File name:

sd-setup.exe

Full analysis: https://app.any.run/tasks/c0e51b01-9d0a-4fb5-aed5-3ea936a3957f
Verdict: Malicious activity
Analysis date: January 16, 2024, 17:22:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A2452EAB403BC77413B63B19C8D2611F

SHA1:

38684AF52CC8444AF7FC25F42B6FF080B3B9FDE5

SHA256:

D5712B53B1E3064B4E282CFE262253C80D1AC27ABC69188E2C0A73830EB3D508

SSDEEP:

98304:U1x7jQSaJcpzGEZ44ccM86MXDUSCSkX14KqTe4zmhbRsV7ZTmATexCLDJg0wD4eq:g0t+df

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sd-setup.exe (PID: 2044)
      • sd-setup.exe (PID: 480)
      • sd-setup.tmp (PID: 1040)
      • SDInit.exe (PID: 696)
      • smart-defrag-setup.exe (PID: 2156)
      • smart-defrag-setup.tmp (PID: 3556)
      • smart-defrag-setup.exe (PID: 2308)
    • Actions looks like stealing of personal data

      • TaskHelper.exe (PID: 1780)
      • sd-setup.tmp (PID: 1040)
      • SmartDefrag.exe (PID: 2296)
    • Creates a writable file in the system directory

      • sd-setup.tmp (PID: 1040)
      • SDInit.exe (PID: 696)
    • Steals credentials from Web Browsers

      • sd-setup.tmp (PID: 1040)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • sd-setup.exe (PID: 2044)
      • sd-setup.exe (PID: 480)
      • sd-setup.tmp (PID: 1040)
      • SDInit.exe (PID: 696)
      • smart-defrag-setup.exe (PID: 2156)
      • smart-defrag-setup.exe (PID: 2308)
      • smart-defrag-setup.tmp (PID: 3556)
    • Drops a system driver (possible attempt to evade defenses)

      • sd-setup.tmp (PID: 1040)
    • Reads the Internet Settings

      • sd-setup.tmp (PID: 1040)
      • SmartDefrag.exe (PID: 2296)
      • SDInit.exe (PID: 1636)
      • smart-defrag-setup.tmp (PID: 3556)
    • Searches for installed software

      • sd-setup.tmp (PID: 1040)
    • Creates files in the driver directory

      • sd-setup.tmp (PID: 1040)
    • Process drops legitimate windows executable

      • sd-setup.tmp (PID: 1040)
      • smart-defrag-setup.tmp (PID: 3556)
    • Reads the Windows owner or organization settings

      • sd-setup.tmp (PID: 1040)
      • smart-defrag-setup.tmp (PID: 3556)
  • INFO

    • Checks supported languages

      • sd-setup.tmp (PID: 2036)
      • sd-setup.exe (PID: 2044)
      • sd-setup.exe (PID: 480)
      • sd-setup.tmp (PID: 1040)
      • SDInit.exe (PID: 696)
      • TaskHelper.exe (PID: 1780)
      • wmpnscfg.exe (PID: 1740)
      • SDInit.exe (PID: 1636)
      • SmartDefrag.exe (PID: 2296)
      • smart-defrag-setup.exe (PID: 2156)
      • smart-defrag-setup.tmp (PID: 4036)
      • smart-defrag-setup.exe (PID: 2308)
      • smart-defrag-setup.tmp (PID: 3556)
      • Setup.exe (PID: 1592)
    • Create files in a temporary directory

      • sd-setup.exe (PID: 2044)
      • sd-setup.exe (PID: 480)
      • sd-setup.tmp (PID: 1040)
      • smart-defrag-setup.exe (PID: 2156)
      • smart-defrag-setup.exe (PID: 2308)
      • smart-defrag-setup.tmp (PID: 3556)
    • Reads the computer name

      • sd-setup.tmp (PID: 2036)
      • TaskHelper.exe (PID: 1780)
      • sd-setup.tmp (PID: 1040)
      • wmpnscfg.exe (PID: 1740)
      • SmartDefrag.exe (PID: 2296)
      • SDInit.exe (PID: 1636)
      • smart-defrag-setup.tmp (PID: 4036)
      • smart-defrag-setup.tmp (PID: 3556)
    • Creates files or folders in the user directory

      • TaskHelper.exe (PID: 1780)
      • SDInit.exe (PID: 1636)
    • Creates files in the program directory

      • sd-setup.tmp (PID: 1040)
      • SmartDefrag.exe (PID: 2296)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1740)
      • msedge.exe (PID: 2960)
    • Reads the machine GUID from the registry

      • SmartDefrag.exe (PID: 2296)
    • Checks proxy server information

      • SmartDefrag.exe (PID: 2296)
    • Application launched itself

      • msedge.exe (PID: 2580)
      • msedge.exe (PID: 2960)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2960)
      • msedge.exe (PID: 884)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 884)
      • msedge.exe (PID: 2960)
    • The process uses the downloaded file

