File name:

Checkers.rar

Full analysis: https://app.any.run/tasks/8f02d882-7944-4b9c-895c-9ace691c597a
Verdict: Malicious activity
Analysis date: October 09, 2021, 15:41:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

7A8E9CFF74574709F9FA16432F1832A5

SHA1:

FFD34CB40DE121397DCFCB4E71AEE0C263D7E588

SHA256:

DF48465FB0CC79DF0227AC10E0B5E6B75173E1E62F310414B4AED65DEFED6DA6

SSDEEP:

49152:w/gjwC2lvyEU8hl5vedhTmMqU9WYpadzhWs1rMCDNas:KRyEU0veKR0WxhKCxj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • ndp472-kb4054531-web.exe (PID: 2368)
    • Drops executable file immediately after starts

      • ndp472-kb4054531-web.exe (PID: 2368)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3552)
      • SearchProtocolHost.exe (PID: 3052)
      • MsiExec.exe (PID: 2824)
      • msiexec.exe (PID: 1412)
      • MsiExec.exe (PID: 3444)
      • svchost.exe (PID: 784)
      • ngen.exe (PID: 1784)
      • aspnet_regiis.exe (PID: 3056)
      • mscorsvw.exe (PID: 1876)
      • mscorsvw.exe (PID: 1912)
      • mscorsvw.exe (PID: 2556)
      • ngen.exe (PID: 3332)
      • ngen.exe (PID: 3772)
      • mscorsvw.exe (PID: 2112)
      • mscorsvw.exe (PID: 4052)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 3972)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 1068)
      • mscorsvw.exe (PID: 1588)
      • mscorsvw.exe (PID: 2568)
      • mscorsvw.exe (PID: 3688)
      • mscorsvw.exe (PID: 3660)
      • mscorsvw.exe (PID: 2884)
      • mscorsvw.exe (PID: 3564)
      • mscorsvw.exe (PID: 2276)
      • mscorsvw.exe (PID: 4056)
      • mscorsvw.exe (PID: 2636)
      • mscorsvw.exe (PID: 3016)
      • mscorsvw.exe (PID: 2464)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 3932)
      • mscorsvw.exe (PID: 1944)
      • mscorsvw.exe (PID: 3040)
      • mscorsvw.exe (PID: 2344)
      • mscorsvw.exe (PID: 1824)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 844)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 2852)
      • mscorsvw.exe (PID: 1260)
      • mscorsvw.exe (PID: 3884)
      • mscorsvw.exe (PID: 3520)
      • mscorsvw.exe (PID: 3512)
      • mscorsvw.exe (PID: 948)
      • mscorsvw.exe (PID: 3692)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 2596)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2768)
      • mscorsvw.exe (PID: 2388)
      • mscorsvw.exe (PID: 600)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2396)
      • mscorsvw.exe (PID: 2928)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 2656)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 3868)
      • mscorsvw.exe (PID: 2456)
      • mscorsvw.exe (PID: 2556)
      • mscorsvw.exe (PID: 3324)
      • mscorsvw.exe (PID: 1156)
      • mscorsvw.exe (PID: 3776)
      • mscorsvw.exe (PID: 3704)
      • mscorsvw.exe (PID: 3736)
      • mscorsvw.exe (PID: 796)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 4060)
      • mscorsvw.exe (PID: 2132)
      • mscorsvw.exe (PID: 2968)
      • mscorsvw.exe (PID: 3892)
      • mscorsvw.exe (PID: 312)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 2260)
      • mscorsvw.exe (PID: 1844)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 3968)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 2900)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 3852)
      • mscorsvw.exe (PID: 2004)
      • mscorsvw.exe (PID: 1008)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 1592)
      • mscorsvw.exe (PID: 2064)
      • mscorsvw.exe (PID: 3436)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2652)
      • mscorsvw.exe (PID: 3452)
      • mscorsvw.exe (PID: 2024)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 2600)
      • mscorsvw.exe (PID: 3220)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 2972)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 1456)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 2720)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2760)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 2532)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3552)
      • ndp472-kb4054531-web.exe (PID: 2416)
      • ndp472-kb4054531-web.exe (PID: 2368)
      • SetupUtility.exe (PID: 732)
      • SetupUtility.exe (PID: 3900)
      • ServiceModelReg.exe (PID: 1584)
      • regtlibv12.exe (PID: 1980)
      • aspnet_regiis.exe (PID: 3056)
      • ngen.exe (PID: 1784)
      • mscorsvw.exe (PID: 1876)
      • mscorsvw.exe (PID: 1912)
      • mscorsvw.exe (PID: 2556)
      • ngen.exe (PID: 3332)
      • mscorsvw.exe (PID: 2112)
      • ngen.exe (PID: 3772)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 3972)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 4052)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 3660)
      • mscorsvw.exe (PID: 1068)
      • mscorsvw.exe (PID: 2568)
      • mscorsvw.exe (PID: 3688)
      • mscorsvw.exe (PID: 1588)
      • mscorsvw.exe (PID: 2636)
      • mscorsvw.exe (PID: 3564)
      • mscorsvw.exe (PID: 2276)
      • mscorsvw.exe (PID: 4056)
      • mscorsvw.exe (PID: 3016)
      • mscorsvw.exe (PID: 2884)
      • mscorsvw.exe (PID: 3932)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 1944)
      • mscorsvw.exe (PID: 2464)
      • mscorsvw.exe (PID: 2344)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 1260)
      • mscorsvw.exe (PID: 3040)
      • mscorsvw.exe (PID: 1824)
      • mscorsvw.exe (PID: 844)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 2852)
      • mscorsvw.exe (PID: 948)
      • mscorsvw.exe (PID: 3520)
      • mscorsvw.exe (PID: 3512)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 3692)
      • mscorsvw.exe (PID: 3884)
      • mscorsvw.exe (PID: 2596)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1008)
      • mscorsvw.exe (PID: 2768)
      • mscorsvw.exe (PID: 2388)
      • mscorsvw.exe (PID: 600)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2396)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 2928)
      • mscorsvw.exe (PID: 3324)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 2656)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 1592)
      • mscorsvw.exe (PID: 2456)
      • mscorsvw.exe (PID: 1156)
      • mscorsvw.exe (PID: 3868)
      • mscorsvw.exe (PID: 2556)
      • mscorsvw.exe (PID: 2064)
      • mscorsvw.exe (PID: 3452)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 3704)
      • mscorsvw.exe (PID: 3776)
      • mscorsvw.exe (PID: 3436)
      • mscorsvw.exe (PID: 3736)
      • mscorsvw.exe (PID: 4060)
      • mscorsvw.exe (PID: 796)
      • mscorsvw.exe (PID: 2132)
      • mscorsvw.exe (PID: 2968)
      • mscorsvw.exe (PID: 3892)
      • mscorsvw.exe (PID: 312)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 1844)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 2900)
      • mscorsvw.exe (PID: 2260)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 3220)
      • mscorsvw.exe (PID: 3852)
      • mscorsvw.exe (PID: 3968)
      • mscorsvw.exe (PID: 2652)
      • mscorsvw.exe (PID: 2004)
      • mscorsvw.exe (PID: 2024)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 2600)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 1456)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 2972)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2720)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 2760)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 3276)
      • mscorsvw.exe (PID: 2532)
    • Changes settings of System certificates

      • Setup.exe (PID: 3552)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 1412)
    • Loads the Task Scheduler COM API

      • ngen.exe (PID: 1784)
      • mscorsvw.exe (PID: 1876)
      • ngen.exe (PID: 3772)
      • ngen.exe (PID: 3332)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1628)
      • ndp472-kb4054531-web.exe (PID: 2368)
      • msiexec.exe (PID: 1412)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 2776)
    • Checks supported languages

      • WinRAR.exe (PID: 1628)
      • ndp472-kb4054531-web.exe (PID: 2368)
      • Setup.exe (PID: 3552)
      • SetupUtility.exe (PID: 732)
      • SetupUtility.exe (PID: 3900)
      • TMP5D99.tmp.exe (PID: 3632)
      • ServiceModelReg.exe (PID: 1584)
      • mofcomp.exe (PID: 2236)
      • regtlibv12.exe (PID: 1980)
      • mofcomp.exe (PID: 2776)
      • ngen.exe (PID: 1784)
      • aspnet_regiis.exe (PID: 3056)
      • mofcomp.exe (PID: 3340)
      • mscorsvw.exe (PID: 1876)
      • mscorsvw.exe (PID: 1912)
      • mscorsvw.exe (PID: 2556)
      • ngen.exe (PID: 3772)
      • mscorsvw.exe (PID: 2112)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 3972)
      • ngen.exe (PID: 3332)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 4052)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 3660)
      • mscorsvw.exe (PID: 1068)
      • mscorsvw.exe (PID: 2568)
      • mscorsvw.exe (PID: 3688)
      • mscorsvw.exe (PID: 1588)
      • mscorsvw.exe (PID: 2636)
      • mscorsvw.exe (PID: 2884)
      • mscorsvw.exe (PID: 3564)
      • mscorsvw.exe (PID: 2276)
      • mscorsvw.exe (PID: 4056)
      • mscorsvw.exe (PID: 3016)
      • mscorsvw.exe (PID: 2464)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 3932)
      • mscorsvw.exe (PID: 1944)
      • mscorsvw.exe (PID: 2344)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 3040)
      • mscorsvw.exe (PID: 1824)
      • mscorsvw.exe (PID: 844)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 2852)
      • mscorsvw.exe (PID: 948)
      • mscorsvw.exe (PID: 1260)
      • mscorsvw.exe (PID: 3520)
      • mscorsvw.exe (PID: 3884)
      • mscorsvw.exe (PID: 3512)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 3692)
      • mscorsvw.exe (PID: 2596)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1008)
      • mscorsvw.exe (PID: 2388)
      • mscorsvw.exe (PID: 600)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 2768)
      • mscorsvw.exe (PID: 2396)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 2928)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 3324)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 2656)
      • mscorsvw.exe (PID: 3868)
      • mscorsvw.exe (PID: 1592)
      • mscorsvw.exe (PID: 2456)
      • mscorsvw.exe (PID: 2556)
      • mscorsvw.exe (PID: 1156)
      • mscorsvw.exe (PID: 2064)
      • mscorsvw.exe (PID: 3776)
      • mscorsvw.exe (PID: 3436)
      • mscorsvw.exe (PID: 3704)
      • mscorsvw.exe (PID: 3452)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 796)
      • mscorsvw.exe (PID: 4060)
      • mscorsvw.exe (PID: 3736)
      • mscorsvw.exe (PID: 2132)
      • mscorsvw.exe (PID: 2968)
      • mscorsvw.exe (PID: 3892)
      • mscorsvw.exe (PID: 312)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 1844)
      • mscorsvw.exe (PID: 2260)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 2900)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 3968)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 3220)
      • mscorsvw.exe (PID: 3852)
      • mscorsvw.exe (PID: 2004)
      • mscorsvw.exe (PID: 2652)
      • mscorsvw.exe (PID: 2024)
      • mscorsvw.exe (PID: 2600)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 1456)
      • mscorsvw.exe (PID: 2972)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2720)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 2760)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 2532)
      • mscorsvw.exe (PID: 3276)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1628)
      • msiexec.exe (PID: 1412)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1628)
      • ndp472-kb4054531-web.exe (PID: 2368)
      • TMP5D99.tmp.exe (PID: 3632)
      • Setup.exe (PID: 3552)
      • msiexec.exe (PID: 1412)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 2776)
    • Reads the computer name

      • WinRAR.exe (PID: 1628)
      • ndp472-kb4054531-web.exe (PID: 2368)
      • Setup.exe (PID: 3552)
      • SetupUtility.exe (PID: 3900)
      • SetupUtility.exe (PID: 732)
      • TMP5D99.tmp.exe (PID: 3632)
      • ServiceModelReg.exe (PID: 1584)
      • mofcomp.exe (PID: 2236)
      • mofcomp.exe (PID: 2776)
      • aspnet_regiis.exe (PID: 3056)
      • mofcomp.exe (PID: 3340)
      • ngen.exe (PID: 1784)
      • mscorsvw.exe (PID: 1876)
      • mscorsvw.exe (PID: 1912)
      • mscorsvw.exe (PID: 2556)
      • ngen.exe (PID: 3772)
      • mscorsvw.exe (PID: 2112)
      • mscorsvw.exe (PID: 1896)
      • ngen.exe (PID: 3332)
      • mscorsvw.exe (PID: 3972)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 4052)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 3660)
      • mscorsvw.exe (PID: 1068)
      • mscorsvw.exe (PID: 3688)
      • mscorsvw.exe (PID: 1588)
      • mscorsvw.exe (PID: 2636)
      • mscorsvw.exe (PID: 2568)
      • mscorsvw.exe (PID: 2276)
      • mscorsvw.exe (PID: 2884)
      • mscorsvw.exe (PID: 3564)
      • mscorsvw.exe (PID: 4056)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 2464)
      • mscorsvw.exe (PID: 3932)
      • mscorsvw.exe (PID: 1944)
      • mscorsvw.exe (PID: 3016)
      • mscorsvw.exe (PID: 3040)
      • mscorsvw.exe (PID: 1824)
      • mscorsvw.exe (PID: 2344)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 844)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 2852)
      • mscorsvw.exe (PID: 948)
      • mscorsvw.exe (PID: 1260)
      • mscorsvw.exe (PID: 3520)
      • mscorsvw.exe (PID: 3884)
      • mscorsvw.exe (PID: 3512)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 3692)
      • mscorsvw.exe (PID: 2596)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1008)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2768)
      • mscorsvw.exe (PID: 2388)
      • mscorsvw.exe (PID: 600)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2396)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2928)
      • mscorsvw.exe (PID: 2656)
      • mscorsvw.exe (PID: 2584)
      • mscorsvw.exe (PID: 3324)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 2452)
      • mscorsvw.exe (PID: 3868)
      • mscorsvw.exe (PID: 2456)
      • mscorsvw.exe (PID: 2556)
      • mscorsvw.exe (PID: 1156)
      • mscorsvw.exe (PID: 1592)
      • mscorsvw.exe (PID: 2064)
      • mscorsvw.exe (PID: 3776)
      • mscorsvw.exe (PID: 3452)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 3436)
      • mscorsvw.exe (PID: 3736)
      • mscorsvw.exe (PID: 796)
      • mscorsvw.exe (PID: 4060)
      • mscorsvw.exe (PID: 3704)
      • mscorsvw.exe (PID: 2968)
      • mscorsvw.exe (PID: 2132)
      • mscorsvw.exe (PID: 3892)
      • mscorsvw.exe (PID: 312)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2260)
      • mscorsvw.exe (PID: 2936)
      • mscorsvw.exe (PID: 1844)
      • mscorsvw.exe (PID: 3712)
      • mscorsvw.exe (PID: 3968)
      • mscorsvw.exe (PID: 4036)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 3220)
      • mscorsvw.exe (PID: 2900)
      • mscorsvw.exe (PID: 2652)
      • mscorsvw.exe (PID: 2004)
      • mscorsvw.exe (PID: 3852)
      • mscorsvw.exe (PID: 3264)
      • mscorsvw.exe (PID: 2600)
      • mscorsvw.exe (PID: 2024)
      • mscorsvw.exe (PID: 2972)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 1456)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2720)
      • mscorsvw.exe (PID: 3268)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 2760)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 2532)
      • mscorsvw.exe (PID: 3276)
    • Reads Environment values

      • Setup.exe (PID: 3552)
    • Creates files in the Windows directory

      • Setup.exe (PID: 3552)
      • msiexec.exe (PID: 1412)
      • lodctr.exe (PID: 2408)
      • aspnet_regiis.exe (PID: 3056)
      • ngen.exe (PID: 1784)
      • mscorsvw.exe (PID: 1876)
      • lodctr.exe (PID: 2464)
      • lodctr.exe (PID: 2564)
      • lodctr.exe (PID: 2716)
      • lodctr.exe (PID: 2776)
      • ngen.exe (PID: 3332)
      • ngen.exe (PID: 3772)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 2532)
      • mscorsvw.exe (PID: 3268)
    • Reads CPU info

      • Setup.exe (PID: 3552)
    • Application launched itself

      • msiexec.exe (PID: 1412)
      • mscorsvw.exe (PID: 1876)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 1412)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 1412)
    • Executed as Windows Service

      • msiexec.exe (PID: 1412)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 1412)
      • aspnet_regiis.exe (PID: 3056)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1412)
    • Checks for the .NET to be installed

      • msiexec.exe (PID: 1412)
    • Searches for installed software

      • msiexec.exe (PID: 1412)
    • Removes files from Windows directory

      • lodctr.exe (PID: 2408)
      • aspnet_regiis.exe (PID: 3056)
      • msiexec.exe (PID: 1412)
      • lodctr.exe (PID: 2464)
      • lodctr.exe (PID: 2564)
      • lodctr.exe (PID: 2716)
      • lodctr.exe (PID: 2776)
      • mscorsvw.exe (PID: 1896)
      • mscorsvw.exe (PID: 928)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 3396)
      • mscorsvw.exe (PID: 2324)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 1892)
      • mscorsvw.exe (PID: 3252)
      • mscorsvw.exe (PID: 3492)
      • mscorsvw.exe (PID: 2316)
      • mscorsvw.exe (PID: 2504)
      • mscorsvw.exe (PID: 4068)
      • mscorsvw.exe (PID: 3744)
      • mscorsvw.exe (PID: 3088)
      • mscorsvw.exe (PID: 3668)
      • mscorsvw.exe (PID: 772)
      • mscorsvw.exe (PID: 2724)
      • mscorsvw.exe (PID: 2868)
      • mscorsvw.exe (PID: 2776)
      • mscorsvw.exe (PID: 2532)
  • INFO

    • Manual execution by user

      • ndp472-kb4054531-web.exe (PID: 2368)
      • ndp472-kb4054531-web.exe (PID: 2416)
    • Dropped object may contain Bitcoin addresses

      • svchost.exe (PID: 784)
      • Setup.exe (PID: 3552)
      • msiexec.exe (PID: 1412)
    • Reads settings of System Certificates

      • Setup.exe (PID: 3552)
      • msiexec.exe (PID: 1412)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 3552)
      • msiexec.exe (PID: 1412)
    • Checks supported languages

      • MsiExec.exe (PID: 2824)
      • MsiExec.exe (PID: 3444)
      • msiexec.exe (PID: 1412)
      • wevtutil.exe (PID: 3244)
      • wevtutil.exe (PID: 1916)
      • lodctr.exe (PID: 2408)
      • lodctr.exe (PID: 3844)
      • lodctr.exe (PID: 3836)
      • lodctr.exe (PID: 2464)
      • lodctr.exe (PID: 2564)
      • lodctr.exe (PID: 2716)
      • lodctr.exe (PID: 3424)
      • lodctr.exe (PID: 2776)
    • Reads the computer name

      • MsiExec.exe (PID: 2824)
      • MsiExec.exe (PID: 3444)
      • msiexec.exe (PID: 1412)
      • wevtutil.exe (PID: 3244)
      • lodctr.exe (PID: 2408)
      • wevtutil.exe (PID: 1916)
      • lodctr.exe (PID: 3844)
      • lodctr.exe (PID: 2464)
      • lodctr.exe (PID: 2564)
      • lodctr.exe (PID: 3836)
      • lodctr.exe (PID: 2716)
      • lodctr.exe (PID: 3424)
      • lodctr.exe (PID: 2776)
    • Creates or modifies windows services

      • msiexec.exe (PID: 1412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
194
Monitored processes
141
Malicious processes
123
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs ndp472-kb4054531-web.exe no specs ndp472-kb4054531-web.exe setup.exe setuputility.exe no specs setuputility.exe no specs tmp5d99.tmp.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs servicemodelreg.exe no specs wevtutil.exe no specs wevtutil.exe no specs svchost.exe no specs lodctr.exe no specs regtlibv12.exe no specs mofcomp.exe no specs mofcomp.exe no specs aspnet_regiis.exe no specs mofcomp.exe no specs ngen.exe no specs mscorsvw.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs lodctr.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs ngen.exe no specs ngen.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 328 -InterruptEvent 0 -NGENProcess 318 -Pipe 320 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
600C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1b4 -InterruptEvent 0 -NGENProcess 264 -Pipe 288 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
732SetupUtility.exe /aupauseC:\4e5b88f2390ad4d8b2f4a42775a944\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.7.3081.0 built by: NET472REL1
Modules
Images
c:\4e5b88f2390ad4d8b2f4a42775a944\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
772C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 240 -InterruptEvent 0 -NGENProcess 244 -Pipe 270 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
ngen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mscoree.dll
772C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 35c -InterruptEvent 0 -NGENProcess 344 -Pipe 3a4 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
ngen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
784C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
796C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 300 -InterruptEvent 0 -NGENProcess 2b0 -Pipe 310 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
844C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 214 -InterruptEvent 0 -NGENProcess 20c -Pipe 208 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\ole32.dll
876C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 35c -InterruptEvent 0 -NGENProcess 348 -Pipe 3bc -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
928C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1f4 -InterruptEvent 0 -NGENProcess 1ec -Pipe 1e8 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
Total events
95 175
Read events
77 103
Write events
16 127
Delete events
1 945

Modification events

(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Checkers.rar
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3052) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3052) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:@C:\Windows\System32\msxml3r.dll,-1
Value:
XML Document
Executable files
2 598
Suspicious files
48
Text files
489
Unknown types
49

Dropped files

PID
Process
Filename
Type
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.exeexecutable
MD5:
SHA256:
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.pdbpdb
MD5:
SHA256:
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.xmlxml
MD5:
SHA256:
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Guna.UI2.dllexecutable
MD5:ACA7F1CA2525160B85404E638732BD87
SHA256:BF7FD5EFCD54D00BFDA76187CB3F04DD36BB38D9B36B505E1493CFFB7A7F3D9E
2368ndp472-kb4054531-web.exeC:\4e5b88f2390ad4d8b2f4a42775a944\Graphics\Rotate10.icoimage
MD5:0CCA04A3468575FDCEFEE9957E32F904
SHA256:B94E68C711B3B06D9A63C80AD013C7C7BBDB5F8E82CBC866B246FF22D99B03FE
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.exe.configxml
MD5:E44B6F93C65C87159D701EE8821227EE
SHA256:543CB9FD5AD09E2F9148E6FFEAE10C58C73A6C640469AD9ED9475E586F8A2B52
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Leaf.xNet.dllexecutable
MD5:EA87F37E78FB9AF4BF805F6E958F68F4
SHA256:DE9AEA105F31F3541CBC5C460B0160D0689A2872D80748CA1456E6E223F0A4AA
1628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\ndp472-kb4054531-web.exeexecutable
MD5:B3844D880D71DE6D787190D2E378101B
SHA256:151B1C11F625E7122D517B6A1778841DF8FF168D931C41730F59B9E4B8BCBE36
2368ndp472-kb4054531-web.exeC:\4e5b88f2390ad4d8b2f4a42775a944\Graphics\Rotate7.icoimage
MD5:B4947D242AB4A902031FCD1FFD3A56CD
SHA256:995C9F4EA0D98C0C4E5037EDE43FC44A680D85CB1E37C782ADAB775915E975B8
2368ndp472-kb4054531-web.exeC:\4e5b88f2390ad4d8b2f4a42775a944\header.bmpimage
MD5:41C22EFA84CA74F0CE7076EB9A482E38
SHA256:255025A0D79EF2DAC04BD610363F966EF58328400BF31E1F8915E676478CD750
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
6
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=amd64&o1=netfx_Full_x86.msi
NL
whitelisted
GET
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=amd64&o1=netfx_Full_x86.msi
NL
whitelisted
3552
Setup.exe
GET
200
2.21.143.74:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
der
1.05 Kb
whitelisted
GET
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03081.00&sar=amd64&o1=netfx_Patch_x86.msp
NL
whitelisted
HEAD
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?LinkId=328846&clcid=0x409
NL
whitelisted
GET
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?LinkId=328846&clcid=0x409
NL
whitelisted
GET
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=x86&o1=netfx_Full.mzz
NL
whitelisted
3552
Setup.exe
GET
200
92.123.194.162:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
der
555 b
whitelisted
HEAD
302
104.89.38.104:80
http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03081.00&sar=amd64&o1=netfx_Patch_x86.msp
NL
whitelisted
3552
Setup.exe
GET
200
92.123.194.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
der
824 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3552
Setup.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
68.232.34.200:443
download.visualstudio.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2.21.140.235:443
download.microsoft.com
Telia Company AB
malicious
104.89.38.104:80
go.microsoft.com
Akamai Technologies, Inc.
NL
malicious
3552
Setup.exe
2.21.143.74:80
www.microsoft.com
Telia Company AB
malicious
3552
Setup.exe
92.123.194.162:80
crl.microsoft.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
crl.microsoft.com
  • 92.123.194.162
  • 92.123.194.163
whitelisted
go.microsoft.com
  • 104.89.38.104
whitelisted
download.microsoft.com
  • 2.21.140.235
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted
www.microsoft.com
  • 2.21.143.74
whitelisted

Threats

No threats detected
No debug info