URL:

https://www.synaptics.com/products/displaylink-graphics/downloads

Full analysis: https://app.any.run/tasks/af7e558d-1b29-4e10-8eab-c8b15b19ea3d
Verdict: Malicious activity
Analysis date: January 30, 2025, 19:23:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
advancedinstaller
Indicators:
MD5:

E4FDA2CED4F22FA7CB2F93131149E9BA

SHA1:

2E90F5DC48AC91ABB22D677F06C62698BF2CEFF7

SHA256:

BFAFFF179835D88FC50A27EC234E172CB9193662CE601CF41917D58B4CB03CDA

SSDEEP:

3:N8DSLQWLzXaQGRWaMS4ZN8Sen:2OLDyRWHRX8X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • additional.exe (PID: 1400)
      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
    • Drops 7-zip archiver for unpacking

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
    • Drops a system driver (possible attempt to evade defenses)

      • additional.exe (PID: 1400)
      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • msiexec.exe (PID: 7056)
      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
    • Reads security settings of Internet Explorer

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
    • ADVANCEDINSTALLER mutex has been found

      • DLDF52.exe (PID: 1328)
    • Checks Windows Trust Settings

      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7024)
      • drvinst.exe (PID: 3656)
      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
    • Reads the Windows owner or organization settings

      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7024)
    • Process drops legitimate windows executable

      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
    • There is functionality for taking screenshot (YARA)

      • DLDF52.exe (PID: 1328)
    • Reads Microsoft Outlook installation path

      • DLDF52.exe (PID: 1328)
    • Application launched itself

      • DLDF52.exe (PID: 1328)
    • Reads Internet Explorer settings

      • DLDF52.exe (PID: 1328)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3508)
    • The process creates files with name similar to system file names

      • DLDF52.exe (PID: 1328)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 7056)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7024)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
  • INFO

    • Reads the computer name

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • msiexec.exe (PID: 1076)
      • msiexec.exe (PID: 2148)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 6708)
      • msiexec.exe (PID: 4528)
      • msiexec.exe (PID: 4944)
      • msiexec.exe (PID: 7056)
      • drvinst.exe (PID: 3656)
      • msiexec.exe (PID: 7024)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
    • Checks supported languages

      • SearchApp.exe (PID: 5064)
      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • additional.exe (PID: 1400)
      • DLDF52.exe (PID: 1328)
      • msiexec.exe (PID: 7024)
      • msiexec.exe (PID: 1076)
      • msiexec.exe (PID: 2148)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 4944)
      • msiexec.exe (PID: 4528)
      • msiexec.exe (PID: 6708)
      • msiexec.exe (PID: 7056)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
      • DisplayLinkTrayApp.exe (PID: 5208)
      • drvinst.exe (PID: 3656)
    • The sample compiled with english language support

      • additional.exe (PID: 1400)
      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • msiexec.exe (PID: 1076)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7024)
      • msiexec.exe (PID: 7056)
      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
    • Create files in a temporary directory

      • additional.exe (PID: 1400)
      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • msiexec.exe (PID: 1076)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 6708)
      • msiexec.exe (PID: 7056)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 4164)
      • msiexec.exe (PID: 1076)
      • msiexec.exe (PID: 7024)
      • msiexec.exe (PID: 7056)
    • Reads the machine GUID from the registry

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7024)
      • msiexec.exe (PID: 7056)
      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
      • SearchApp.exe (PID: 5064)
    • Reads the software policy settings

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7024)
      • drvinst.exe (PID: 3656)
      • drvinst.exe (PID: 6860)
      • drvinst.exe (PID: 6944)
      • SearchApp.exe (PID: 5064)
    • Creates files or folders in the user directory

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
    • Checks proxy server information

      • DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe (PID: 5728)
      • DLDF52.exe (PID: 1328)
    • Application launched itself

      • chrome.exe (PID: 4164)
      • msiexec.exe (PID: 7024)
    • Reads Environment values

      • DLDF52.exe (PID: 1328)
      • msiexec.exe (PID: 1076)
      • msiexec.exe (PID: 2148)
      • DLDF52.exe (PID: 2996)
      • msiexec.exe (PID: 7056)
      • msiexec.exe (PID: 6708)
    • Process checks computer location settings

      • DLDF52.exe (PID: 1328)
      • SearchApp.exe (PID: 5064)
    • Manages system restore points

