File name:

MasculineUnban_EARLY_BETA.exe

Full analysis: https://app.any.run/tasks/7519664b-026a-47c5-964f-501d48e78bef
Verdict: Malicious activity
Analysis date: May 16, 2025, 15:38:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
amifldrv64-sys
vuln-driver
themida
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 6 sections
MD5:

ACAFC89FE5F6EFE9701AE037A7FF3690

SHA1:

7AC0C75C25129FCDA88AB4F3D3C8EB5BEB38D45F

SHA256:

E18FF240D3D8A5773515E6E61FA119D909530FD232DAD719A479CC44842BD1A4

SSDEEP:

98304:v0RzFU1J9HrOcFbOuSeORxedrjRFHOXonqpWvWc2QDtBH0a+U+WhNWg+hwyJQ0li:FCmDVzPNyS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Vulnerable driver has been detected

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • Antivirus name has been found in the command line (generic signature)

      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
      • cmd.exe (PID: 7632)
    • Executing a file with an untrusted certificate

      • Volumeid64.exe (PID: 7920)
      • DriveCleanup.exe (PID: 7976)
      • DeviceCleanupCmd.exe (PID: 7880)
    • Changes the autorun value in the registry

      • AppleCleaner.exe (PID: 7944)
      • netsh.exe (PID: 644)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • The process creates files with name similar to system file names

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • Executable content was dropped or overwritten

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • Executing commands from a ".bat" file

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
      • cmd.exe (PID: 7304)
    • Starts CMD.EXE for commands execution

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
      • cmd.exe (PID: 7304)
      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
      • AppleCleaner.exe (PID: 7944)
    • Process drops legitimate windows executable

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • The executable file from the user directory is run by the CMD process

