File name:

Setup_WiFiPasswordDecryptor.exe

Full analysis: https://app.any.run/tasks/463d8b5e-1f91-4634-8730-27d4276ad565
Verdict: Malicious activity
Analysis date: May 18, 2025, 03:47:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

FC72ACA2A6A4633EB41A854D11C5156D

SHA1:

30A7C7BEE51D8A11FB8FA8620669DA81E026D370

SHA256:

D29D233A2A4C6B619CD98F85AB642A87D71BFABDC75E2FE9AB092D3100848D9B

SSDEEP:

98304:A3nKq3/TyZCBBWdEeUYNNJisHvym9S3nKq3/TyZCBBWdEeUYNNJisHvya99hYOaI:cI9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • ADVANCEDINSTALLER mutex has been found

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Process drops legitimate windows executable

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Reads the Windows owner or organization settings

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
      • msiexec.exe (PID: 6972)
    • Executable content was dropped or overwritten

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
    • There is functionality for taking screenshot (YARA)

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Detects AdvancedInstaller (YARA)

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Reads security settings of Internet Explorer

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
      • MSIEB52.tmp (PID: 5960)
    • Application launched itself

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6972)
    • Starts application with an unusual extension

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
  • INFO

    • The sample compiled with english language support

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • msiexec.exe (PID: 6972)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
    • Reads the computer name

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • msiexec.exe (PID: 6972)
      • msiexec.exe (PID: 6324)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
      • msiexec.exe (PID: 5776)
      • identity_helper.exe (PID: 8188)
      • MSIEB52.tmp (PID: 5960)
    • Checks supported languages

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • msiexec.exe (PID: 6972)
      • msiexec.exe (PID: 6324)
      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
      • msiexec.exe (PID: 5776)
      • identity_helper.exe (PID: 8188)
      • MSIEB52.tmp (PID: 5960)
    • Reads Environment values

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
      • msiexec.exe (PID: 6324)
      • msiexec.exe (PID: 5776)
      • identity_helper.exe (PID: 8188)
    • Creates files or folders in the user directory

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Create files in a temporary directory

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Process checks computer location settings

      • Setup_WiFiPasswordDecryptor.exe (PID: 6964)
    • Reads the machine GUID from the registry

      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6972)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6972)
    • Creates files in the program directory

      • Setup_WiFiPasswordDecryptor.exe (PID: 4024)
    • Application launched itself

      • msedge.exe (PID: 2268)
    • Manual execution by a user

      • msedge.exe (PID: 7256)
    • Reads the software policy settings

      • slui.exe (PID: 4272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:03:23 09:36:36+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1132032
InitializedDataSize: 648192
UninitializedDataSize: -
EntryPoint: 0xd2ba3
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.0.0
ProductVersionNumber: 8.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: SecurityXploded
FileDescription: This installer database contains the logic and data required to install WiFi Password Decryptor.
FileVersion: 8
InternalName: Setup_WiFiPasswordDecryptor
LegalCopyright: Copyright (C) 2017 SecurityXploded
OriginalFileName: Setup_WiFiPasswordDecryptor.exe
ProductName: WiFi Password Decryptor
ProductVersion: 8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
182
Monitored processes
49
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup_wifipassworddecryptor.exe msiexec.exe msiexec.exe no specs sppextcomobj.exe no specs slui.exe setup_wifipassworddecryptor.exe msiexec.exe no specs wifipassworddecryptor.exe no specs msieb52.tmp no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x31c,0x320,0x324,0x314,0x32c,0x7ffc89b45fd8,0x7ffc89b45fe4,0x7ffc89b45ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1272"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7000 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3508 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2148"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6980 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
2148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7164 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2268"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Program Files (x86)\SecurityXploded\WiFi Password Decryptor\Readme.htmlC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
MSIEB52.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2980"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5844 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3884"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7268 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4024"C:\Users\admin\AppData\Local\Temp\Setup_WiFiPasswordDecryptor.exe" /i "C:\Users\admin\AppData\Roaming\SecurityXploded\WiFi Password Decryptor 8.0\install\WiFiPasswordDecryptor.msi" CLIENTPROCESSID="6964" SECONDSEQUENCE="1" CHAINERUIPROCESSID="6964Chainer" ACTION="INSTALL" EXECUTEACTION="INSTALL" CLIENTUILEVEL="0" ADDLOCAL="MainFeature" ALLUSERS="1" PRIMARYFOLDER="APPDIR" ROOTDRIVE="C:\" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\Setup_WiFiPasswordDecryptor.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\" EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs " AI_SETUPEXEPATH_ORIGINAL="C:\Users\admin\AppData\Local\Temp\Setup_WiFiPasswordDecryptor.exe" TARGETDIR="C:\" APPDIR="C:\Program Files (x86)\SecurityXploded\WiFi Password Decryptor\" AI_INSTALL="1" SHORTCUTDIR="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiFi Password Decryptor"C:\Users\admin\AppData\Local\Temp\Setup_WiFiPasswordDecryptor.exe
Setup_WiFiPasswordDecryptor.exe
User:
admin
Company:
SecurityXploded
Integrity Level:
HIGH
Description:
This installer database contains the logic and data required to install WiFi Password Decryptor.
Exit code:
0
Version:
8.0
Modules
Images
c:\users\admin\appdata\local\temp\setup_wifipassworddecryptor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4152"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6600 --field-trial-handle=2304,i,15750414166571636107,12714801386189041756,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
7 909
Read events
7 762
Write events
139
Delete events
8

