File name:

KTL_5.7.3.exe

Full analysis: https://app.any.run/tasks/82110912-f108-4ca0-b76d-b2547546d36a
Verdict: Malicious activity
Analysis date: June 14, 2025, 03:00:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
mpress
autoit
obfuscated-js
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections
MD5:

EC86FA9D7462B9CCF45201274645E67D

SHA1:

A654AB9D5487CB84775262B1E34795E70B41FF86

SHA256:

C081004CB7AABA284FEB580DF12F6CA777D1DA07479EACAC39533C182DC3E1F6

SSDEEP:

49152:oAKda+xbKBV6Z0m3aXL227BRzxX2kpFKZNMr9xKtGQC2qk3jROJjAAfgdX3pXaed:j+RK6ZF3e7LxX2khK4Qje4dX3p9vmnOj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • KTL_5.7.3.exe (PID: 6620)
      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • KTL_5.7.3.exe (PID: 6668)
    • Reads Microsoft Outlook installation path

      • KTL_5.7.3.exe (PID: 6668)
    • Reads security settings of Internet Explorer

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Reads Internet Explorer settings

      • KTL_5.7.3.exe (PID: 6668)
    • Executable content was dropped or overwritten

      • startup.exe (PID: 3876)
      • startup.exe (PID: 6268)
      • startup.exe (PID: 6104)
    • There is functionality for taking screenshot (YARA)

      • KTL_5.7.3.exe (PID: 6668)
      • setup_ui.exe (PID: 7964)
      • KTL_5.7.3.exe (PID: 8692)
    • Application launched itself

      • startup.exe (PID: 3876)
      • KTL_5.7.3.exe (PID: 6668)
      • msiexec.exe (PID: 1040)
    • Starts itself from another location

      • startup.exe (PID: 6268)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
      • msiexec.exe (PID: 1040)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 8896)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 8896)
  • INFO

    • The sample compiled with english language support

      • KTL_5.7.3.exe (PID: 6668)
      • firefox.exe (PID: 5644)
      • startup.exe (PID: 6268)
      • startup.exe (PID: 6104)
      • startup.exe (PID: 3876)
      • msiexec.exe (PID: 1040)
      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
    • Reads mouse settings

      • KTL_5.7.3.exe (PID: 6668)
    • Checks supported languages

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Reads the computer name

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Create files in a temporary directory

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
    • Manual execution by a user

      • firefox.exe (PID: 5168)
      • msedge.exe (PID: 9212)
    • Application launched itself

      • firefox.exe (PID: 5168)
      • firefox.exe (PID: 5644)
      • msedge.exe (PID: 8944)
      • msedge.exe (PID: 9212)
      • msedge.exe (PID: 8912)
      • msedge.exe (PID: 7920)
    • Checks proxy server information

      • KTL_5.7.3.exe (PID: 6668)
      • startup.exe (PID: 3876)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 5644)
    • Reads the software policy settings

      • startup.exe (PID: 3876)
    • Reads the machine GUID from the registry

      • startup.exe (PID: 3876)
      • setup_ui.exe (PID: 1028)
    • Checks for the presence of KasperskyLab

      • startup.exe (PID: 3876)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5644)
    • The process uses AutoIt

      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
    • Mpress packer has been detected

      • KTL_5.7.3.exe (PID: 6668)
      • KTL_5.7.3.exe (PID: 8692)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 5644)
      • msiexec.exe (PID: 1040)
      • msiexec.exe (PID: 8896)
      • msiexec.exe (PID: 7572)
    • Process checks whether UAC notifications are on

      • startup.exe (PID: 3876)
    • Creates files in the program directory

      • startup.exe (PID: 3876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:17 16:42:41+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit, No debug
PEType: PE32
LinkerVersion: 14.16
CodeSize: 633856
InitializedDataSize: 1301504
UninitializedDataSize: -
EntryPoint: 0x1df3f8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.7.3.0
ProductVersionNumber: 5.7.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 5.7.3.0
ProductVersion: 5.7.3.0
ProductName: Kaspersky Tweak Lite
OriginalFileName: KTL
InternalName: KTL
FileDescription: Kaspersky Tweak Lite
CompanyName: TAWAB Soft 2025
LegalTrademarks: TAWAB Soft 2025
LegalCopyright: TAWAB Soft 2025
Comments: please visit : https://sites.google.com/view/samsoft
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
217
Monitored processes
66
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ktl_5.7.3.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs startup.exe setup_ui.exe startup.exe startup.exe setup_ui.exe slui.exe ktl_5.7.3.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe msedge.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs ktl_5.7.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4920,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5176 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
304"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5300,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5268 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
984"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5232,i,4368162642838346827,157830249329945786,262144 --variations-seed-version --mojo-platform-channel-handle=5272 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Users\admin\AppData\Local\Temp\308F6A4DBC840F114B0F817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAABIglZ13psVSIt0EyK4+3g3AogAACQP//+zOrnP1RzPYTcAIQAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgA1AAAAAAAJAP//AAAeAP//AAAQAP//AAAKAP//AAAWAP//AAAfAP//AAAOAP//AAAAAA==:C:\Users\admin\AppData\Local\Temp\308F6A4DBC840F114B0F817F87F669EE\setup_ui.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.18.0]
Exit code:
0
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\308f6a4dbc840f114b0f817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
1040C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1496"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5052,i,17422986050885056309,9834134279219405094,262144 --variations-seed-version --mojo-platform-channel-handle=5096 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2764,i,17422986050885056309,9834134279219405094,262144 --variations-seed-version --mojo-platform-channel-handle=2948 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2612"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6172 -prefsLen 39231 -prefMapHandle 6168 -prefMapSize 272997 -jsInitHandle 6164 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6208 -initialChannelId {950ba554-bc7c-4727-aef8-f1ad0a5e9ac6} -parentPid 5644 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5644" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
3160C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 7372 -prefsLen 39520 -prefMapHandle 7676 -prefMapSize 272997 -jsInitHandle 7680 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5656 -initialChannelId {22b7b88c-e9fa-49de-8d95-91c2460817c6} -parentPid 5644 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5644" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
Total events
49 952
Read events
49 500
Write events
442
Delete events
10