      • msedge.exe (PID: 3948)
      • msedge.exe (PID: 3432)
      • msedge.exe (PID: 2960)
      • msedge.exe (PID: 3448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:03:17 11:22:54+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 71680
UninitializedDataSize: -
EntryPoint: 0x16478
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.3.0.1126
ProductVersionNumber: 2.3.0.1126
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: IObit
FileDescription: Smart Defrag v2
FileVersion: 2.3.0.1126
LegalCopyright: Copyright © 2005-2012
ProductName: Smart Defrag 2
ProductVersion: 2.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
60
Malicious processes
9
Suspicious processes
2

Behavior graph

Click at the process to see the details
start sd-setup.exe sd-setup.tmp no specs sd-setup.exe sd-setup.tmp taskhelper.exe sdinit.exe wmpnscfg.exe no specs sdinit.exe no specs smartdefrag.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs smart-defrag-setup.exe smart-defrag-setup.tmp no specs smart-defrag-setup.exe smart-defrag-setup.tmp setup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
480"C:\Users\admin\Desktop\sd-setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$401AA C:\Users\admin\Desktop\sd-setup.exe
sd-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Smart Defrag v2
Exit code:
0
Version:
2.3.0.1126
Modules
Images
c:\users\admin\desktop\sd-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
696"C:\Program Files\IObit\Smart Defrag 2\SDInit.exe" /AFTERINSTALLC:\Program Files\IObit\Smart Defrag 2\SDInit.exe
sd-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Smart Defrag Initialization Program
Exit code:
0
Version:
1.0.0.13
Modules
Images
c:\program files\iobit\smart defrag 2\sdinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\iobit\smart defrag 2\rtl120.bpl
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
884"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1548 --field-trial-handle=1292,i,15793381274557551927,13104759843797206417,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6d66f598,0x6d66f5a8,0x6d66f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1040"C:\Users\admin\AppData\Local\Temp\is-40HPU.tmp\sd-setup.tmp" /SL5="$301BA,4301536,158720,C:\Users\admin\Desktop\sd-setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$401AA C:\Users\admin\AppData\Local\Temp\is-40HPU.tmp\sd-setup.tmp
sd-setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-40hpu.tmp\sd-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1264"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4728 --field-trial-handle=1292,i,15793381274557551927,13104759843797206417,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1484"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1636 --field-trial-handle=1292,i,15793381274557551927,13104759843797206417,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1592"C:\Users\admin\AppData\Local\Temp\is-3VU0L.tmp\Setup.exe" "C:\Users\admin\Downloads\smart-defrag-setup.exe"C:\Users\admin\AppData\Local\Temp\is-3VU0L.tmp\Setup.exe
smart-defrag-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Smart Defrag Installer
Exit code:
0
Version:
9.2.0.40
Modules
Images
c:\users\admin\appdata\local\temp\is-3vu0l.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1636"C:\Program Files\IObit\Smart Defrag 2\SDInit.exe" /SHOWUIWINDOWC:\Program Files\IObit\Smart Defrag 2\SDInit.exesd-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Smart Defrag Initialization Program
Exit code:
0
Version:
1.0.0.13
Modules
Images
c:\program files\iobit\smart defrag 2\sdinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\iobit\smart defrag 2\rtl120.bpl
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1740"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
16 161
Read events
15 973
Write events
187
Delete events
1

Modification events

(PID) Process:(1040) sd-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1040) sd-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1040) sd-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1040) sd-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1636) SDInit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1636) SDInit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1636) SDInit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1636) SDInit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2296) SmartDefrag.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:BootExecute
Value:
autocheck autochk *
(PID) Process:(2296) SmartDefrag.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
92
Suspicious files
273
Text files
454
Unknown types
0

Dropped files

PID
Process
Filename
Type
480sd-setup.exeC:\Users\admin\AppData\Local\Temp\is-40HPU.tmp\sd-setup.tmpexecutable
MD5:6909A2F99AE429EFC7F5C4A541511648
SHA256:9668CB304FEF372321AC9C7DB1A0145A8868044F4B2B7C899CC047673B26AEAA
1040sd-setup.tmpC:\Users\admin\AppData\Local\Temp\is-71LNL.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2044sd-setup.exeC:\Users\admin\AppData\Local\Temp\is-E1OB1.tmp\sd-setup.tmpexecutable
MD5:6909A2F99AE429EFC7F5C4A541511648
SHA256:9668CB304FEF372321AC9C7DB1A0145A8868044F4B2B7C899CC047673B26AEAA
1040sd-setup.tmpC:\Users\admin\AppData\Local\Temp\is-71LNL.tmp\Check.dllexecutable
MD5:1382FEADA7938C83C2C736774D919190
SHA256:70F35DA23FD1CF1626E300CE3300104B0B36677E947152C2FB09892F0989CDE3
1040sd-setup.tmpC:\Users\admin\AppData\Local\Temp\is-71LNL.tmp\Inno_English.lngtext
MD5:6B5B2ADF93C30438B4085966C3D060C5
SHA256:5D804AF00F37F7C715988559071E1BC8DE7A7E5A2EF96414B42AB428D9404681
1040sd-setup.tmpC:\Program Files\IObit\Smart Defrag 2\unins000.exeexecutable
MD5:6909A2F99AE429EFC7F5C4A541511648
SHA256:9668CB304FEF372321AC9C7DB1A0145A8868044F4B2B7C899CC047673B26AEAA
1040sd-setup.tmpC:\Users\admin\AppData\Local\Temp\is-71LNL.tmp\RdZone.dllexecutable
MD5:D13973C5DF570E45DE6D68C55E127B7E
SHA256:D0E31B51F6186C072202BE2F0A4B93F80239FB0ED15219F195F4597D2B3E7F91
1040sd-setup.tmpC:\Users\admin\AppData\Local\Temp\is-71LNL.tmp\SDDriverMgr.dllexecutable
MD5:460B73B0A0CF73974C037C5D860B1876
SHA256:5CF63726E28909DB2A70BC4237224703B56969F905A16703FDF8D561A7BC0910
1040sd-setup.tmpC:\Program Files\IObit\Smart Defrag 2\is-B2BDL.tmpexecutable
MD5:5435047567B804414AFE86C5573BF59E
SHA256:660902ADF24918FEECCF227CB9C811DD613598710712D347E3202965DA718BF9
1040sd-setup.tmpC:\Program Files\IObit\Smart Defrag 2\vcl120.bplbinary
MD5:773EBD87010A6F644869A59D98792C9C
SHA256:C9581C6A50061ED588678F29591B2515FEA81A70A7E523751106BBADBFE11842
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
60
TCP/UDP connections
206
DNS requests
246
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2296
SmartDefrag.exe
GET
404
152.199.20.140:80
http://update.iobit.com/infofiles/smartdefrag/isd2update.upt
unknown
xml
433 b
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/js/lang/en.js
unknown
html
12.2 Kb
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/js/isrthree.js
unknown
text
4.06 Kb
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/js/modernizr.min.js
unknown
html
7.15 Kb
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/js/review-3d-carousel.min.js
unknown
text
8.87 Kb
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/images/2024ny/ny_nav_icon_normal_new_en.png
unknown
image
3.12 Kb
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/images/good.svg
unknown
image
1.26 Kb
unknown
2296
SmartDefrag.exe
POST
200
152.199.20.140:80
http://download.iobit.com/news/version-check.ini
unknown
text
753 b
unknown
2296
SmartDefrag.exe
POST
200
152.199.20.140:80
http://download.iobit.com/news/sd/v2/sd2-update.dat
unknown
text
145 b
unknown
884
msedge.exe
GET
200
52.45.129.150:80
http://www.iobit.com/tpl/styles/global.css?t=1705029027361
unknown
text
276 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2296
SmartDefrag.exe
152.199.20.140:80
update.iobit.com
EDGECAST
US
unknown
884
msedge.exe
52.45.129.150:80
www.iobit.com
AMAZON-AES
US
unknown
2960
msedge.exe
239.255.255.250:1900
whitelisted
884
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
884
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
884
msedge.exe
152.199.20.140:443
update.iobit.com
EDGECAST
US
unknown
884
msedge.exe
172.217.16.202:443
fonts.googleapis.com
GOOGLE
US
whitelisted
884
msedge.exe
142.250.74.195:443
fonts.gstatic.com
GOOGLE
US
whitelisted
884
msedge.exe
104.18.40.68:443
kit.fontawesome.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
update.iobit.com
  • 152.199.20.140
whitelisted
download.iobit.com
  • 152.199.20.140
whitelisted
www.iobit.com
  • 52.45.129.150
  • 54.204.75.253
  • 52.86.1.164
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
codes.iobit.com
  • 152.199.20.140
whitelisted
fonts.googleapis.com
  • 172.217.16.202
whitelisted
fonts.gstatic.com
  • 142.250.74.195
whitelisted
kit.fontawesome.com
  • 104.18.40.68
  • 172.64.147.188
whitelisted
ka-f.fontawesome.com
  • 172.64.165.7
  • 172.64.164.7
whitelisted

Threats

No threats detected
Process
Message
smart-defrag-setup.tmp
ExtractInstaller=0
smart-defrag-setup.tmp
sParam="C:\Users\admin\Downloads\smart-defrag-setup.exe"
smart-defrag-setup.tmp
ExtractInstaller=C:\Users\admin\AppData\Local\Temp\is-3VU0L.tmp\Setup.exe
smart-defrag-setup.tmp
result= true
Setup.exe
Self.FCfgPath : C:\Users\admin\AppData\Roaming\IObit\Smart Defrag\Config.ini