      • SrTasks.exe (PID: 6584)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
45
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs displaylink usb graphics software for windows11.6 m0-exe.exe no specs displaylink usb graphics software for windows11.6 m0-exe.exe additional.exe conhost.exe no specs chrome.exe no specs dldf52.exe msiexec.exe msiexec.exe msiexec.exe no specs dldf52.exe vssvc.exe no specs chrome.exe no specs chrome.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe taskkill.exe no specs conhost.exe no specs msiexec.exe msiexec.exe chrome.exe no specs drvinst.exe drvinst.exe drvinst.exe displaylinktrayapp.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
520"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4352 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1076C:\Windows\syswow64\MsiExec.exe -Embedding B563D0BEDCDB49D34E3454078251D77A CC:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1328DLDF52.exe /exelang 1033 DL_INSTALL_AUDIO=Yes DL_NO_EULA=Yes DL_PROMOTE_STORE_APP=Yes DL_PRODUCT_NAME="DisplayLink Graphics" DL_BRANDING_UPGRADE_CODE="{78A36ACD-80D5-490f-B4C4-83D7FCC08391}" DL_BRANDING_PRODUCT_CODE="{7A240486-2EFA-42D9-AF37-590752CD6413}" DL_BRANDING_CAB="C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLE0CA.tmp" DL_BRANDING_NEW_DEVICE_ACTIVITY=mirror0 DL_ID_USBDRIVER_PATH="C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLIDUSB\x64" DL_HOTDESK_SERVICE="No" DL_INSTALL_ANALYTICS=Yes DL_VMM_FIRMWARE_INCLUDED="No" DL_TEMP_DIR="C:\Users\admin\AppData\Local\Temp\DL2.tmp\" /lv "C:\Users\admin\AppData\Local\Temp\DLC7333.LOG"C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe
DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe
User:
admin
Company:
DisplayLink Corp.
Integrity Level:
HIGH
Description:
DisplayLink Graphics Installer
Exit code:
1626
Version:
11.6.7168.0
Modules
Images
c:\users\admin\appdata\local\temp\dl2.tmp\dldf52.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1400"C:\Users\admin\AppData\Local\Temp\DL2.tmp\additional.exe" -y -o"C:\Users\admin\AppData\Local\Temp\DL2.tmp\"C:\Users\admin\AppData\Local\Temp\DL2.tmp\additional.exe
DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
19.00
Modules
Images
c:\users\admin\appdata\local\temp\dl2.tmp\additional.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1540"C:\Users\admin\Downloads\DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe" C:\Users\admin\Downloads\DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exechrome.exe
User:
admin
Company:
DisplayLink Corp.
Integrity Level:
MEDIUM
Description:
Installs DisplayLink Software
Exit code:
3221226540
Version:
11, 6, 7312, 0
Modules
Images
c:\users\admin\downloads\displaylink usb graphics software for windows11.6 m0-exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1576\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2148C:\Windows\System32\MsiExec.exe -Embedding A3F417ECABF0889A9AC89D45C43064A3 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2996"C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe" /i C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi /lv C:\Users\admin\AppData\Local\Temp\DLC7333.LOG AI_EUIMSI=1 APPDIR="C:\Program Files\DisplayLink Core Software" M_DIR="C:\ProgramData\Microsoft" SECONDSEQUENCE="1" CLIENTPROCESSID="1328" AI_MORE_CMD_LINE=1C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe
DLDF52.exe
User:
admin
Company:
DisplayLink Corp.
Integrity Level:
HIGH
Description:
DisplayLink Graphics Installer
Exit code:
0
Version:
11.6.7168.0
Modules
Images
c:\users\admin\appdata\local\temp\dl2.tmp\dldf52.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3124"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4352 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
3172"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5724 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
46 344
Read events
45 827
Write events
485
Delete events
32

Modification events

(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4164) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D000000276707754C73DB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicText
Value:
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicTextTruncated
Value:
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00320035003500370038003200350037002D0030003500660039002D0034003900630066002D0062003200310063002D006400340064003700310066003500650039003600650036007D0000004BB90B754C73DB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LastConstraintIndexBuildCompleted
Value:
AB290C754C73DB01EE070C754C73DB01
Executable files
137
Suspicious files
623
Text files
235
Unknown types
4

Dropped files

PID
Process
Filename
Type
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1383f8.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1383f8.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1383f8.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF138408.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF138408.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF138418.TMP
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
116
DNS requests
108
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4128
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7004
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4128
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6816
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
6816
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
104.126.37.145:443
r.bing.com
Akamai International B.V.
DE
whitelisted
4164
chrome.exe
239.255.255.250:1900
whitelisted
6336
chrome.exe
50.112.41.9:443
www.synaptics.com
AMAZON-02
US
whitelisted
6336
chrome.exe
108.177.127.84:443
accounts.google.com
GOOGLE
US
whitelisted
6336
chrome.exe
172.217.23.100:443
www.google.com
GOOGLE
US
whitelisted
6336
chrome.exe
151.101.65.229:443
cdn.jsdelivr.net
FASTLY
US
whitelisted
6336
chrome.exe
108.138.36.77:443
consent.trustarc.com
AMAZON-02
US
shared
6336
chrome.exe
151.101.130.217:443
cdn.bfldr.com
FASTLY
US
suspicious

DNS requests

Domain
IP
Reputation
www.synaptics.com
  • 50.112.41.9
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
www.google.com
  • 172.217.23.100
  • 142.250.185.132
whitelisted
consent.trustarc.com
  • 108.138.36.77
  • 108.138.36.50
  • 108.138.36.25
  • 108.138.36.20
shared
cdn.jsdelivr.net
  • 151.101.65.229
  • 151.101.129.229
  • 151.101.1.229
  • 151.101.193.229
whitelisted
cdn.bfldr.com
  • 151.101.130.217
  • 151.101.2.217
  • 151.101.66.217
  • 151.101.194.217
unknown
www.gstatic.com
  • 142.250.185.227
whitelisted
fonts.googleapis.com
  • 142.250.186.170
whitelisted
fonts.gstatic.com
  • 142.250.185.227
whitelisted
players.brightcove.net
  • 23.218.209.37
whitelisted

Threats

PID
Process
Class
Message
6336
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6336
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6336
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6336
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Process
Message
DLDF52.exe
MSI (c) (B4:04) [19:25:12:614]: Entering MsiOpenPackageEx. szPackagePath: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi, dwOptions: 0, hProduct: D3F1AC
DLDF52.exe
MSI (c) (B4:04) [19:25:12:614]: Entering MsiOpenPackage. szPackagePath: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi, hProduct: D3F1AC
DLDF52.exe
DLDF52.exe
DLDF52.exe
DLDF52.exe
MSI (c) (B4:04) [19:25:12:614]: Machine policy value 'Timeout' is 1800
DLDF52.exe
MSI (c) (B4:04) [19:25:12:630]: SOFTWARE RESTRICTION POLICY: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi has a digital signature
DLDF52.exe
MSI (c) (B4:04) [19:25:12:630]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi' against software restriction policy
DLDF52.exe
DLDF52.exe