URL:

https://yepdownload.com/regshot

Full analysis: https://app.any.run/tasks/72b46e18-c986-4e56-b123-eca11e8c66bd
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 01, 2021, 00:56:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MD5:

221C89FDF1A4AC102C06091F0B46BC5C

SHA1:

20E1A6938F6D88E2CFD91009CE7FC8554ECAB3AC

SHA256:

D777CCD8DFA3295DF3ECFCFE4C5A7D20F8DF9E99C18075DB833A1E0BD6B48F46

SSDEEP:

3:N8/KKKU:2CKKU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2628)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3060)
      • AntiMalware_Setup.exe (PID: 588)
      • AntiMalware_Setup.exe (PID: 2744)
      • AntiMalware.exe (PID: 3252)
    • Actions looks like stealing of personal data

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware.exe (PID: 3252)
    • Loads dropped or rewritten executable

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware.exe (PID: 3252)
      • regsvr32.exe (PID: 2060)
    • Changes settings of System certificates

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • AntiMalware.exe (PID: 3252)
    • Drops executable file immediately after starts

      • AntiMalware_Setup.exe (PID: 588)
      • AntiMalware_Setup.exe (PID: 2744)
    • Registers / Runs the DLL via REGSVR32.EXE

      • AntiMalware_Setup.tmp (PID: 2608)
    • Uses Task Scheduler to run other applications

      • AntiMalware_Setup.tmp (PID: 2608)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2268)
    • Steals credentials from Web Browsers

      • AntiMalware.exe (PID: 3252)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2820)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware_Setup.exe (PID: 2744)
      • AntiMalware_Setup.exe (PID: 588)
      • AntiMalware_Setup.tmp (PID: 2608)
    • Application launched itself

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2628)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3060)
    • Drops a file that was compiled in debug mode

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware_Setup.tmp (PID: 2608)
    • Reads internet explorer settings

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware.exe (PID: 3252)
    • Reads Environment values

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware.exe (PID: 3252)
    • Cleans NTFS data-stream (Zone Identifier)

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2628)
    • Adds / modifies Windows certificates

      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • AntiMalware.exe (PID: 3252)
    • Reads Windows owner or organization settings

      • AntiMalware_Setup.tmp (PID: 2608)
    • Drops a file with a compile date too recent

      • chrome.exe (PID: 2820)
      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates a directory in Program Files

      • AntiMalware_Setup.tmp (PID: 2608)
    • Drops a file with too old compile date

      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates files in the Windows directory

      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates files in the driver directory

      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2060)
    • Starts Internet Explorer

      • AntiMalware.exe (PID: 3252)
    • Reads CPU info

      • AntiMalware.exe (PID: 3252)
    • Creates or modifies windows services

      • AntiMalware.exe (PID: 3252)
    • Reads the Windows organization settings

      • AntiMalware_Setup.tmp (PID: 2608)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2820)
      • iexplore.exe (PID: 3692)
    • Reads the hosts file

      • chrome.exe (PID: 1388)
      • chrome.exe (PID: 2820)
    • Reads settings of System Certificates

      • chrome.exe (PID: 2820)
      • chrome.exe (PID: 1388)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 2208)
      • regshot-1-9-0-en-win_0654906155.exe (PID: 3056)
      • AntiMalware.exe (PID: 3252)
      • iexplore.exe (PID: 2368)
    • Manual execution by user

      • regshot-1-9-0-en-win_0654906155.exe (PID: 3060)
    • Application was dropped or rewritten from another process

      • AntiMalware_Setup.tmp (PID: 1840)
      • AntiMalware_Setup.tmp (PID: 2608)
    • Loads dropped or rewritten executable

      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates a software uninstall entry

      • AntiMalware_Setup.tmp (PID: 2608)
    • Creates files in the program directory

      • AntiMalware_Setup.tmp (PID: 2608)
    • Changes internet zones settings

      • iexplore.exe (PID: 3692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
97
Monitored processes
47
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs regshot-1-9-0-en-win_0654906155.exe no specs regshot-1-9-0-en-win_0654906155.exe chrome.exe no specs regshot-1-9-0-en-win_0654906155.exe no specs regshot-1-9-0-en-win_0654906155.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs antimalware_setup.exe antimalware_setup.tmp no specs antimalware_setup.exe antimalware_setup.tmp regsvr32.exe no specs schtasks.exe no specs antimalware.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
252"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3519047299532960747 --renderer-client-id=27 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1316 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
588"C:\Users\admin\Downloads\AntiMalware_Setup.exe" C:\Users\admin\Downloads\AntiMalware_Setup.exe
chrome.exe
User:
admin
Company:
Zemana Ltd.
Integrity Level:
MEDIUM
Description:
Advanced Malware Protection
Exit code:
0
Version:
3.2.27
Modules
Images
c:\users\admin\downloads\antimalware_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
700"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3149332025001608412 --renderer-client-id=26 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4388 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
788"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14778734108210829182 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2176 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
892"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7135286173662312111 --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3412 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
968"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2828 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1264"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=11074261314549696466 --mojo-platform-channel-handle=4268 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1388"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=2171087770998649561 --mojo-platform-channel-handle=1452 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1456"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6123581305561589153 --renderer-client-id=32 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4352 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1532"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,12327114893495186691,16967171145161084627,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16600822034490871395 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3604 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
4 484
Read events
4 080
Write events
400
Delete events
4

Modification events

(PID) Process:(968) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2820-13253936177080125
Value:
259
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2820) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(2820) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
30
Suspicious files
151
Text files
378
Unknown types
17

Dropped files

PID
Process
Filename
Type
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FEE7331-B04.pma
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6fabe89e-7bfe-403c-8d59-8d3b1c838ae8.tmp
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF1545dc.TMP
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF1544a4.TMPtext
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF1544b3.TMPtext
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF1546a7.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
116
DNS requests
69
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2208
regshot-1-9-0-en-win_0654906155.exe
POST
200
13.224.195.32:80
http://df2gms67ann7.cloudfront.net/
US
malicious
2208
regshot-1-9-0-en-win_0654906155.exe
POST
200
13.224.195.32:80
http://df2gms67ann7.cloudfront.net/
US
malicious
3056
regshot-1-9-0-en-win_0654906155.exe
POST
200
13.224.195.32:80
http://df2gms67ann7.cloudfront.net/
US
malicious
2208
regshot-1-9-0-en-win_0654906155.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQC%2F8UqksxhNuVrE%2FyJIkN74
US
der
472 b
whitelisted
2208
regshot-1-9-0-en-win_0654906155.exe
POST
200
143.204.101.128:80
http://d25o8a75dj1x6r.cloudfront.net/
US
text
920 b
whitelisted
2208
regshot-1-9-0-en-win_0654906155.exe
POST
200
13.224.195.32:80
http://df2gms67ann7.cloudfront.net/
US
malicious
2208
regshot-1-9-0-en-win_0654906155.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
727 b
whitelisted
2368
iexplore.exe
GET
200
192.124.249.24:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
US
der
1.66 Kb
whitelisted
2368
iexplore.exe
GET
200
192.124.249.24:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
US
der
1.66 Kb
whitelisted
2368
iexplore.exe
GET
200
192.124.249.24:80
http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCEuKAq1blmBJ
US
der
1.74 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1388
chrome.exe
67.207.92.67:443
yepdownload.com
Digital Ocean, Inc.
US
unknown
1388
chrome.exe
91.199.212.52:80
crt.sectigo.com
Comodo CA Ltd
GB
suspicious
1388
chrome.exe
172.217.16.195:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1388
chrome.exe
2.16.106.171:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
1388
chrome.exe
172.217.23.130:443
pagead2.googlesyndication.com
Google Inc.
US
whitelisted
1388
chrome.exe
195.181.175.52:443
cdn.sendpulse.com
Datacamp Limited
DE
suspicious
1388
chrome.exe
87.250.250.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
1388
chrome.exe
216.58.207.40:443
www.googletagmanager.com
Google Inc.
US
whitelisted
1388
chrome.exe
172.217.18.110:443
clients1.google.com
Google Inc.
US
whitelisted
1388
chrome.exe
172.217.23.142:443
www.google-analytics.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
yepdownload.com
  • 67.207.92.67
whitelisted
accounts.google.com
  • 142.250.103.84
shared
crt.sectigo.com
  • 91.199.212.52
whitelisted
ssl.gstatic.com
  • 172.217.16.195
whitelisted
www.download.windowsupdate.com
  • 2.16.106.171
  • 2.16.106.186
whitelisted
pagead2.googlesyndication.com
  • 172.217.23.130
whitelisted
cdn.sendpulse.com
  • 195.181.175.52
  • 195.181.175.48
  • 195.181.175.55
  • 195.181.175.46
whitelisted
www.googletagmanager.com
  • 216.58.207.40
whitelisted
mc.yandex.ru
  • 87.250.250.119
  • 93.158.134.119
  • 87.250.251.119
  • 77.88.21.119
whitelisted
clients1.google.com
  • 172.217.18.110
whitelisted

Threats

PID
Process
Class
Message
2208
regshot-1-9-0-en-win_0654906155.exe
A Network Trojan was detected
ADWARE [PTsecurity] InstallCore
3056
regshot-1-9-0-en-win_0654906155.exe
A Network Trojan was detected
ADWARE [PTsecurity] InstallCore
Process
Message
AntiMalware.exe
AMLogger: 2021-01-01 00:59:18,835 [INFO ] [1] [Zemana.AntiMalware.UI.Program.Main] Line: 55 - ################################# SYSTEM INITIALIZED #################################
AntiMalware.exe
AMLogger: 2021-01-01 00:59:18,960 [INFO ] [1] [Zemana.AntiMalware.UI.Program.Main] Line: 55 - v3.2.27 is launching...
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,007 [INFO ] [1] [Zemana.AntiMalware.UI.Services.CommandHandler.CreateOrShowRunningUIInstance] Line: 245 - ================= Running command C:\Program Files\Zemana\AntiMalware\AntiMalware.exe /SL5=$30204,12312908,121344,C:\Users\admin\Downloads\AntiMalware_Setup.exe /SPAWNWND=$20206 /NOTIFYWND=$801D0 /INSTALLER /SELECTEDLANG x0409 /AUTOUPLOAD =================
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,675 [INFO ] [1] [Zemana.AntiMalware.Core.Localization.Translator.Initialize] Line: 111 - Translator has been initialized.
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,695 [INFO ] [1] [Zemana.AntiMalware.Core.Notifications.Notifier.Initialize] Line: 26 - Notifier has been initialized.
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,710 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.GetCurrentLanguageCode] Line: 1494 - The setup selected language has ben set by translator. SelectedLang: en-US
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,710 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.SetThreadCulture] Line: 694 - Thread culture has ben set to en-US
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,820 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.ApplyLocalization] Line: 706 - Translation has been applied
AntiMalware.exe
AMLogger: 2021-01-01 00:59:19,820 [INFO ] [1] [Zemana.AntiMalware.UI.frmMain.RebrandApplication] Line: 891 - Zemana AntiMalware is being initialized... AppId: 2
AntiMalware.exe
AMLogger: 2021-01-01 00:59:20,148 [INFO ] [1] [Zemana.AntiMalware.Core.Reporting.ScanReporter..ctor] Line: 34 - Creating initial scan report directory... Directory: C:\Users\admin\AppData\Local\Zemana\AntiMalware\reports