File name:

vlc-media-player-3.0.21-installer_pGz8g-1.exe

Full analysis: https://app.any.run/tasks/7360d8b8-f8ed-43f5-948e-047e7dc29606
Verdict: Malicious activity
Analysis date: October 17, 2024, 07:29:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-html
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

8C8BD1534C03E0ADDC67BE5D24D7ADE1

SHA1:

0496A84A6B9E989458FDD88CF49D352E027F7937

SHA256:

C3F3568273A2784BCD8E5CAA62D2299FB5CE3F03EC78F9581A034761D772BAC3

SSDEEP:

49152:D7HecD4dnbibBlK5fCSHPc6i2TOai/TRbIrKuCXlnWnTI+08n6/G3Uoa0SPVW1s3:v+cD4dnL5fvxg/TRbIrCX9kIQ6+3Uoyv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • installer.exe (PID: 6556)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Executable content was dropped or overwritten

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 6872)
      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
      • installer.exe (PID: 7156)
      • saBSI.exe (PID: 632)
      • installer.exe (PID: 6556)
      • vlc-media-player-3.0.21-installer.exe (PID: 6816)
      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 1396)
    • Process drops legitimate windows executable

      • installer.exe (PID: 6556)
    • Executes application which crashes

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 6872)
    • Executes as Windows Service

      • servicehost.exe (PID: 6844)
  • INFO

    • Checks supported languages

      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Create files in a temporary directory

      • vlc-media-player-3.0.21-installer_pGz8g-1.exe (PID: 4508)
    • Reads the computer name

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
    • Process checks computer location settings

      • vlc-media-player-3.0.21-installer_pGz8g-1.tmp (PID: 3844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.40.1.8969
ProductVersionNumber: 2.40.1.8969
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 2.40.1.8969
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 3.1.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
19
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start vlc-media-player-3.0.21-installer_pgz8g-1.exe vlc-media-player-3.0.21-installer_pgz8g-1.tmp no specs vlc-media-player-3.0.21-installer_pgz8g-1.exe vlc-media-player-3.0.21-installer_pgz8g-1.tmp sabsi.exe installer.exe installer.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe no specs explorer.exe no specs rundll32.exe no specs werfault.exe werfault.exe vlc-media-player-3.0.21-installer.exe no specs vlc-media-player-3.0.21-installer.exe servicehost.exe uihost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632"C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe" /affid 91082 PaidDistribution=true CountryCode=DEC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Version:
4,1,1,865
Modules
Images
c:\users\admin\appdata\local\temp\is-fjgon.tmp\component0_extract\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1396"C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" /SPAWNWND=$60230 /NOTIFYWND=$70298 C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softonic International SA
Exit code:
3221226525
Version:
2.40.1.8969
Modules
Images
c:\users\admin\appdata\local\temp\vlc-media-player-3.0.21-installer_pgz8g-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
3432C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6872 -s 2544C:\Windows\SysWOW64\WerFault.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3844"C:\Users\admin\AppData\Local\Temp\is-EMAP2.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmp" /SL5="$70298,837598,832512,C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" C:\Users\admin\AppData\Local\Temp\is-EMAP2.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmpvlc-media-player-3.0.21-installer_pGz8g-1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
3221226525
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-emap2.tmp\vlc-media-player-3.0.21-installer_pgz8g-1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4040"C:\Program Files\McAfee\WebAdvisor\UIHost.exe" C:\Program Files\McAfee\WebAdvisor\uihost.exeservicehost.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
MEDIUM
Description:
McAfee WebAdvisor(user level process)
Version:
4,1,1,965
Modules
Images
c:\program files\mcafee\webadvisor\uihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4508"C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe" C:\Users\admin\AppData\Local\Temp\vlc-media-player-3.0.21-installer_pGz8g-1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Softonic International SA
Exit code:
3221226525
Version:
2.40.1.8969
Modules
Images
c:\users\admin\appdata\local\temp\vlc-media-player-3.0.21-installer_pgz8g-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4548"C:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exe" C:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\vlc-media-player-3.0.21-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4836C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6872 -s 1608C:\Windows\SysWOW64\WerFault.exe
vlc-media-player-3.0.21-installer_pGz8g-1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6240 /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll"C:\Windows\SysWOW64\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6344regsvr32.exe /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll"C:\Windows\System32\regsvr32.exeinstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
33 762
Read events
33 505
Write events
244
Delete events
13

