File name:

ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe

Full analysis: https://app.any.run/tasks/8a49c5e3-63c7-4b14-add9-1a176d3312fd
Verdict: Malicious activity
Analysis date: March 13, 2024, 07:24:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D63F153BA77F9DEE790D171A5A3D9D4D

SHA1:

C4A2491426A1E4E2ED4D858BD33C053616E3B6D8

SHA256:

C0BFB4B702F81C9C04BA578846C58CA41923824F1729BBD379D53AF6708703CA

SSDEEP:

98304:UgIjhRwfnbTAyAB+Wj+mOpkoFZKssPnqrOpVTJvU6f0hvpfJEUjdVouB8U+j74jU:anAI1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3656)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3948)
    • Create files in the Startup directory

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Creates a writable file in the system directory

      • DCA.Edge.Console.exe (PID: 1336)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3656)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3948)
    • Reads the Windows owner or organization settings

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Process drops legitimate windows executable

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Uses TASKKILL.EXE to kill process

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Reads security settings of Internet Explorer

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.Console.exe (PID: 1336)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
    • Checks Windows Trust Settings

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.Console.exe (PID: 1336)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
    • Starts SC.EXE for service management

      • DCA.Edge.Console.exe (PID: 2896)
    • Reads settings of System Certificates

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
    • Reads the Internet Settings

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
    • Executes as Windows Service

      • DCA.Edge.Console.exe (PID: 1336)
    • Searches for installed software

      • DCA.Edge.Console.exe (PID: 1336)
    • Non-standard symbols in registry

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
  • INFO

    • Reads the computer name

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.Console.exe (PID: 1336)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3536)
    • Checks supported languages

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3948)
      • DCA.Edge.Console.exe (PID: 2896)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3656)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.Console.exe (PID: 1336)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3536)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Creates files in the program directory

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1336)
    • Create files in a temporary directory

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3656)
      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe (PID: 3948)
    • Reads the software policy settings

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.Console.exe (PID: 1336)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
    • Reads the machine GUID from the registry

      • DCA.Edge.Console.exe (PID: 2896)
      • DCA.Edge.Console.exe (PID: 1992)
      • DCA.Edge.TrayIcon.exe (PID: 3776)
      • DCA.Edge.Console.exe (PID: 1336)
    • Creates a software uninstall entry

      • ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp (PID: 3464)
    • Reads Environment values

      • DCA.Edge.TrayIcon.exe (PID: 3776)
      • DCA.Edge.Console.exe (PID: 1336)
    • Reads product name

      • DCA.Edge.Console.exe (PID: 1336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 14:39:04+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 360448
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.5.7.9296
ProductVersionNumber: 1.5.7.9296
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ECI Software Solutions, Inc.
FileDescription: ECI DCA Setup
FileVersion: 1.5.7.9296
LegalCopyright: ©2016-2024 ECI Software Solutions, Inc.
ProductName: ECI DCA
ProductVersion: 1.5.7.9296
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eci dca 1.5.7.9296 [h500ckmnujgk].exe eci dca 1.5.7.9296 [h500ckmnujgk].tmp no specs eci dca 1.5.7.9296 [h500ckmnujgk].exe eci dca 1.5.7.9296 [h500ckmnujgk].tmp taskkill.exe no specs taskkill.exe no specs dca.edge.console.exe no specs sc.exe no specs sc.exe no specs dca.edge.trayicon.exe no specs dca.edge.console.exe no specs dca.edge.console.exe

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" --config "C:\ProgramData\ECI DCA\dca.config"C:\Program Files\ECI DCA\DCA.Edge.Console.exe
services.exe
User:
SYSTEM
Company:
ECI Software Solutions, Inc
Integrity Level:
SYSTEM
Description:
ECI DCA
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1992"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" start-service C:\Program Files\ECI DCA\DCA.Edge.Console.exeECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
HIGH
Description:
ECI DCA
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2372"C:\Windows\system32\sc.exe" failure "DCAPulse" reset= 180 actions= restart/5000/restart/30000/restart/180000C:\Windows\System32\sc.exeDCA.Edge.Console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2636"taskkill.exe" /im DCA.Edge.TrayIcon.exeC:\Windows\System32\taskkill.exeECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2896"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" config --config "C:\ProgramData\ECI DCA\dca.config" --installer "C:\Users\admin\Downloads\ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe" --install-service C:\Program Files\ECI DCA\DCA.Edge.Console.exeECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
HIGH
Description:
ECI DCA
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3464"C:\Users\admin\AppData\Local\Temp\is-5NM8N.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp" /SL5="$F0130,3478115,428032,C:\Users\admin\Downloads\ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-5NM8N.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp
ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5nm8n.tmp\eci dca 1.5.7.9296 [h500ckmnujgk].tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3536"C:\Users\admin\AppData\Local\Temp\is-SJJOK.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp" /SL5="$E0170,3478115,428032,C:\Users\admin\Downloads\ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe" C:\Users\admin\AppData\Local\Temp\is-SJJOK.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpECI DCA 1.5.7.9296 [H500CKMNUJGK].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-sjjok.tmp\eci dca 1.5.7.9296 [h500ckmnujgk].tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3656"C:\Users\admin\Downloads\ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe" C:\Users\admin\Downloads\ECI DCA 1.5.7.9296 [H500CKMNUJGK].exe
explorer.exe
User:
admin
Company:
ECI Software Solutions, Inc.
Integrity Level:
MEDIUM
Description:
ECI DCA Setup
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\users\admin\downloads\eci dca 1.5.7.9296 [h500ckmnujgk].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3724"C:\Windows\system32\sc.exe" create "DCAPulse" start= delayed-auto DisplayName= "ECI DCA" binPath= "\"C:\Program Files\ECI DCA\DCA.Edge.Console.exe\" --config \"C:\ProgramData\ECI DCA\dca.config\"" C:\Windows\System32\sc.exeDCA.Edge.Console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3776"C:\Program Files\ECI DCA\DCA.Edge.TrayIcon.exe"C:\Program Files\ECI DCA\DCA.Edge.TrayIcon.exeECI DCA 1.5.7.9296 [H500CKMNUJGK].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
MEDIUM
Description:
ECI DCA Service Monitor
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.trayicon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
24 574
Read events
24 425
Write events
132
Delete events
17