Modification events

(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\1573B2F840D61F0B0B16AEDE5A35726F9E93117B
Operation:writeName:Blob
Value:
1900000001000000100000000482B43DE35322C3316263CAA047B71E0F00000001000000140000003321029F5D2AA18F786D64B9E0F6974ED14430AF0200000001000000C40000001C0000006C00000001000000000000000000000000000000010000007B00380042004600320036004300440046002D0046003100430046002D0034003800420031002D0041004500380038002D003200370033003400300036004400300045004500320045007D00000000004D006900630072006F0073006F0066007400200042006100730065002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E003000000000000B000000010000000200000000000300000001000000140000001573B2F840D61F0B0B16AEDE5A35726F9E93117B140000000100000014000000C249345BDD960BACF1A4722906D8E08F8253957820000000010000007802000030820274308201DDA00302010202110084A4E6838DC066869EC2E8B759251B40300D06092A864886F70D0101050500305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E301E170D3230303130313036343830395A170D3435303130313036343830395A305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E30819F300D06092A864886F70D010101050003818D003081890281810085A57ABF7363A26064014FE26DEB8E8870DEDED94E04A591821F72509524C6611AB43A36ECEE63E558989C6BC21A46006039F0F26F45B660A17252FD511ADB5435624573A893ACB95E40E4FE887D9E610F93DA3F8EAE6610180BCE1601947B165C9BBB622FF9CF7CBBCA8DCD653DD21A7A4688B04597A761C97DB8D73ADB8AEF0203010001A3463044300E0603551D0F0101FF04040302078030130603551D25040C300A06082B06010505070303301D0603551D0E04160414C249345BDD960BACF1A4722906D8E08F82539578300D06092A864886F70D0101050500038181003F9676C4420AF79A4EC4F8805077D7B106B84F0855366716486B1D531FBC3BE661B244158D7EBA6DD20A9A9DD87FF427C93595AA0A6238B6F1CAF341C5686CF9AA031AC66B6C0C1D31F58DFAC1284550EA510B99FE73C4EE7F4FD121EC21FB9DBF7E13E0689235F2B8655C50D3838CC2684196B995CD57DFE0109D506CF83F60
(PID) Process:(5644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6668) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(3876) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
7
Executable files
502
Suspicious files
1 285
Text files
522
Unknown types
0

Dropped files

PID
Process
Filename
Type
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\~DF152FFC3911A25722.TMPbinary
MD5:6A1818053A264D881FF1C76A37F556CA
SHA256:8438FAAE3712AA6FFDA155947E01F880E40E48A1163AAA399964086D788AA396
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:DD89AA41282E67ACD7C69EFC0E05CF6F
SHA256:24450124DFA6AE725F7D84FD9A68860A04484DF440FF09D10B8E49B414BA81B6
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\~DFC0D73ECBC36EA535.TMPbinary
MD5:53FE6B103C6A583ED6591DFCE4B5B6F1
SHA256:7BDB13A3BB01B344D1D6F05C601C9475D0DDA2A49F6F4C1FB26A4D1149CE9E07
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
5644firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:3134ED3F12E4F4F8643DB90043B0FD7B
SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1
5644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licExpo.icoimage
MD5:ACB74483BF38B4497FCFD0B275FFE743
SHA256:E09A4C4062797E06CE8DD03960A43067EEA2BEAABF70C7FFE370F6434F56D698
6668KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licReset.icoimage
MD5:65E328AC8667E56B91F34411635E4F5A
SHA256:134F2698140BA21472646DBED559956BD06EB40C3363813B8696182E6F3ADEDA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
113
TCP/UDP connections
295
DNS requests
391
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5644
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5644
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
5644
firefox.exe
POST
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
unknown
whitelisted
5644
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5644
firefox.exe
POST
200
104.124.11.185:80
http://r10.o.lencr.org/
unknown
whitelisted
5644
firefox.exe
POST
200
2.16.241.8:80
http://r11.o.lencr.org/
unknown
whitelisted
5644
firefox.exe
POST
200
2.16.241.8:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6960
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5644
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
5644
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
5644
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
5644
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted
5644
firefox.exe
142.250.184.195:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.110
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted
example.org
  • 96.7.128.192
  • 96.7.128.186
  • 23.215.0.132
  • 23.215.0.133
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6876
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6876
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
setup_ui.exe
LocalizationEngine Making localization parameters
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui.interoplayer, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui.core, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
setup_ui.exe Information: 0 :
setup_ui.exe
Localization Resources scanned in assembly 'kl.setup.ui, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.
setup_ui.exe
Localization Resources scanned in assembly 'kl.ui.framework, Version=21.21.7.384, Culture=neutral, PublicKeyToken=null'. Resources count: 0.