Modification events

(PID) Process:(6872) vlc-media-player-3.0.21-installer_pGz8g-1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E8070A000400110007001D0037008502010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(6872) vlc-media-player-3.0.21-installer_pGz8g-1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000008C4A005D6620DB01
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:UUID
Value:
{08FF75EE-9A1D-4769-AA8D-D103EA71C92F}
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallerFlags
Value:
1
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationStatus
Value:
PENDING
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallationID
Value:
UNDEFINED
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:CountryCode
Value:
DE
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:NEW_USER_STATE
Value:
EXPIRED
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ABTEST
Value:
SYSTEM,STR,TRUE
(PID) Process:(632) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor\Settings
Operation:writeName:NEW_USER_ANY_FLOW
Value:
SYSTEM,STR,TRUE
Executable files
24
Suspicious files
265
Text files
898
Unknown types
1

Dropped files

PID
Process
Filename
Type
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\is-R1FIM.tmp
MD5:
SHA256:
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\vlc-media-player-3.0.21-installer.exe
MD5:
SHA256:
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\Downloads\vlc-media-player-3.0.21-installer.exe
MD5:
SHA256:
7156installer.exeC:\Program Files\McAfee\Temp4138438693\browserplugin.cab
MD5:
SHA256:
4508vlc-media-player-3.0.21-installer_pGz8g-1.exeC:\Users\admin\AppData\Local\Temp\is-EMAP2.tmp\vlc-media-player-3.0.21-installer_pGz8g-1.tmpexecutable
MD5:DAC5CEAA20BF9031EC6831F6BCB8A44F
SHA256:94C77B4DF83451967C0A7E11AB54CC038D0A0AFB5EA55E45027C6D9D54CE787F
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\image.jpgimage
MD5:621CFAE2BFDD85A61D60603771983A45
SHA256:5ED5422C6696DEC778E171B352B7323C17805166A92E966AE3971D90AFED967A
7156installer.exeC:\Program Files\McAfee\Temp4138438693\browserhost.cabcompressed
MD5:14ABF3FFF7093C935DF671811E7F1E9A
SHA256:69632B49EDA20D98DB292D887D82C9A301A8E8C3CF021A246AE84160DA9903FB
7156installer.exeC:\Program Files\McAfee\Temp4138438693\balloon_safe_annotation.pngimage
MD5:2048DF489A12C4C9E2341BEF42883205
SHA256:DDA74B071B5869A22B327633D9641F1340EC5B913359BB389C34C44A6DB579A5
6872vlc-media-player-3.0.21-installer_pGz8g-1.tmpC:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\N.pngimage
MD5:1A01027365500D86730A737EB32CBF2A
SHA256:D79A97538B93179012A5EBEBDE873EDC18E30A0287953800F7AA7EA4F25724E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
58
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3432
WerFault.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3432
WerFault.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5896
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5700
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
92.123.104.11:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 92.123.104.11
  • 92.123.104.7
  • 92.123.104.67
  • 92.123.104.9
  • 92.123.104.5
  • 92.123.104.4
  • 92.123.104.6
  • 92.123.104.10
  • 92.123.104.8
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
d25qho5rs4tpl0.cloudfront.net
  • 18.245.78.68
  • 18.245.78.70
  • 18.245.78.128
  • 18.245.78.22
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.68
whitelisted
th.bing.com
  • 92.123.104.24
  • 92.123.104.18
  • 92.123.104.27
  • 92.123.104.21
  • 92.123.104.25
  • 92.123.104.19
  • 92.123.104.17
  • 92.123.104.20
  • 92.123.104.16
whitelisted
images.sftcdn.net
  • 151.101.65.91
  • 151.101.129.91
  • 151.101.1.91
  • 151.101.193.91
whitelisted

Threats

No threats detected
Process
Message
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-FJGON.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory