URL:

https://www.glarysoft.com/products/utilities/glary-utilities/download/

Full analysis: https://app.any.run/tasks/52776c36-29cb-437e-8f41-e88a57b0e0a5
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 15, 2025, 17:06:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
Indicators:
MD5:

C81F8AEFAAB9FB76CA42927DC1F1D338

SHA1:

35BF26675B803BD34AFDDE0E9EF60AEF24933B06

SHA256:

DA4FE08EC379C326D6D92E16D6460FA54DFDD7D15F58AAD52060511EE85B92A1

SSDEEP:

3:N8DSL/KX9aQGRWLfRMz0Xz/zkCn:2OL/QQRWL5MYXLt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • nsE37F.tmp (PID: 2600)
      • net.exe (PID: 2668)
      • net.exe (PID: 1980)
      • ns7D5F.tmp (PID: 1180)
      • net.exe (PID: 3388)
      • nsE2F1.tmp (PID: 2612)
    • Actions looks like stealing of personal data

      • Initialize.exe (PID: 3424)
      • Integrator.exe (PID: 3844)
      • Initialize.exe (PID: 944)
      • Integrator.exe (PID: 3064)
      • DiskCleaner.exe (PID: 2108)
      • TracksEraser.exe (PID: 2544)
    • Steals credentials from Web Browsers

      • Initialize.exe (PID: 3424)
      • Integrator.exe (PID: 3844)
      • Initialize.exe (PID: 944)
      • Integrator.exe (PID: 3064)
      • DiskCleaner.exe (PID: 2108)
      • TracksEraser.exe (PID: 2544)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • gu6setup.exe (PID: 3956)
      • gu6setup.exe (PID: 912)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • gu6setup.exe (PID: 3956)
      • gu6setup.exe (PID: 912)
    • Executable content was dropped or overwritten

      • gu6setup.exe (PID: 3956)
      • statisticsinfo.exe (PID: 2952)
      • StartupManager.exe (PID: 2864)
      • gu6setup.exe (PID: 912)
    • Starts application with an unusual extension

      • gu6setup.exe (PID: 912)
    • There is functionality for taking screenshot (YARA)

      • gu6setup.exe (PID: 912)
      • gu6setup.exe (PID: 3956)
      • MemfilesService.exe (PID: 3312)
      • MemfilesService.exe (PID: 1612)
      • Initialize.exe (PID: 944)
      • Integrator.exe (PID: 3844)
      • DiskCleaner.exe (PID: 2108)
      • TracksEraser.exe (PID: 2544)
    • Process drops legitimate windows executable

      • gu6setup.exe (PID: 912)
    • The process drops C-runtime libraries

      • gu6setup.exe (PID: 912)
    • Creates/Modifies COM task schedule object

      • gu6setup.exe (PID: 912)
    • Creates a software uninstall entry

      • statisticsinfo.exe (PID: 2952)
      • gu6setup.exe (PID: 912)
    • Reads security settings of Internet Explorer

      • statisticsinfo.exe (PID: 2952)
      • StartupManager.exe (PID: 2864)
      • Initialize.exe (PID: 3424)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • upgrade.exe (PID: 1028)
      • Initialize.exe (PID: 944)
      • SoftwareUpdate.exe (PID: 2776)
      • TracksEraser.exe (PID: 2544)
    • Reads the Internet Settings

      • statisticsinfo.exe (PID: 2952)
      • StartupManager.exe (PID: 2864)
      • Initialize.exe (PID: 3424)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • upgrade.exe (PID: 1028)
      • Initialize.exe (PID: 944)
      • SoftwareUpdate.exe (PID: 2776)
      • DiskCleaner.exe (PID: 2108)
      • TracksEraser.exe (PID: 2544)
    • Creates or modifies Windows services

      • DiskDefrag.exe (PID: 2740)
    • Searches for installed software

      • statisticsinfo.exe (PID: 2952)
      • Integrator.exe (PID: 3844)
      • SoftwareUpdate.exe (PID: 2776)
    • Drops a system driver (possible attempt to evade defenses)

      • StartupManager.exe (PID: 2864)
    • Creates files in the driver directory

      • StartupManager.exe (PID: 2864)
    • Executes as Windows Service

      • MemfilesService.exe (PID: 3312)
      • GUBootService.exe (PID: 1976)
    • Starts CMD.EXE for commands execution

      • MemfilesService.exe (PID: 3312)
      • cmd.exe (PID: 872)
    • Application launched itself

      • cmd.exe (PID: 872)
    • Creates file in the systems drive root

      • MemfilesService.exe (PID: 1612)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 3568)
    • Reads Microsoft Outlook installation path

      • upgrade.exe (PID: 1028)
      • Integrator.exe (PID: 3844)
    • Reads Internet Explorer settings

      • upgrade.exe (PID: 1028)
    • Checks Windows Trust Settings

      • Integrator.exe (PID: 3844)
      • SoftwareUpdate.exe (PID: 2776)
    • Reads settings of System Certificates

      • Integrator.exe (PID: 3844)
      • SoftwareUpdate.exe (PID: 2776)
    • Adds/modifies Windows certificates

      • Integrator.exe (PID: 3844)
    • The process verifies whether the antivirus software is installed

      • DiskCleaner.exe (PID: 2108)
    • Reads browser cookies

      • TracksEraser.exe (PID: 2544)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 1560)
    • Checks supported languages

      • wmpnscfg.exe (PID: 904)
      • gu6setup.exe (PID: 3956)
      • gu6setup.exe (PID: 912)
      • nsE37F.tmp (PID: 2600)
      • GUAssistComSvc.exe (PID: 2512)
      • DiskDefrag.exe (PID: 2740)
      • StartupManager.exe (PID: 2864)
      • statisticsinfo.exe (PID: 2952)
      • GUBootService.exe (PID: 2852)
      • procmgr.exe (PID: 1920)
      • GUPMService.exe (PID: 2828)
      • MemfilesService.exe (PID: 2276)
      • MemfilesService.exe (PID: 3312)
      • Initialize.exe (PID: 3424)
      • ns7D5F.tmp (PID: 1180)
      • MemfilesService.exe (PID: 1612)
      • GUBootService.exe (PID: 3656)
      • nsF80E.tmp (PID: 3676)
      • nsE2F1.tmp (PID: 2612)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • Initialize.exe (PID: 944)
      • upgrade.exe (PID: 1028)
      • GUAssistComSvc.exe (PID: 396)
      • Integrator.exe (PID: 3064)
      • SoftwareUpdate.exe (PID: 2776)
      • GUBootService.exe (PID: 1976)
      • DiskCleaner.exe (PID: 2108)
      • GUAssistComSvc.exe (PID: 488)
      • StartupManager.exe (PID: 2800)
      • TracksEraser.exe (PID: 2544)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 904)
    • Reads the computer name

      • wmpnscfg.exe (PID: 904)
      • gu6setup.exe (PID: 3956)
      • gu6setup.exe (PID: 912)
      • GUAssistComSvc.exe (PID: 2512)
      • StartupManager.exe (PID: 2864)
      • DiskDefrag.exe (PID: 2740)
      • statisticsinfo.exe (PID: 2952)
      • GUPMService.exe (PID: 2828)
      • GUBootService.exe (PID: 2852)
      • procmgr.exe (PID: 1920)
      • MemfilesService.exe (PID: 2276)
      • Initialize.exe (PID: 3424)
      • MemfilesService.exe (PID: 3312)
      • MemfilesService.exe (PID: 1612)
      • GUBootService.exe (PID: 3656)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • Initialize.exe (PID: 944)
      • upgrade.exe (PID: 1028)
      • Integrator.exe (PID: 3064)
      • SoftwareUpdate.exe (PID: 2776)
      • GUBootService.exe (PID: 1976)
      • DiskCleaner.exe (PID: 2108)
      • GUAssistComSvc.exe (PID: 396)
      • StartupManager.exe (PID: 2800)
      • GUAssistComSvc.exe (PID: 488)
      • TracksEraser.exe (PID: 2544)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2268)
      • msedge.exe (PID: 1560)
    • Create files in a temporary directory

      • gu6setup.exe (PID: 3956)
      • gu6setup.exe (PID: 912)
      • statisticsinfo.exe (PID: 2952)
      • Integrator.exe (PID: 3844)
      • upgrade.exe (PID: 1028)
      • AutoUpdate.exe (PID: 3488)
    • The sample compiled with english language support

      • gu6setup.exe (PID: 912)
      • statisticsinfo.exe (PID: 2952)
    • Creates files in the program directory

      • gu6setup.exe (PID: 912)
      • StartupManager.exe (PID: 2864)
      • Initialize.exe (PID: 3424)
      • MemfilesService.exe (PID: 1612)
      • Integrator.exe (PID: 3844)
      • Initialize.exe (PID: 944)
      • Integrator.exe (PID: 3064)
      • DiskCleaner.exe (PID: 2108)
      • GUBootService.exe (PID: 1976)
      • StartupManager.exe (PID: 2800)
      • TracksEraser.exe (PID: 2544)
    • The sample compiled with arabic language support

      • gu6setup.exe (PID: 912)
    • The sample compiled with chinese language support

      • gu6setup.exe (PID: 912)
    • Reads Environment values

      • statisticsinfo.exe (PID: 2952)
      • gu6setup.exe (PID: 912)
      • Integrator.exe (PID: 3844)
      • DiskCleaner.exe (PID: 2108)
    • Checks proxy server information

      • statisticsinfo.exe (PID: 2952)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • upgrade.exe (PID: 1028)
      • SoftwareUpdate.exe (PID: 2776)
    • Reads the machine GUID from the registry

      • DiskDefrag.exe (PID: 2740)
      • statisticsinfo.exe (PID: 2952)
      • Integrator.exe (PID: 3844)
      • AutoUpdate.exe (PID: 3488)
      • upgrade.exe (PID: 1028)
      • SoftwareUpdate.exe (PID: 2776)
      • GUAssistComSvc.exe (PID: 396)
      • GUBootService.exe (PID: 1976)
      • DiskCleaner.exe (PID: 2108)
      • GUAssistComSvc.exe (PID: 488)
      • StartupManager.exe (PID: 2800)
    • Creates files or folders in the user directory

      • Initialize.exe (PID: 3424)
      • gu6setup.exe (PID: 912)
      • Integrator.exe (PID: 3844)
      • Initialize.exe (PID: 944)
      • upgrade.exe (PID: 1028)
      • AutoUpdate.exe (PID: 3488)
      • Integrator.exe (PID: 3064)
      • SoftwareUpdate.exe (PID: 2776)
      • DiskCleaner.exe (PID: 2108)
      • TracksEraser.exe (PID: 2544)
    • Process checks whether UAC notifications are on

      • Integrator.exe (PID: 3844)
    • Reads the software policy settings

      • Integrator.exe (PID: 3844)
      • SoftwareUpdate.exe (PID: 2776)
    • Reads product name

      • Integrator.exe (PID: 3844)
      • DiskCleaner.exe (PID: 2108)
    • Reads Microsoft Office registry keys

      • TracksEraser.exe (PID: 2544)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
109
Monitored processes
62
Malicious processes
11
Suspicious processes
7

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs gu6setup.exe no specs gu6setup.exe gu6setup.exe no specs gu6setup.exe nse2f1.tmp no specs net.exe no specs net1.exe no specs nse37f.tmp no specs net.exe no specs net1.exe no specs guassistcomsvc.exe no specs diskdefrag.exe no specs statisticsinfo.exe startupmanager.exe gubootservice.exe no specs gupmservice.exe no specs procmgr.exe no specs memfilesservice.exe no specs ns7d5f.tmp no specs net.exe no specs net1.exe no specs memfilesservice.exe no specs cmd.exe no specs cmd.exe no specs initialize.exe memfilesservice.exe no specs gubootservice.exe no specs nsf80e.tmp no specs schtasks.exe no specs integrator.exe initialize.exe autoupdate.exe upgrade.exe integrator.exe softwareupdate.exe guassistcomsvc.exe no specs gubootservice.exe no specs diskcleaner.exe guassistcomsvc.exe no specs startupmanager.exe no specs trackseraser.exe

Process information

PID
CMD
Path
Indicators
Parent process
336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5192 --field-trial-handle=1308,i,372858387457572542,17511353740934660205,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
396"C:\Program Files\Glary Utilities\GUAssistComSvc.exe" -EmbeddingC:\Program Files\Glary Utilities\GUAssistComSvc.exesvchost.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
488"C:\Program Files\Glary Utilities\GUAssistComSvc.exe" -EmbeddingC:\Program Files\Glary Utilities\GUAssistComSvc.exesvchost.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
600"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=2920 --field-trial-handle=1308,i,372858387457572542,17511353740934660205,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
688"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1452 --field-trial-handle=1308,i,372858387457572542,17511353740934660205,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
872C:\Windows\system32\cmd.exe /c cmd /K echo The following code only works for x64C:\Windows\System32\cmd.exeMemfilesService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
904"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
904cmd /K echo The following code only works for x64C:\Windows\System32\cmd.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
912"C:\Users\admin\Downloads\gu6setup.exe" C:\Users\admin\Downloads\gu6setup.exe
msedge.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Description:
Glary Utilities Installer
Exit code:
0
Modules
Images
c:\users\admin\downloads\gu6setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
944"C:\Program Files\Glary Utilities\Initialize.exe" C:\Program Files\Glary Utilities\Initialize.exe
Integrator.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Description:
Glary Utilities Initialize
Exit code:
0
Version:
6, 0, 0, 43
Total events
31 441
Read events
30 054
Write events
999
Delete events
388

Modification events

(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(1560) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(1560) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
B0293397C78C2F00
(PID) Process:(1560) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault
Operation:delete valueName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
Executable files
154
Suspicious files
185
Text files
780
Unknown types
0

Dropped files

PID
Process
Filename
Type
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF108d0f.TMP
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF108d3e.TMP
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF108d4e.TMP
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF108df9.TMP
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG.old~RF108d6d.TMPtext
MD5:5EF0F31B6E7675AE779CC7D73CBB1AA3
SHA256:4CA9894E5D3F96E2A7BC1654E87A6D2D88CAE9CA910A126E4350E5BAE17907DF
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Versiontext
MD5:61FE7896F9494DCDF53480A325F4FB85
SHA256:ACFD3CD36E0DFCF1DCB67C7F31F2A5B9BA0815528A0C604D4330DFAA9E683E51
1560msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:34E5EAD530AB9B83DC9A97EF692C43DA
SHA256:08C1ED902B6CBCED9EABBA790AEAD31EB32972D703B6971165662E6F7C0369BE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
70
DNS requests
62
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2268
msedge.exe
GET
301
188.114.97.3:80
http://www.glarysoft.com/glary-utilities/download/
unknown
whitelisted
2952
statisticsinfo.exe
POST
200
52.24.207.204:80
http://analytics.glarysoft.com/api/v1/install
unknown
unknown
3488
AutoUpdate.exe
GET
200
188.114.96.3:80
http://www.glarysoft.com/update/glary-utilities/autoupdate.ini
unknown
whitelisted
3844
Integrator.exe
POST
200
188.114.96.3:80
http://myaccount.glarysoft.com/openapi.php/lr/expire_time
unknown
unknown
3844
Integrator.exe
POST
200
23.23.198.31:80
http://gu.glarysoft.com/boottime/service.php
unknown
unknown
1028
upgrade.exe
GET
200
188.114.96.3:80
http://www.glarysoft.com/update/glary-utilities/pro/pro50/
unknown
whitelisted
1028
upgrade.exe
GET
200
188.114.97.3:80
http://www_orig.glarysoft.com/update/glary-utilities/pro/upgradetopro.ini?src=10000&id=1&v=6.0.0.1
unknown
unknown
1028
upgrade.exe
GET
200
188.114.96.3:80
http://www.glarysoft.com/update/glary-utilities/pro/pro50/50.png
unknown
whitelisted
3844
Integrator.exe
POST
200
23.23.198.31:80
http://gu.glarysoft.com/boottime/service.php
unknown
unknown
3844
Integrator.exe
GET
302
188.114.96.3:80
http://go.glarysoft.com/g/t/news/cn/10000/s/Glary%20Utilities/v/6.21.0.25/urlrand/7297
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
2268
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1560
msedge.exe
239.255.255.250:1900
whitelisted
2268
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2268
msedge.exe
188.114.97.3:443
www.glarysoft.com
CLOUDFLARENET
NL
whitelisted
2268
msedge.exe
188.114.97.3:80
www.glarysoft.com
CLOUDFLARENET
NL
whitelisted
2268
msedge.exe
142.250.185.138:443
fonts.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.glarysoft.com
  • 188.114.97.3
  • 188.114.96.3
whitelisted
fonts.googleapis.com
  • 142.250.185.138
whitelisted
translate.google.com
  • 142.250.185.110
whitelisted
fonts.gstatic.com
  • 216.58.212.163
whitelisted
static.zdassets.com
  • 216.198.54.3
  • 216.198.53.3
whitelisted
platform-api.sharethis.com
  • 54.230.228.73
  • 54.230.228.76
  • 54.230.228.77
  • 54.230.228.32
whitelisted
www.gstatic.com
  • 142.250.185.195
whitelisted

Threats

PID
Process
Class
Message
2952
statisticsinfo.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
3844
Integrator.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
No debug info