File name:

vlc-media-player-3.0.21-installer_pGz8g-1.exe

Full analysis: https://app.any.run/tasks/7360d8b8-f8ed-43f5-948e-047e7dc29606
Verdict: Malicious activity
Analysis date: October 17, 2024, 07:29:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-html
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

8C8BD1534C03E0ADDC67BE5D24D7ADE1

SHA1:

0496A84A6B9E989458FDD88CF49D352E027F7937

SHA256:

C3F3568273A2784BCD8E5CAA62D2299FB5CE3F03EC78F9581A034761D772BAC3

SSDEEP:

49152:D7HecD4dnbibBlK5fCSHPc6i2TOai/TRbIrKuCXlnWnTI+08n6/G3Uoa0SPVW1s3:v+cD4dnL5fvxg/TRbIrCX9kIQ6+3Uoyv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • installer.exe (PID: 6556)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Executable content was dropped or overwritten

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 6872)
      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
      • saBSI.exe (PID: 632)
      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 1396)
      • installer.exe (PID: 7156)
      • installer.exe (PID: 6556)
      • vlc-media-player-3.0.21-installer.exe (PID: 6816)
    • Executes application which crashes

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 6872)
    • Process drops legitimate windows executable

      • installer.exe (PID: 6556)
    • Executes as Windows Service

      • servicehost.exe (PID: 6844)
  • INFO

    • Reads the computer name

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Checks supported languages

      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Process checks computer location settings

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Create files in a temporary directory

      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.40.1.8969
ProductVersionNumber: 2.40.1.8969
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 2.40.1.8969
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 3.1.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
19
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start vlc-media-player-3.0.21-installer_pgz8g-1.exe vlc-media-player-3.0.21-installer_pgz8g-1.tmp no specs vlc-media-player-3.0.21-installer_pgz8g-1.exe vlc-media-player-3.0.21-installer_pgz8g-1.tmp sabsi.exe installer.exe installer.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe no specs explorer.exe no specs rundll32.exe no specs werfault.exe werfault.exe vlc-media-player-3.0.21-installer.exe no specs vlc-media-player-3.0.21-installer.exe servicehost.exe uihost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632"C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe" /affid 91082 PaidDistribution=true CountryCode=DEC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Version:
4,1,1,865
Modules
Images
c:\users\admin\appdata\local\temp\is-fjgon.tmp\component0_extract\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1396"C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" /SPAWNWND=$60230 /NOTIFYWND=$70298 C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softonic International SA
Exit code:
3221226525
Version:
2.40.1.8969
Modules
Images
c:\users\admin\appdata\local\temp\vlc-media-player-3.0.21-installer_pgz8g-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
3432C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6872 -s 2544C:\Windows\SysWOW64\WerFault.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3844"C:\Users\admin\AppData\Local\Temp\is-EMAP2.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmp" /SL5="$70298,837598,832512,C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" C:\Users\admin\AppData\Local\Temp\is-EMAP2.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmpvlc-media-player-3.0.21-installer_pGz8g-1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
3221226525
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-emap2.tmp\vlc-media-player-3.0.21-installer_pgz8g-1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4040"C:\Program Files\McAfee\WebAdvisor\UIHost.exe" C:\Program Files\McAfee\WebAdvisor\uihost.exeservicehost.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
MEDIUM
Description:
McAfee WebAdvisor(user level process)
Version:
4,1,1,965
Modules
Images
c:\program files\mcafee\webadvisor\uihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4508"C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Softonic International SA
Exit code:
3221226525
Version:
2.40.1.8969
Modules
Images
c:\users\admin\appdata\local\temp\vlc-media-player-3.0.21-installer_pgz8g-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4548"C:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exe" C:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\vlc-media-player-3.0.21-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4836C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6872 -s 1608C:\Windows\SysWOW64\WerFault.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6240 /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll"C:\Windows\SysWOW64\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6344regsvr32.exe /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll"C:\Windows\System32\regsvr32.exeinstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
33 762
Read events
33 505
Write events
244
Delete events
13

Modification events

(PID) Process:(6872) vlc-media-player-3.0.21-installer_pGz8g-1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E8070A000400110007001D0037008502010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(6872) vlc-media-player-3.0.21-installer_pGz8g-1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000008C4A005D6620DB01
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:UUID
Value:
{08FF75EE-9A1D-4769-AA8D-D103EA71C92F}
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallerFlags
Value:
1
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationStatus
Value:
PENDING
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationID
Value:
UNDEFINED
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:CountryCode
Value:
DE
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:NEW_USER_STATE
Value:
EXPIRED
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ABTEST
Value:
SYSTEM,STR,TRUE
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ANY_FLOW
Value:
SYSTEM,STR,TRUE
Executable files
24
Suspicious files
265
Text files
898
Unknown types
1

Dropped files

PID
Process
Filename
Type
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\is-R1FIM.tmp
MD5:
SHA256:
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\vlc-media-player-3.0.21-installer.exe
MD5:
SHA256:
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exe
MD5:
SHA256:
7156installer.exeC:\Program Files\McAfee\Temp4138438693\browserplugin.cab
MD5:
SHA256:
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\image.jpgimage
MD5:621CFAE2BFDD85A61D60603771983A45
SHA256:5ED5422C6696DEC778E171B352B7323C17805166A92E966AE3971D90AFED967A
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\Y.pngimage
MD5:C199687E52F7393C941A143B45D78207
SHA256:0EB767424750B6F8C22AE5EBB105C5C37B3A047EED986FFA6DEBA53EFDC2142E
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\is-SCTNE.tmpcompressed
MD5:F68008B70822BD28C82D13A289DEB418
SHA256:CC6F4FAF4E8A9F4D2269D1D69A69EA326F789620FB98078CC98597F3CB998589
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\is-OIIV6.tmpimage
MD5:621CFAE2BFDD85A61D60603771983A45
SHA256:5ED5422C6696DEC778E171B352B7323C17805166A92E966AE3971D90AFED967A
1396vlc-media-player-3.0.21-installer_pGz8g-1.exeC:\Users\admin\AppData\Local\Temp\is-HQ3KT.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmpexecutable
MD5:DAC5CEAA20BF9031EC6831F6BCB8A44F
SHA256:94C77B4DF83451967C0A7E11AB54CC038D0A0AFB5EA55E45027C6D9D54CE787F
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\100.pngimage
MD5:5FD73821F3F097D177009D88DFD33605
SHA256:A6ECCE54116936CA27D4BE9797E32BF2F3CFC7E41519A23032992970FBD9D3BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
58
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5896
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3432
WerFault.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3432
WerFault.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5700
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
92.123.104.11:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 92.123.104.11
  • 92.123.104.7
  • 92.123.104.67
  • 92.123.104.9
  • 92.123.104.5
  • 92.123.104.4
  • 92.123.104.6
  • 92.123.104.10
  • 92.123.104.8
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
d25qho5rs4tpl0.cloudfront.net
  • 18.245.78.68
  • 18.245.78.70
  • 18.245.78.128
  • 18.245.78.22
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.68
whitelisted
th.bing.com
  • 92.123.104.24
  • 92.123.104.18
  • 92.123.104.27
  • 92.123.104.21
  • 92.123.104.25
  • 92.123.104.19
  • 92.123.104.17
  • 92.123.104.20
  • 92.123.104.16
whitelisted
images.sftcdn.net
  • 151.101.65.91
  • 151.101.129.91
  • 151.101.1.91
  • 151.101.193.91
whitelisted

Threats

No threats detected
Process
Message
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory