File name:

KTL_5.7.3.exe

Full analysis: https://app.any.run/tasks/82110912-f108-4ca0-b76d-b2547546d36a
Verdict: Malicious activity
Analysis date: June 14, 2025, 03:00:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
mpress
autoit
obfuscated-js
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections
MD5:

EC86FA9D7462B9CCF45201274645E67D

SHA1:

A654AB9D5487CB84775262B1E34795E70B41FF86

SHA256:

C081004CB7AABA284FEB580DF12F6CA777D1DA07479EACAC39533C182DC3E1F6

SSDEEP:

49152:oAKda+xbKBV6Z0m3aXL227BRzxX2kpFKZNMr9xKtGQC2qk3jROJjAAfgdX3pXaed:j+RK6ZF3e7LxX2khK4Qje4dX3p9vmnOj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • KTL_5.7.3.exe (PID: 6620)
      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • KTL_5.7.3.exe (PID: 6668)
    • Reads Microsoft Outlook installation path

      • KTL_5.7.3.exe (PID: 6668)
    • Reads Internet Explorer settings

      • KTL_5.7.3.exe (PID: 6668)
    • Reads security settings of Internet Explorer

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Executable content was dropped or overwritten

      • startup.exe (PID: 3876)
      • startup.exe (PID: 6104)
      • startup.exe (PID: 6268)
    • There is functionality for taking screenshot (YARA)

      • KTL_5.7.3.exe (PID: 6668)
      • setup_ui.exe (PID: 7964)
      • KTL_5.7.3.exe (PID: 8692)
    • Starts itself from another location

      • startup.exe (PID: 6268)
    • Application launched itself

      • startup.exe (PID: 3876)
      • KTL_5.7.3.exe (PID: 6668)
      • msiexec.exe (PID: 1040)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
      • msiexec.exe (PID: 1040)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 8896)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 8896)
  • INFO

    • Checks supported languages

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Manual execution by a user

      • firefox.exe (PID: 5168)
      • msedge.exe (PID: 9212)
    • Reads mouse settings

      • KTL_5.7.3.exe (PID: 6668)
    • Reads the computer name

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Application launched itself

      • firefox.exe (PID: 5168)
      • firefox.exe (PID: 5644)
      • msedge.exe (PID: 8944)
      • msedge.exe (PID: 9212)
      • msedge.exe (PID: 8912)
      • msedge.exe (PID: 7920)
    • Create files in a temporary directory

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
    • Checks proxy server information

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
    • The process uses AutoIt

      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
    • Mpress packer has been detected

      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 5644)
      • msiexec.exe (PID: 1040)
      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5644)
    • Reads the software policy settings

      • startup.exe (PID: 3876)
    • The sample compiled with english language support

      • firefox.exe (PID: 5644)
      • startup.exe (PID: 3876)
      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 6268)
      • startup.exe (PID: 6104)
      • msiexec.exe (PID: 1040)
      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
    • Checks for the presence of KasperskyLab

      • startup.exe (PID: 3876)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 5644)
    • Process checks whether UAC notifications are on

      • startup.exe (PID: 3876)
    • Reads the machine GUID from the registry

      • setup_ui.exe (PID: 1028)
      • startup.exe (PID: 3876)
    • Creates files in the program directory

      • startup.exe (PID: 3876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:17 16:42:41+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit, No debug
PEType: PE32
LinkerVersion: 14.16
CodeSize: 633856
InitializedDataSize: 1301504
UninitializedDataSize: -
EntryPoint: 0x1df3f8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.7.3.0
ProductVersionNumber: 5.7.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 5.7.3.0
ProductVersion: 5.7.3.0
ProductName: Kaspersky Tweak Lite
OriginalFileName: KTL
InternalName: KTL
FileDescription: Kaspersky Tweak Lite
CompanyName: TAWAB Soft 2025
LegalTrademarks: TAWAB Soft 2025
LegalCopyright: TAWAB Soft 2025
Comments: please visit : https://sites.google.com/view/samsoft
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
217
Monitored processes
66
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ktl_5.7.3.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs startup.exe setup_ui.exe startup.exe startup.exe setup_ui.exe slui.exe ktl_5.7.3.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe msedge.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs ktl_5.7.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4920,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5176 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
304"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5300,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5268 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
984"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5232,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5272 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Users\admin\AppData\Local\Temp\308F6A4DBC840F114B0F817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAABIglZ13psVSIt0EyK4+3g3AogAACQP//+zOrnP1RzPYTcAIQAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgA1AAAAAAAJAP//AAAeAP//AAAQAP//AAAKAP//AAAWAP//AAAfAP//AAAOAP//AAAAAA==:C:\Users\admin\AppData\Local\Temp\308F6A4DBC840F114B0F817F87F669EE\setup_ui.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.18.0]
Exit code:
0
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\308f6a4dbc840f114b0f817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
1040C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1496"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5052,i,17422986050885056309,9834134279219405094,262144 --variations-seed-version --mojo-platform-channel-handle=5096 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2764,i,17422986050885056309,9834134279219405094,262144 --variations-seed-version --mojo-platform-channel-handle=2948 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2612"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6172 -prefsLen 39231 -prefMapHandle 6168 -prefMapSize 272997 -jsInitHandle 6164 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6208 -initialChannelId {950ba554-bc7c-4727-aef8-f1ad0a5e9ac6} -parentPid 5644 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5644" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
3160C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 7372 -prefsLen 39520 -prefMapHandle 7676 -prefMapSize 272997 -jsInitHandle 7680 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5656 -initialChannelId {22b7b88c-e9fa-49de-8d95-91c2460817c6} -parentPid 5644 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5644" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
Total events
49 952
Read events
49 500
Write events
442
Delete events
10