Modification events

(PID) Process:(3464) ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
880D0000E2363A7B1775DA01
(PID) Process:(3464) ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3CB915EC4A969D222B0BF9D00544BE2A58B249525FB2184431361C492F9C8CAC
(PID) Process:(3464) ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3464) ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\ECI DCA\Abot.dll
(PID) Process:(3464) ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
C994372B39BD5EF52B936AE6D2F6809B90E3A5FF29D9C8FF2D3E88DE9BBD4ACE
(PID) Process:(2896) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2896) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2896) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2896) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2896) DCA.Edge.Console.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
97
Suspicious files
5
Text files
6
Unknown types
6

Dropped files

PID
Process
Filename
Type
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\is-BBPER.tmpexecutable
MD5:D447544C6131F197B619BC0019852EE1
SHA256:DF886EB50E15FFA297A9BBE2DC1B7804C121A0EC3E66A007CA65C0E6714CD0E8
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\is-I8IJ4.tmpexecutable
MD5:14DA5BFCD0E595C9234A1E14E24FA512
SHA256:F95D4AC735CD2B13D7BC4614FB3D835200559CB1AB30B81AB79B35FFA74817AB
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Users\admin\AppData\Local\Temp\is-33PTR.tmp\idp.dllexecutable
MD5:55C310C0319260D798757557AB3BF636
SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\is-7O1KQ.tmpexecutable
MD5:F9EC1D09FA0800597C4767C149604A7B
SHA256:29A9B60D94C569DB0CCFAE726D8FF38185815C957FA05D105913F36757F28847
3656ECI DCA 1.5.7.9296 [H500CKMNUJGK].exeC:\Users\admin\AppData\Local\Temp\is-SJJOK.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpexecutable
MD5:D447544C6131F197B619BC0019852EE1
SHA256:DF886EB50E15FFA297A9BBE2DC1B7804C121A0EC3E66A007CA65C0E6714CD0E8
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\AngleSharp.dllexecutable
MD5:F9EC1D09FA0800597C4767C149604A7B
SHA256:29A9B60D94C569DB0CCFAE726D8FF38185815C957FA05D105913F36757F28847
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\DCA.Cryptography.Blowfish.dllexecutable
MD5:9890716A59BD6E48A4F0D1B0507C12B3
SHA256:6160DBD410F578CD425A7D2517B00DF60097EEC6CD6DD7D5F9E43ADE59D203AD
3948ECI DCA 1.5.7.9296 [H500CKMNUJGK].exeC:\Users\admin\AppData\Local\Temp\is-5NM8N.tmp\ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpexecutable
MD5:D447544C6131F197B619BC0019852EE1
SHA256:DF886EB50E15FFA297A9BBE2DC1B7804C121A0EC3E66A007CA65C0E6714CD0E8
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\is-2J18S.tmpexecutable
MD5:9890716A59BD6E48A4F0D1B0507C12B3
SHA256:6160DBD410F578CD425A7D2517B00DF60097EEC6CD6DD7D5F9E43ADE59D203AD
3464ECI DCA 1.5.7.9296 [H500CKMNUJGK].tmpC:\Program Files\ECI DCA\CommandLine.dllexecutable
MD5:53FB22B2B1726EBDE42C5F2CC921055A
SHA256:C13F3009E6619BDD07C3BC7FD60DF0721144258C2DC0772B330ECEDCD098F266
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
9
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1336
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
binary
727 b
unknown
1336
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
binary
471 b
unknown
1336
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA98u5eOYdBR7R%2Fa5LSCbuo%3D
unknown
binary
727 b
unknown
1336
DCA.Edge.Console.exe
GET
304
23.32.238.176:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6f620e2de5fecb97
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1336
DCA.Edge.Console.exe
23.32.238.219:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1336
DCA.Edge.Console.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1336
DCA.Edge.Console.exe
18.194.186.127:443
updates.printfleetcdn.com
AMAZON-02
DE
unknown
1336
DCA.Edge.Console.exe
23.32.238.176:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.32.238.219
  • 23.32.238.176
  • 23.32.238.216
  • 23.32.238.233
  • 23.32.238.224
  • 23.32.238.168
  • 23.32.238.179
  • 23.32.238.232
  • 23.32.238.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
updates.printfleetcdn.com
  • 18.194.186.127
unknown
1710314718.5DZOMQ1RC4J12HUT2ZNI4RZH97NOYZH6T9JC4J2VENV67Z7W00.H500CKMNUJGK.ECI-DCA-1-5-7-9296.Microsoft-Windows-NT-6-1-7601-Service-Pack-1.ping.reg.pf-d.ca
unknown

Threats

No threats detected
No debug info