Modification events

(PID) Process:(6972) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
3C1B00005EC9E09BA7C7DB01
(PID) Process:(6972) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
98418E05876ECEC9E9D9A2677092F742F002F71603D4CF00EF37A8C32BE16528
(PID) Process:(6972) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10e523.rbs
Value:
31180711
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10e523.rbsLow
Value:
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C2DB32824CBB87F4EA5D4F4CB6400736
Operation:writeName:C1ADD6063328F4C4A918877FBC975B01
Value:
02:\Software\Microsoft\Windows\CurrentVersion\Uninstall\WiFi Password Decryptor 8.0\DisplayName
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0D84D5C6B1669D949A438683B8A585EC
Operation:writeName:C1ADD6063328F4C4A918877FBC975B01
Value:
C:\Program Files (x86)\SecurityXploded\WiFi Password Decryptor\WiFiPasswordDecryptor.exe
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\452506AF95A6D544380FBE14FB53E857
Operation:writeName:C1ADD6063328F4C4A918877FBC975B01
Value:
02:\Software\SecurityXploded\WiFi Password Decryptor\Version
(PID) Process:(6972) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0A954FD0F50EED4690C0A034A639FF1
Operation:writeName:C1ADD6063328F4C4A918877FBC975B01
Value:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiFi Password Decryptor\
Executable files
30
Suspicious files
176
Text files
80
Unknown types
0

Dropped files

PID
Process
Filename
Type
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\shiB383.tmpexecutable
MD5:CE85F5D941EBCA72DA2A55835B303EB9
SHA256:6CF60B8101CBB475F3803E18617172CC180AFA4BC0CA8CA261C2AB6ED1C93EA1
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Roaming\SecurityXploded\WiFi Password Decryptor 8.0\install\WiFiPasswordDecryptor.aiuiexecutable
MD5:E36D00404C519341BBAD8E25F8F8950E
SHA256:21BFB8A45EF2AB75D100688883AD96F32F29FA15F437A078E7FAFA71D64A5885
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\folderlogoiconimage
MD5:17780B507A253C687F744FD9B2627864
SHA256:451331950FF77FC77E7E58C8F1AC8A099268C75A872DFAE3B7B475F33F9A5E70
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\installer_background.jpgimage
MD5:5B34E845DC4D57F5CC4DAA0492980D19
SHA256:27B89E45BBC31A069FE577D504C3045A6035CDEA0DEE36F1240E0663F246B528
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\MSIBD29.tmpexecutable
MD5:CA367C9FD5FB936729B4B6DCD78B003A
SHA256:287610819C64C5C5D0DA75C8691046CFFAA4538DD5F4CCDD14997B804D34F705
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\sx_logo_icon.icoimage
MD5:87360088F68F5FF62AE038C9E6856C07
SHA256:6FC308D85B50C8F8903317E00924AAB7CB2C07CFA3F7E0C1A181E01E3162B8E3
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\waitlogoiconimage
MD5:5C95ADF9CBC1231E805DE8529778E1C4
SHA256:81873D1DB5399D8B42A371FD0BFCEB4FF9F4E21446E9B180245055CCBDCC1235
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\infoimage
MD5:FD535E63F539EACB3F11D03B52B39A80
SHA256:0086BC01150989F553A0A4AE0E14926C6E247CEDDA312E1F946AE35D575742AB
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\exclamicimage
MD5:93D722FA20A988A5C257A58BF155DC66
SHA256:F587867EED0BEC33EF150F3A8525BDE9B6746C705543874E56653AA80EA53225
6964Setup_WiFiPasswordDecryptor.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6964\printicoimage
MD5:BDC280616F9670F41C57C16BF08E8387
SHA256:6E5C2E9E923569F943E9F8A86EE5023034B3DB1F6434118A0D95F429F90FFBE7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
68
DNS requests
70
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
744
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
744
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2392
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/241074c3-f448-482a-8c90-855c388ea76a?P1=1747695943&P2=404&P3=2&P4=n3FlPIZ78tgZo%2f3enThBtgUtVz8GzWEVeFvyI9bIX7OkK2GRQqW8vPm7t%2bMckMJLoEUh%2fmrgCvRKzyWE1Xqajg%3d%3d
unknown
whitelisted
2392
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/241074c3-f448-482a-8c90-855c388ea76a?P1=1747695943&P2=404&P3=2&P4=n3FlPIZ78tgZo%2f3enThBtgUtVz8GzWEVeFvyI9bIX7OkK2GRQqW8vPm7t%2bMckMJLoEUh%2fmrgCvRKzyWE1Xqajg%3d%3d
unknown
whitelisted
2392
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/241074c3-f448-482a-8c90-855c388ea76a?P1=1747695943&P2=404&P3=2&P4=n3FlPIZ78tgZo%2f3enThBtgUtVz8GzWEVeFvyI9bIX7OkK2GRQqW8vPm7t%2bMckMJLoEUh%2fmrgCvRKzyWE1Xqajg%3d%3d
unknown
whitelisted
2392
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/241074c3-f448-482a-8c90-855c388ea76a?P1=1747695943&P2=404&P3=2&P4=n3FlPIZ78tgZo%2f3enThBtgUtVz8GzWEVeFvyI9bIX7OkK2GRQqW8vPm7t%2bMckMJLoEUh%2fmrgCvRKzyWE1Xqajg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.138
  • 20.190.160.22
  • 20.190.160.17
  • 20.190.160.132
  • 20.190.160.64
  • 40.126.32.76
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
business.bing.com
  • 13.107.6.158
  • 172.202.163.200
whitelisted

Threats

PID
Process
Class
Message
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
6712
msedge.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
No debug info