2024, 11:02:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

19826CEBEB3D47B9A9AD1ED9162BEB8F

SHA1:

B6DE74B19CEE5CF8161F371683B0817BFF381609

SHA256:

BE85475F2D91EDA638C199F5BEEFEDBEDAAC349E0F8DB593715C292012A3FF3D

SSDEEP:

98304:R+cD4dnjzypendOVQQ/W8NG3jkjvc6P3GN3gD5JaqocCGT0yk0eEdX4kTV1f+3Fx:tSlMZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3348)
      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3372)
      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Create files in the Startup directory

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2948)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • The process drops C-runtime libraries

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Drops a system driver (possible attempt to evade defenses)

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
    • Reads the Windows owner or organization settings

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Executable content was dropped or overwritten

      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3348)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3372)
    • Creates or modifies Windows services

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2948)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
    • Reads security settings of Internet Explorer

      • devcon.exe (PID: 2192)
    • Adds/modifies Windows certificates

      • devcon.exe (PID: 2192)
    • Reads settings of System Certificates

      • devcon.exe (PID: 2192)
      • rundll32.exe (PID: 2980)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3672)
  • INFO

    • Creates files or folders in the user directory

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Checks supported languages

      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3348)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 3384)
      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3372)
      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Create files in a temporary directory

      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3348)
      • WinUSBDisplay_Windows_V3.1.5.75.exe (PID: 3372)
      • devcon.exe (PID: 2076)
      • devcon.exe (PID: 2192)
    • Reads the computer name

      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 3384)
      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Creates a software uninstall entry

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
    • Reads the machine GUID from the registry

      • devcon.exe (PID: 2076)
      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
    • Reads the software policy settings

      • drvinst.exe (PID: 2948)
      • devcon.exe (PID: 2192)
      • rundll32.exe (PID: 2980)
      • drvinst.exe (PID: 2428)
      • drvinst.exe (PID: 4068)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2980)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 2428)
    • Creates files in the program directory

      • WinUSBDisplay_Windows_V3.1.5.75.tmp (PID: 2752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 126464
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.1.5.75
ProductVersionNumber: 3.1.5.75
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: MS
FileDescription: Win USB Display Setup
FileVersion: 3.1.5.75
LegalCopyright: Copyright © MacroSilicon 2022
OriginalFileName:
ProductName: Win USB Display
ProductVersion: 3.1.5.75
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winusbdisplay_windows_v3.1.5.75.exe winusbdisplay_windows_v3.1.5.75.tmp no specs winusbdisplay_windows_v3.1.5.75.exe winusbdisplay_windows_v3.1.5.75.tmp devcon.exe drvinst.exe devcon.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
2076"C:\Program Files\Win USB Display\tool\x86\devcon.exe" dp_add "C:\Program Files\Win USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_345F&PID_9132&MI_03C:\Program Files\Win USB Display\tool\x86\devcon.exe
WinUSBDisplay_Windows_V3.1.5.75.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.10586.0 (th2_release.151029-1700)
Modules
Images
c:\program files\win usb display\tool\x86\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2192"C:\Program Files\Win USB Display\tool\x86\devcon.exe" install "C:\Program Files\Win USB Display\video_driver\dfmirage.inf" dfmirageC:\Program Files\Win USB Display\tool\x86\devcon.exe
WinUSBDisplay_Windows_V3.1.5.75.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.10586.0 (th2_release.151029-1700)
Modules
Images
c:\program files\win usb display\tool\x86\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2428DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5c25d5a2-13b1-0b7b-ff59-7b70c3ec6a64}\dfmirage.inf" "0" "670102fe7" "000004AC" "WinSta0\Default" "000005EC" "208" "c:\program files\win usb display\video_driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2752"C:\Users\admin\AppData\Local\Temp\is-MMQM3.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmp" /SL5="$60194,3547400,869376,C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe" /SPAWNWND=$70160 /NOTIFYWND=$9014C C:\Users\admin\AppData\Local\Temp\is-MMQM3.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmp
WinUSBDisplay_Windows_V3.1.5.75.exe
User:
admin
Company:
MS
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mmqm3.tmp\winusbdisplay_windows_v3.1.5.75.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2948DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{516cced0-8bd0-5b46-8d6f-994a7fc57e16}\MSUSBDisplay.inf" "0" "6f3175313" "00000594" "WinSta0\Default" "0000055C" "208" "C:\Program Files\Win USB Display\lib_usb"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2980rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{539ba45e-29f1-7182-d200-9649acf59b09} Global\{0f3d4d6c-3b28-3434-9029-b422e7fdfc71} C:\Windows\System32\DriverStore\Temp\{49f1cc80-adfd-7fa5-70ae-b9165f4ec271}\dfmirage.inf C:\Windows\System32\DriverStore\Temp\{49f1cc80-adfd-7fa5-70ae-b9165f4ec271}\dfmirage.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3348"C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe" C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe
explorer.exe
User:
admin
Company:
MS
Integrity Level:
MEDIUM
Description:
Win USB Display Setup
Exit code:
0
Version:
3.1.5.75
Modules
Images
c:\users\admin\desktop\winusbdisplay_windows_v3.1.5.75.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3372"C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe" /SPAWNWND=$70160 /NOTIFYWND=$9014C C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe
WinUSBDisplay_Windows_V3.1.5.75.tmp
User:
admin
Company:
MS
Integrity Level:
HIGH
Description:
Win USB Display Setup
Exit code:
0
Version:
3.1.5.75
Modules
Images
c:\users\admin\desktop\winusbdisplay_windows_v3.1.5.75.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3384"C:\Users\admin\AppData\Local\Temp\is-KICLV.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmp" /SL5="$9014C,3547400,869376,C:\Users\admin\Desktop\WinUSBDisplay_Windows_V3.1.5.75.exe" C:\Users\admin\AppData\Local\Temp\is-KICLV.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmpWinUSBDisplay_Windows_V3.1.5.75.exe
User:
admin
Company:
MS
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kiclv.tmp\winusbdisplay_windows_v3.1.5.75.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3672C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
25 209
Read events
24 899
Write events
293
Delete events
17

Modification events

(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C00A0000D233872338C2DA01
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
109EF75874CED43413BAE0654D20C003FCF6286A92AD4C27C814D03C2A50B27B
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Win USB Display\WinUsbDisplay.exe
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
0D5752A33FF038E3BABC8198DB39636DC4E3CFCB4344E2B8B86468E8714A1153
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0
Operation:writeName:Attach.ToDesktop
Value:
0
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VirtualDisplay
Operation:writeName:DisplayName
Value:
VirtualDisplay
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VirtualDisplay
Operation:writeName:ErrorControl
Value:
1
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VirtualDisplay
Operation:writeName:ImagePath
Value:
\??\C:\Program Files\Win USB Display\displaywddm\VirtualDisplay.sys
(PID) Process:(2752) WinUSBDisplay_Windows_V3.1.5.75.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VirtualDisplay
Operation:writeName:Start
Value:
1
Executable files
85
Suspicious files
65
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\is-6UG85.tmpexecutable
MD5:E8382FC5D76159A6E0CB51B26D394DA8
SHA256:53DDF4CDF81AE2659B5E0C79FC9EAFF56629BA778019A94BF4A8A093FF510F3E
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\is-VRC1L.tmpexecutable
MD5:6FE22E049A79656F306BD86D4AF7D5D6
SHA256:0BF87C69471374FBED04A61C344FC8D933201F3D69880E8444D69137B6F04951
3348WinUSBDisplay_Windows_V3.1.5.75.exeC:\Users\admin\AppData\Local\Temp\is-KICLV.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmpexecutable
MD5:81EDEF1456847E107D2C8AA7D52BA52B
SHA256:E1A97ACD1C9637331AD15C1139907539841F7937D0CA3596CEA9D777B63F6B60
3372WinUSBDisplay_Windows_V3.1.5.75.exeC:\Users\admin\AppData\Local\Temp\is-MMQM3.tmp\WinUSBDisplay_Windows_V3.1.5.75.tmpexecutable
MD5:81EDEF1456847E107D2C8AA7D52BA52B
SHA256:E1A97ACD1C9637331AD15C1139907539841F7937D0CA3596CEA9D777B63F6B60
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\WinUsbDisplay.exeexecutable
MD5:E8382FC5D76159A6E0CB51B26D394DA8
SHA256:53DDF4CDF81AE2659B5E0C79FC9EAFF56629BA778019A94BF4A8A093FF510F3E
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\is-01DOR.tmpimage
MD5:2098EF97358FBBDFAE0206BBCB4E2234
SHA256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\is-L5L5T.tmpexecutable
MD5:3F76E3830F061414AC3AE99CA5F5BE2F
SHA256:F65C999FF4DB0FA98CB84006A4BADEBAF32232003181A9057EA93622C2D068C0
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\libyuv.dllexecutable
MD5:3F76E3830F061414AC3AE99CA5F5BE2F
SHA256:F65C999FF4DB0FA98CB84006A4BADEBAF32232003181A9057EA93622C2D068C0
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\tool\x64\devcon.exeexecutable
MD5:79C8395D54FA2E32425A56807240523B
SHA256:8181EB7DF558D3A42A0C55BE96A19D1BD88B77E0228B8E69BD4704821CA88510
2752WinUSBDisplay_Windows_V3.1.5.75.tmpC:\Program Files\Win USB Display\tool\x64\is-I9U4F.tmpexecutable
MD5:25D0A711E33C75B197D76884DBA1DBF1
SHA256:B6BAE3BB8FE8DEE5DB004965BBEA0466BAB7BB4B4193E8FA544ABF47F03562A5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1060
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
unknown
unknown
1372
svchost.exe
GET
200
2.21.240.93:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
92.122.89.124:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
2564
svchost.exe
239.255.255.250:3702
unknown
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
2.21.240.93:80
crl.microsoft.com
Akamai International B.V.
SE
unknown
1372
svchost.exe
92.122.89.124:80
www.microsoft.com
Akamai International B.V.
NL
unknown
1060
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 2.21.240.93
  • 2.21.240.225
whitelisted
www.microsoft.com
  • 92.122.89.124
whitelisted

Threats

No threats detected
No debug info