File name:

WinBooster.exe

Full analysis: https://app.any.run/tasks/5bbd9b9e-a017-4e93-a7e9-7adc18c50a81
Verdict: Malicious activity
Analysis date: September 22, 2024, 17:47:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0648D04040A9F5CE97930C4F8238C3FF

SHA1:

BD22E90AB9B1CD6905E8808785919F6710776B62

SHA256:

C9E0DF3D341FFE7F92071FD55A7852448DCF75068A28103C5D9DE968A0CA2364

SSDEEP:

98304:Erq3BdwRmos0qusxbz6pm+iTpwddON5ipf64tYDefz4NfZa7mUZwznp939ox47d1:yATTENJFohV/p3iwx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinBooster.tmp (PID: 1076)
      • WinBooster WPF.exe (PID: 1640)
    • Executable content was dropped or overwritten

      • WinBooster.exe (PID: 8)
      • WinBooster.exe (PID: 6484)
      • WinBooster.tmp (PID: 1432)
      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 3176)
      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 2224)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 7652)
      • WinBooster WPF.exe (PID: 1644)
    • Reads the Windows owner or organization settings

      • WinBooster.tmp (PID: 1432)
    • Process drops legitimate windows executable

      • WinBooster.tmp (PID: 1432)
      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 3176)
      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 2224)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 7652)
      • msiexec.exe (PID: 6608)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 2224)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 7652)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.8-win-x64 (1).exe (PID: 2224)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6608)
    • Application launched itself

      • RunAsTI.exe (PID: 7992)
  • INFO

    • Checks supported languages

      • WinBooster.exe (PID: 8)
      • WinBooster.tmp (PID: 1076)
      • WinBooster.exe (PID: 6484)
      • WinBooster.tmp (PID: 1432)
      • WinBooster WPF.exe (PID: 1640)
    • Reads the computer name

      • WinBooster.tmp (PID: 1076)
      • WinBooster.exe (PID: 6484)
      • WinBooster.tmp (PID: 1432)
      • WinBooster WPF.exe (PID: 1640)
    • Create files in a temporary directory

      • WinBooster.exe (PID: 8)
      • WinBooster.exe (PID: 6484)
      • WinBooster.tmp (PID: 1432)
    • Process checks computer location settings

      • WinBooster.tmp (PID: 1076)
    • Creates files in the program directory

      • WinBooster.tmp (PID: 1432)
    • Manual execution by a user

      • WinBooster WPF.exe (PID: 2536)
      • msedge.exe (PID: 6992)
      • WinBooster WPF.exe (PID: 1640)
      • WinBooster WPF.exe (PID: 1644)
      • WinBooster WPF.exe (PID: 7536)
    • Creates a software uninstall entry

      • WinBooster.tmp (PID: 1432)
    • Sends debugging messages

      • WinBooster WPF.exe (PID: 1640)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6992)
      • msiexec.exe (PID: 6608)
      • firefox.exe (PID: 2240)
      • msedge.exe (PID: 1804)
    • Application launched itself

      • msedge.exe (PID: 2932)
      • msedge.exe (PID: 6992)
      • msedge.exe (PID: 8152)
      • firefox.exe (PID: 7636)
      • firefox.exe (PID: 2240)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 141824
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Monolith Develpment
FileDescription: WinBooster Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: WinBooster
ProductVersion: 2.0.9.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
260
Monitored processes
115
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winbooster.exe winbooster.tmp no specs winbooster.exe winbooster.tmp winbooster wpf.exe no specs winbooster wpf.exe no specs winbooster wpf.exe sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs windowsdesktop-runtime-8.0.8-win-x64 (1).exe windowsdesktop-runtime-8.0.8-win-x64 (1).exe windowsdesktop-runtime-8.0.8-win-x64.exe msiexec.exe msiexec.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winbooster wpf.exe no specs winbooster wpf.exe runasti.exe no specs runasti.exe trustedworker.exe openwith.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
8"C:\Users\admin\AppData\Local\Temp\WinBooster.exe" C:\Users\admin\AppData\Local\Temp\WinBooster.exe
explorer.exe
User:
admin
Company:
Monolith Develpment
Integrity Level:
MEDIUM
Description:
WinBooster Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winbooster.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
360"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=5148 --field-trial-handle=2372,i,3667128945656273299,9719440739999932327,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
376C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5288 --field-trial-handle=2272,i,15697369427728664986,5021237745533604107,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1048C:\Windows\syswow64\MsiExec.exe -Embedding D5AA996C457B43E13D33AB74728256EDC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1076"C:\Users\admin\AppData\Local\Temp\is-022OP.tmp\WinBooster.tmp" /SL5="$7025E,7459087,827904,C:\Users\admin\AppData\Local\Temp\WinBooster.exe" C:\Users\admin\AppData\Local\Temp\is-022OP.tmp\WinBooster.tmpWinBooster.exe
User:
admin
Company:
Monolith Develpment
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-022op.tmp\winbooster.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1116"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4492 --field-trial-handle=2272,i,15697369427728664986,5021237745533604107,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4140 --field-trial-handle=2372,i,3667128945656273299,9719440739999932327,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5432 --field-trial-handle=2372,i,3667128945656273299,9719440739999932327,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1432"C:\Users\admin\AppData\Local\Temp\is-JKR08.tmp\WinBooster.tmp" /SL5="$1203D8,7459087,827904,C:\Users\admin\AppData\Local\Temp\WinBooster.exe" /SPAWNWND=$120346 /NOTIFYWND=$7025E /ALLUSERSC:\Users\admin\AppData\Local\Temp\is-JKR08.tmp\WinBooster.tmp
WinBooster.exe
User:
admin
Company:
Monolith Develpment
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jkr08.tmp\winbooster.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
23 580
Read events
22 605
Write events
931
Delete events
44

Modification events

(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.3.3
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\WinBooster
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\WinBooster\
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
WinBooster
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: No Icons
Value:
1
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:Inno Setup: Language
Value:
russian
(PID) Process:(1432) WinBooster.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{16277C01-31CE-4D2F-991B-300D842BE8CB}_is1
Operation:writeName:DisplayName
Value:
WinBooster, версия 2.0.9.3
Executable files
571
Suspicious files
776
Text files
259
Unknown types
4

Dropped files

PID
Process
Filename
Type
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-UCLM2.tmpexecutable
MD5:68ED89CBFD733924EFAA36300159DA2A
SHA256:C26B6DB3B1D5CB52023B89FF82F16B69FCF7D80EDCF263B5CB4180D266F270FD
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-T5TPN.tmpexecutable
MD5:F2CCA8ED864A3794C945DC508815D71F
SHA256:4ED51A1862AC7D066A11681857A133DE5EC5E24A3974054D4CF1CE7D539A7F9E
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-DKCGI.tmpexecutable
MD5:F29FEFC4FC7D10674B265BD1465815D2
SHA256:DD9370535A26F454EAE46F9B2CCA591D8C389E47418C34A8E83412285D77B61D
1432WinBooster.tmpC:\Users\admin\AppData\Local\Temp\is-O3MDK.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\CSScriptLib.dllexecutable
MD5:EB7E1C76E01AE84895828103CFBCF3F4
SHA256:20C2F44C664C7E0E7A0BB8ECC96A7643883920C5FFD4155EF910CFE9C4D16CAC
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-M683T.tmpexecutable
MD5:30EF817B2D5DE6CD65D24EA0B068CD57
SHA256:936E56EF4837DD69B3FB9B4D8BF5AD0568EE05540F02FD8CEAE031959435849E
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\BouncyCastle.Crypto.dllexecutable
MD5:3CF6BF0E0A27F3665EDD6362D137E4CC
SHA256:1985B85BB44BE6C6EAF35E02EF11E23A890E809B8EC2E53210A4AD5A85B26C70
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-I3B8K.tmpexecutable
MD5:EB7E1C76E01AE84895828103CFBCF3F4
SHA256:20C2F44C664C7E0E7A0BB8ECC96A7643883920C5FFD4155EF910CFE9C4D16CAC
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\unins000.exeexecutable
MD5:68ED89CBFD733924EFAA36300159DA2A
SHA256:C26B6DB3B1D5CB52023B89FF82F16B69FCF7D80EDCF263B5CB4180D266F270FD
1432WinBooster.tmpC:\Program Files (x86)\WinBooster\is-EN631.tmpexecutable
MD5:7B5B408B173F54AB53F7C62BDB277ACF
SHA256:0B11F580A96D5612CCCF33C25473D81E2D90ABB40539C2DAC085D050F2AFBB77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
94
TCP/UDP connections
157
DNS requests
204
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4652
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2824
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2340
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7660
svchost.exe
HEAD
200
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727463763&P2=404&P3=2&P4=bNBUYb0djFjarnrLE6Qoj4swdr0mEnBPxJE6oiZGldD62HS0ylNM62eSWd37D8ovk4XTBOBtGXWAUpS9uebPkA%3d%3d
unknown
whitelisted
2340
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7660
svchost.exe
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727463763&P2=404&P3=2&P4=bNBUYb0djFjarnrLE6Qoj4swdr0mEnBPxJE6oiZGldD62HS0ylNM62eSWd37D8ovk4XTBOBtGXWAUpS9uebPkA%3d%3d
unknown
whitelisted
7660
svchost.exe
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727463763&P2=404&P3=2&P4=bNBUYb0djFjarnrLE6Qoj4swdr0mEnBPxJE6oiZGldD62HS0ylNM62eSWd37D8ovk4XTBOBtGXWAUpS9uebPkA%3d%3d
unknown
whitelisted
7660
svchost.exe
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727463763&P2=404&P3=2&P4=bNBUYb0djFjarnrLE6Qoj4swdr0mEnBPxJE6oiZGldD62HS0ylNM62eSWd37D8ovk4XTBOBtGXWAUpS9uebPkA%3d%3d
unknown
whitelisted
7660
svchost.exe
HEAD
200
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c12dff9-696d-48d4-bbe8-7d8bdad98e65?P1=1727397620&P2=404&P3=2&P4=jxNUXUkMsl5KkOZXaz0mWga1sCf%2bL6BnmYDjlRmXLhFPMCpkIxYy5nK%2fAAy1PKIeP2qg6d%2f7bbBL4cARkYjTLA%3d%3d
unknown
whitelisted
7660
svchost.exe
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727463763&P2=404&P3=2&P4=bNBUYb0djFjarnrLE6Qoj4swdr0mEnBPxJE6oiZGldD62HS0ylNM62eSWd37D8ovk4XTBOBtGXWAUpS9uebPkA%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4652
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
3900
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
13.89.178.26:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4652
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4652
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2824
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.110
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
browser.pipe.aria.microsoft.com
  • 20.42.73.27
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
aka.ms
  • 2.22.34.124
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Process
Message
WinBooster WPF.exe
You must install .NET to run this application. App: C:\Program Files (x86)\WinBooster\WinBooster WPF.exe Architecture: x64 App host version: 8.0.5 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.5
TrustedWorker.exe
You must install or update .NET to run this application. App: C:\Program Files\WinBooster\TrustedWorker.exe Architecture: x64
TrustedWorker.exe
Framework: 'Microsoft.NETCore.App', version '6.0.0' (x64)
TrustedWorker.exe
.NET location: C:\Program Files\dotnet\
TrustedWorker.exe
The following frameworks were found:
TrustedWorker.exe
8.0.8 at [C:\Program Files\dotnet\shared\Microsoft.NETCore.App]
TrustedWorker.exe
Learn more: https://aka.ms/dotnet/app-launch-failed To install missing framework, download: https://aka.ms/dotnet-core-applaunch?framework=Microsoft.NETCore.App&framework_version=6.0.0&arch=x64&rid=win-x64&os=win10