File name:

cold-turkey-4-3.exe

Full analysis: https://app.any.run/tasks/039a0d6a-1afc-42c6-9b3a-7a4e84dd5341
Verdict: Malicious activity
Analysis date: November 19, 2023, 12:05:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4E1FEEDEF4784AD3031A9BA22B3DE6C8

SHA1:

7404A10F0F165263ABAB779D25A8E5D1D0256663

SHA256:

C23C718E0B75E6990D9B08076B52418AABDC286766C62EF8E2B2C6DE02081EC6

SSDEEP:

98304:W+QqZ8fzB4oKfYlMmzoe93sY3XpTkfMrzonRADXey61Um7VGOY1ib91cbVmMmeC6:4t+MqEbjmV45nUi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cold-turkey-4-3.exe (PID: 3572)
      • cold-turkey-4-3.exe (PID: 3448)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • cold-turkey-4-3.tmp (PID: 3464)
      • Setup.exe (PID: 3988)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • cold-turkey-4-3.tmp (PID: 3464)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cold-turkey-4-3.tmp (PID: 3464)
    • Reads the Internet Settings

      • cold-turkey-4-3.tmp (PID: 3464)
      • Setup.exe (PID: 3988)
    • Process drops legitimate windows executable

      • cold-turkey-4-3.tmp (PID: 3464)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • Setup.exe (PID: 3988)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 3988)
    • Reads settings of System Certificates

      • Setup.exe (PID: 3988)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 3988)
    • Adds/modifies Windows certificates

      • NDP471-KB4033344-Web.exe (PID: 3908)
    • Executes as Windows Service

      • ServiceHub.Power.exe (PID: 1508)
  • INFO

    • Create files in a temporary directory

      • cold-turkey-4-3.exe (PID: 3448)
      • cold-turkey-4-3.exe (PID: 3572)
      • cold-turkey-4-3.tmp (PID: 3464)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • Setup.exe (PID: 3988)
      • SetupUtility.exe (PID: 4072)
    • Checks supported languages

      • cold-turkey-4-3.exe (PID: 3448)
      • cold-turkey-4-3.tmp (PID: 3156)
      • cold-turkey-4-3.exe (PID: 3572)
      • cold-turkey-4-3.tmp (PID: 3464)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • Setup.exe (PID: 3988)
      • SetupUtility.exe (PID: 4072)
      • wmpnscfg.exe (PID: 4040)
      • SetupUtility.exe (PID: 3028)
      • Cold Turkey Blocker.exe (PID: 3628)
      • Cold Turkey Blocker.exe (PID: 2116)
      • ServiceHub.Helper.exe (PID: 752)
      • ServiceHub.Power.exe (PID: 1508)
      • CTServiceInstaller.exe (PID: 2056)
      • Cold Turkey Blocker.exe (PID: 2300)
    • Reads the computer name

      • cold-turkey-4-3.tmp (PID: 3156)
      • cold-turkey-4-3.tmp (PID: 3464)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • Setup.exe (PID: 3988)
      • SetupUtility.exe (PID: 4072)
      • Cold Turkey Blocker.exe (PID: 2116)
      • SetupUtility.exe (PID: 3028)
      • Cold Turkey Blocker.exe (PID: 3628)
      • wmpnscfg.exe (PID: 4040)
      • CTServiceInstaller.exe (PID: 2056)
      • ServiceHub.Power.exe (PID: 1508)
      • ServiceHub.Helper.exe (PID: 752)
      • Cold Turkey Blocker.exe (PID: 2300)
    • Reads the machine GUID from the registry

      • cold-turkey-4-3.tmp (PID: 3464)
      • NDP471-KB4033344-Web.exe (PID: 3908)
      • Setup.exe (PID: 3988)
      • wmpnscfg.exe (PID: 4040)
      • Cold Turkey Blocker.exe (PID: 3628)
      • Cold Turkey Blocker.exe (PID: 2116)
      • SetupUtility.exe (PID: 4072)
      • CTServiceInstaller.exe (PID: 2056)
      • ServiceHub.Power.exe (PID: 1508)
      • ServiceHub.Helper.exe (PID: 752)
      • Cold Turkey Blocker.exe (PID: 2300)
    • Creates files in the program directory

      • cold-turkey-4-3.tmp (PID: 3464)
      • Cold Turkey Blocker.exe (PID: 3628)
      • ServiceHub.Power.exe (PID: 1508)
      • ServiceHub.Helper.exe (PID: 752)
    • Reads Environment values

      • Setup.exe (PID: 3988)
    • Reads CPU info

      • Setup.exe (PID: 3988)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 4040)
      • Cold Turkey Blocker.exe (PID: 3628)
      • Cold Turkey Blocker.exe (PID: 2116)
      • Cold Turkey Blocker.exe (PID: 2300)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 3988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:09:13 11:00:51+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 95232
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Cold Turkey Software, Inc.
FileDescription: Cold Turkey Blocker Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Cold Turkey Blocker
ProductVersion: 4.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
17
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cold-turkey-4-3.exe no specs cold-turkey-4-3.tmp no specs cold-turkey-4-3.exe cold-turkey-4-3.tmp no specs netsh.exe no specs netsh.exe no specs ndp471-kb4033344-web.exe no specs setup.exe setuputility.exe no specs wmpnscfg.exe no specs setuputility.exe no specs cold turkey blocker.exe cold turkey blocker.exe ctserviceinstaller.exe no specs servicehub.power.exe servicehub.helper.exe cold turkey blocker.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files\Cold Turkey\ServiceHub.Helper.exe"C:\Program Files\Cold Turkey\ServiceHub.Helper.exe
ServiceHub.Power.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ServiceHub.Helper
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\cold turkey\servicehub.helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1508"C:\Program Files\Cold Turkey\ServiceHub.Power.exe"C:\Program Files\Cold Turkey\ServiceHub.Power.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
ServiceHub.Power
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\cold turkey\servicehub.power.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2056"C:\Program Files\Cold Turkey\CTServiceInstaller.exe"C:\Program Files\Cold Turkey\CTServiceInstaller.execold-turkey-4-3.tmp
User:
admin
Company:
Cold Turkey Software Inc.
Integrity Level:
HIGH
Description:
CTServiceInstaller
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\cold turkey\ctserviceinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2116"C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe" C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe
explorer.exe
User:
admin
Company:
Cold Turkey Software Inc.
Integrity Level:
MEDIUM
Description:
Cold Turkey Blocker
Exit code:
0
Version:
4.3.0.0
Modules
Images
c:\program files\cold turkey\cold turkey blocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2300"C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe" C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe
explorer.exe
User:
admin
Company:
Cold Turkey Software Inc.
Integrity Level:
MEDIUM
Description:
Cold Turkey Blocker
Exit code:
0
Version:
4.3.0.0
Modules
Images
c:\program files\cold turkey\cold turkey blocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3028SetupUtility.exe /screbootC:\bee957f231a1b8949513f6b1f2b7c4\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.7.2558.0 built by: NET471REL1
Modules
Images
c:\bee957f231a1b8949513f6b1f2b7c4\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3156"C:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmp" /SL5="$60134,6728624,837632,C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" C:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmpcold-turkey-4-3.exe
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-510s3.tmp\cold-turkey-4-3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3448"C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exeexplorer.exe
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
MEDIUM
Description:
Cold Turkey Blocker Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\cold-turkey-4-3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3464"C:\Users\admin\AppData\Local\Temp\is-0IPPR.tmp\cold-turkey-4-3.tmp" /SL5="$70186,6728624,837632,C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\is-0IPPR.tmp\cold-turkey-4-3.tmpcold-turkey-4-3.exe
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-0ippr.tmp\cold-turkey-4-3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3572"C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe
cold-turkey-4-3.tmp
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
HIGH
Description:
Cold Turkey Blocker Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\cold-turkey-4-3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
9 697
Read events
9 580
Write events
109
Delete events
8

Modification events

(PID) Process:(3464) cold-turkey-4-3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3464) cold-turkey-4-3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3464) cold-turkey-4-3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3464) cold-turkey-4-3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3596) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3888) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) Setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4040) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{784E2847-F83C-4B00-AE03-5AF10C50E479}\{50830C6A-FC7F-4591-8A53-F202885CA60F}
Operation:delete keyName:(default)
Value:
(PID) Process:(4040) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{784E2847-F83C-4B00-AE03-5AF10C50E479}
Operation:delete keyName:(default)
Value:
(PID) Process:(4040) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2769D8E4-923F-48BB-9411-BF680144BCCE}
Operation:delete keyName:(default)
Value:
Executable files
95
Suspicious files
81
Text files
373
Unknown types
0

Dropped files

PID
Process
Filename
Type
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\is-UHP5R.tmpexecutable
MD5:0E086B159AD8DD140C08AC2915A6EFFE
SHA256:085BA841A7A4DF1DF4574DE1C292ED488BC2E80E269157CA0056BDFC70FB1CD0
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\is-912NL.tmpexecutable
MD5:10749CDC412FE224B1105231598C85EC
SHA256:06B916E9C702168ABBBF8FA197B812ACA5068DCE1EB3112307270AF0568C027B
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\CTHostInstaller.exeexecutable
MD5:BFE27AE92274F2861C135912ECB120D0
SHA256:2389CF414553F7E66DC83CC007C87F7C7D2C7328D83480EB0FFEC7F3A9F055AF
3448cold-turkey-4-3.exeC:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmpexecutable
MD5:BD1E68FBA4152B139E4E7B8718B86366
SHA256:D1A45B8D5F9C898356726DCBD0A4CA35BE1F31C979823C2BA601FCD492DD5267
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\unins000.exeexecutable
MD5:500B83216DD3683D1A8D850E370100C4
SHA256:AA5C169EE43F1D8111B458D6620A511C23DBF4B966B2B2309C56397CEFCE4EA0
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\is-1FA5Q.tmpbinary
MD5:06F8A880BDA481AF8FDE7B1E85276085
SHA256:DB65EF15747F119E6645381F3EF1E7F9C2F7F48B227D5B079C5EE10D64DE79C6
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\CTMsgHostEdge.exeexecutable
MD5:C7E99DB3117C14B9D3CEE1FBEF0E1661
SHA256:2D84A9129B5A18D25DA47821274407599F3211BD345C8F9FE6EE7C4BA3AE2EBF
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\is-HIE20.tmpbinary
MD5:0A8AF25D1F9D0A3D27C8DCE58C8E4B86
SHA256:6949974F9F8BC30A1EBA5747B854C2F8C9B9CA0D315251830DF3EB2044D9C53D
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\CTMsgHostEdge.jsonbinary
MD5:0A8AF25D1F9D0A3D27C8DCE58C8E4B86
SHA256:6949974F9F8BC30A1EBA5747B854C2F8C9B9CA0D315251830DF3EB2044D9C53D
3464cold-turkey-4-3.tmpC:\Program Files\Cold Turkey\CTMsgHostFirefox.jsonbinary
MD5:06F8A880BDA481AF8FDE7B1E85276085
SHA256:DB65EF15747F119E6645381F3EF1E7F9C2F7F48B227D5B079C5EE10D64DE79C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
12
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
868
svchost.exe
HEAD
302
23.32.186.57:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz
unknown
unknown
868
svchost.exe
GET
302
23.32.186.57:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz
unknown
unknown
3988
Setup.exe
GET
302
23.32.186.57:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz
unknown
unknown
3988
Setup.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
binary
1.05 Kb
unknown
3988
Setup.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
binary
519 b
unknown
3988
Setup.exe
GET
200
67.27.235.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?abbb1ee64cc68804
unknown
compressed
4.66 Kb
unknown
3988
Setup.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
binary
767 b
unknown
3988
Setup.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
binary
1.11 Kb
unknown
3988
Setup.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
binary
824 b
unknown
3988
Setup.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
binary
555 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3988
Setup.exe
67.27.235.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3988
Setup.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
868
svchost.exe
23.32.186.57:80
go.microsoft.com
AKAMAI-AS
BR
unknown
868
svchost.exe
68.232.34.200:443
download.visualstudio.microsoft.com
EDGECAST
US
whitelisted
3988
Setup.exe
88.221.125.143:80
www.microsoft.com
AKAMAI-AS
DE
unknown
3988
Setup.exe
23.32.186.57:80
go.microsoft.com
AKAMAI-AS
BR
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 67.27.235.126
  • 8.241.123.254
  • 67.27.158.126
  • 67.27.158.254
  • 67.27.235.254
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.83
  • 2.16.164.114
  • 2.16.164.99
  • 2.16.164.106
  • 2.16.164.122
  • 2.16.164.98
  • 2.16.164.32
  • 2.16.164.10
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted
www.microsoft.com
  • 88.221.125.143
whitelisted

Threats

No threats detected
Process
Message
Cold Turkey Blocker.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
Cold Turkey Blocker.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
Setup.exe
User cancelled installation.
ServiceHub.Power.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
ServiceHub.Helper.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
ServiceHub.Helper.exe
SQLite error (1): no such table: settings
Cold Turkey Blocker.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...