Modification events

(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\1573B2F840D61F0B0B16AEDE5A35726F9E93117B
Operation:writeName:Blob
Value:
1900000001000000100000000482B43DE35322C3316263CAA047B71E0F00000001000000140000003321029F5D2AA18F786D64B9E0F6974ED14430AF0200000001000000C40000001C0000006C00000001000000000000000000000000000000010000007B00380042004600320036004300440046002D0046003100430046002D0034003800420031002D0041004500380038002D003200370033003400300036004400300045004500320045007D00000000004D006900630072006F0073006F0066007400200042006100730065002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E003000000000000B000000010000000200000000000300000001000000140000001573B2F840D61F0B0B16AEDE5A35726F9E93117B140000000100000014000000C249345BDD960BACF1A4722906D8E08F8253957820000000010000007802000030820274308201DDA00302010202110084A4E6838DC066869EC2E8B759251B40300D06092A864886F70D0101050500305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E301E170D3230303130313036343830395A170D3435303130313036343830395A305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E30819F300D06092A864886F70D010101050003818D003081890281810085A57ABF7363A26064014FE26DEB8E8870DEDED94E04A591821F72509524C6611AB43A36ECEE63E558989C6BC21A46006039F0F26F45B660A17252FD511ADB5435624573A893ACB95E40E4FE887D9E610F93DA3F8EAE6610180BCE1601947B165C9BBB622FF9CF7CBBCA8DCD653DD21A7A4688B04597A761C97DB8D73ADB8AEF0203010001A3463044300E0603551D0F0101FF04040302078030130603551D25040C300A06082B06010505070303301D0603551D0E04160414C249345BDD960BACF1A4722906D8E08F82539578300D06092A864886F70D0101050500038181003F9676C4420AF79A4EC4F8805077D7B106B84F0855366716486B1D531FBC3BE661B244158D7EBA6DD20A9A9DD87FF427C93595AA0A6238B6F1CAF341C5686CF9AA031AC66B6C0C1D31F58DFAC1284550EA510B99FE73C4EE7F4FD121EC21FB9DBF7E13E0689235F2B8655C50D3838CC2684196B995CD57DFE0109D506CF83F60
(PID) Process:(5644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
7
Executable files
502
Suspicious files
1 285
Text files
522
Unknown types
0

Dropped files

PID
Process
Filename
Type
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\flag_usa.jpgimage
MD5:37CC8C7241C52CF03BA78EAA368975C0
SHA256:016C98C51F7326E5DCA1EF44DF06F71B21B51E49442CA1F5E751EC8ED75E7AA8
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\KAV.icoimage
MD5:07285205035CC97BB897BC9858439FD0
SHA256:58E5CFF5B042904D6AD8AEC159B5F46EE327FC2584EFB4082C211ACE2532089B
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\bounce-tracking-protection.sqlite-journalbinary
MD5:CABA904E549AF92CEC354A204EC9B090
SHA256:96643C4270200B5952A78AC82D28A751160F256F48EA5E61342F30C2E6B1DDE2
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licReset.icoimage
MD5:65E328AC8667E56B91F34411635E4F5A
SHA256:134F2698140BA21472646DBED559956BD06EB40C3363813B8696182E6F3ADEDA
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\Nolicense.jpgimage
MD5:3BDC5C25DE0F1A8C29C44049AB77CB8C
SHA256:53F5FEE17915B07125DFA2E2101C41960D18DCC0C3AFCFBDFF740E8B746F9635
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\~DF152FFC3911A25722.TMPbinary
MD5:6A1818053A264D881FF1C76A37F556CA
SHA256:8438FAAE3712AA6FFDA155947E01F880E40E48A1163AAA399964086D788AA396
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2FD670934FEF0C60E2119BD874AAF470
SHA256:771A7C83CA015BDBC6AB86A7BD9B1D54E40062E28942D311A9178A0FE6433CF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
113
TCP/UDP connections
295
DNS requests
391
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
5644
firefox.exe
POST
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
unknown
whitelisted
5644
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
POST
200
2.16.241.8:80
http://r11.o.lencr.org/
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
unknown
whitelisted
5644
firefox.exe
POST
200
104.124.11.185:80
http://r10.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6960
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5644
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
5644
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
5644
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
5644
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted
5644
firefox.exe
142.250.184.195:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.110
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted
example.org
  • 96.7.128.192
  • 96.7.128.186
  • 23.215.0.132
  • 23.215.0.133
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6876
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6876
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
setup_ui.exe
LocalizationEngine Making localization parameters
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui.core, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
Localization Resources scanned in assembly 'kl.ui.framework, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui.interoplayer, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
setup_ui.exe Information: 0 :