      • extd.exe (PID: 7328)
      • extd.exe (PID: 7388)
      • extd.exe (PID: 7468)
      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
      • extd.exe (PID: 5204)
      • Volumeid64.exe (PID: 7920)
      • AppleCleaner.exe (PID: 7944)
      • DevManView.exe (PID: 7968)
      • DeviceCleanupCmd.exe (PID: 7880)
      • DriveCleanup.exe (PID: 7976)
      • DevManView.exe (PID: 660)
      • DevManView.exe (PID: 2568)
      • DevManView.exe (PID: 7660)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 8004)
      • DevManView.exe (PID: 968)
      • DevManView.exe (PID: 7600)
      • DevManView.exe (PID: 4572)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 8040)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 8056)
      • DevManView.exe (PID: 7596)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 6048)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 7868)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 6468)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 2568)
      • DevManView.exe (PID: 6700)
      • DevManView.exe (PID: 7584)
      • DevManView.exe (PID: 7772)
      • DevManView.exe (PID: 2084)
      • DevManView.exe (PID: 7476)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 5408)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 7840)
      • DevManView.exe (PID: 924)
      • DevManView.exe (PID: 668)
      • DevManView.exe (PID: 8044)
      • DevManView.exe (PID: 6620)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 4868)
      • DevManView.exe (PID: 1912)
      • DevManView.exe (PID: 7620)
      • DevManView.exe (PID: 8168)
      • DevManView.exe (PID: 7152)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7256)
      • DevManView.exe (PID: 7244)
      • DevManView.exe (PID: 2192)
      • DevManView.exe (PID: 4024)
      • DevManView.exe (PID: 5232)
      • DevManView.exe (PID: 7980)
      • DevManView.exe (PID: 7884)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7888)
      • DevManView.exe (PID: 7716)
      • DevManView.exe (PID: 4336)
      • DevManView.exe (PID: 2108)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 7860)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 7968)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 3768)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 6248)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 3304)
      • DevManView.exe (PID: 2104)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 7936)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 6416)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 7496)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 5116)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 7680)
      • DevManView.exe (PID: 7776)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 2332)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 6404)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 420)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 8076)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7896)
      • DevManView.exe (PID: 5744)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 2268)
      • DevManView.exe (PID: 7848)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 3768)
      • DevManView.exe (PID: 2564)
      • DevManView.exe (PID: 7860)
      • DevManView.exe (PID: 6048)
      • DevManView.exe (PID: 6392)
      • DevManView.exe (PID: 728)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 2084)
      • DevManView.exe (PID: 3156)
      • DevManView.exe (PID: 2656)
      • DevManView.exe (PID: 5892)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 5324)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 4944)
      • DevManView.exe (PID: 7784)
      • DevManView.exe (PID: 3968)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 8036)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 5116)
      • DevManView.exe (PID: 8028)
      • DevManView.exe (PID: 8068)
      • DevManView.exe (PID: 7944)
      • DevManView.exe (PID: 7428)
      • DevManView.exe (PID: 2284)
      • DevManView.exe (PID: 7048)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 6620)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 7664)
      • DevManView.exe (PID: 2600)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 2644)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 6988)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 5408)
      • DevManView.exe (PID: 8160)
      • DevManView.exe (PID: 7524)
      • DevManView.exe (PID: 896)
      • DevManView.exe (PID: 4000)
      • DevManView.exe (PID: 1096)
      • DevManView.exe (PID: 7268)
      • DevManView.exe (PID: 7988)
      • DevManView.exe (PID: 2240)
      • DevManView.exe (PID: 5744)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 236)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 240)
      • DevManView.exe (PID: 1348)
      • DevManView.exe (PID: 8088)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 2776)
      • DevManView.exe (PID: 7288)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 7856)
      • DevManView.exe (PID: 7372)
      • DevManView.exe (PID: 7936)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 4944)
      • DevManView.exe (PID: 7180)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 7416)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 8148)
      • DevManView.exe (PID: 8164)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 6124)
      • DevManView.exe (PID: 2832)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 5200)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 1384)
      • DevManView.exe (PID: 6988)
      • DevManView.exe (PID: 7424)
      • DevManView.exe (PID: 7476)
      • DevManView.exe (PID: 7696)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 5452)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 7520)
      • DevManView.exe (PID: 5112)
      • DevManView.exe (PID: 7612)
      • DevManView.exe (PID: 300)
      • DevManView.exe (PID: 7492)
      • DevManView.exe (PID: 7048)
      • DevManView.exe (PID: 7972)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 5548)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 5328)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 7372)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 7360)
      • DevManView.exe (PID: 5608)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 8032)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 1616)
      • DevManView.exe (PID: 7856)
      • DevManView.exe (PID: 5552)
      • DevManView.exe (PID: 1384)
      • DevManView.exe (PID: 7256)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 1096)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 3300)
      • DevManView.exe (PID: 7968)
      • DevManView.exe (PID: 4244)
      • DevManView.exe (PID: 5328)
      • DevManView.exe (PID: 6248)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 240)
      • DevManView.exe (PID: 6516)
      • DevManView.exe (PID: 7084)
      • DevManView.exe (PID: 872)
      • DevManView.exe (PID: 7424)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 4164)
      • DevManView.exe (PID: 7512)
      • DevManView.exe (PID: 6136)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 3028)
      • DevManView.exe (PID: 7156)
      • DevManView.exe (PID: 2896)
      • DevManView.exe (PID: 7996)
      • DevManView.exe (PID: 1676)
      • DevManView.exe (PID: 2236)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 8068)
      • DevManView.exe (PID: 3304)
      • DevManView.exe (PID: 6416)
      • DevManView.exe (PID: 7980)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 2796)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 632)
      • DevManView.exe (PID: 7924)
      • DevManView.exe (PID: 2600)
      • DevManView.exe (PID: 7272)
      • DevManView.exe (PID: 5936)
      • DevManView.exe (PID: 6640)
      • DevManView.exe (PID: 4336)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 300)
      • DevManView.exe (PID: 3100)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 3176)
      • DevManView.exe (PID: 7496)
      • DevManView.exe (PID: 7620)
      • DevManView.exe (PID: 7988)
      • DevManView.exe (PID: 3672)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 7976)
      • DevManView.exe (PID: 8072)
      • DevManView.exe (PID: 672)
      • DevManView.exe (PID: 4016)
      • DevManView.exe (PID: 7896)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 5112)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 6072)
      • DevManView.exe (PID: 7696)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 6940)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 7504)
      • DevManView.exe (PID: 4976)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 2096)
      • DevManView.exe (PID: 7136)
      • DevManView.exe (PID: 5172)
      • DevManView.exe (PID: 3800)
      • DevManView.exe (PID: 7100)
      • DevManView.exe (PID: 8132)
      • DevManView.exe (PID: 4180)
      • DevManView.exe (PID: 2284)
      • DevManView.exe (PID: 7796)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 6760)
      • DevManView.exe (PID: 5216)
      • DevManView.exe (PID: 3796)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 976)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 7480)
      • DevManView.exe (PID: 4400)
      • DevManView.exe (PID: 4560)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 8052)
      • DevManView.exe (PID: 7184)
      • DevManView.exe (PID: 7984)
      • DevManView.exe (PID: 7556)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 6960)
      • DevManView.exe (PID: 484)
      • DevManView.exe (PID: 8136)
      • DevManView.exe (PID: 7632)
      • DevManView.exe (PID: 4220)
      • DevManView.exe (PID: 7180)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 4488)
      • DevManView.exe (PID: 3992)
      • DevManView.exe (PID: 7312)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 7868)
      • DevManView.exe (PID: 7412)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 6272)
      • DevManView.exe (PID: 8164)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 3900)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2664)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 2656)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 4868)
      • DevManView.exe (PID: 7592)
      • DevManView.exe (PID: 232)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 516)
      • DevManView.exe (PID: 5624)
      • DevManView.exe (PID: 7816)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 4012)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 7820)
      • DevManView.exe (PID: 3784)
      • DevManView.exe (PID: 5728)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 8032)
      • DevManView.exe (PID: 7352)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 5608)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 7928)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 6192)
      • DevManView.exe (PID: 5056)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 8168)
      • DevManView.exe (PID: 6820)
      • DevManView.exe (PID: 3572)
      • DevManView.exe (PID: 6532)
      • DevManView.exe (PID: 4988)
      • DevManView.exe (PID: 4476)
      • DevManView.exe (PID: 716)
      • DevManView.exe (PID: 7036)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7276)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 3804)
      • DevManView.exe (PID: 8088)
      • DevManView.exe (PID: 7632)
      • DevManView.exe (PID: 4488)
      • DevManView.exe (PID: 8120)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 7292)
      • DevManView.exe (PID: 8136)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 4560)
      • DevManView.exe (PID: 6456)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 6904)
      • DevManView.exe (PID: 7268)
      • DevManView.exe (PID: 668)
      • DevManView.exe (PID: 3992)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 5508)
      • DevManView.exe (PID: 7592)
      • DevManView.exe (PID: 236)
      • DevManView.exe (PID: 7456)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 7520)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 8016)
      • DevManView.exe (PID: 5892)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 7892)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 6972)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 2284)
      • DevManView.exe (PID: 7600)
      • DevManView.exe (PID: 2344)
      • DevManView.exe (PID: 7796)
      • DevManView.exe (PID: 5044)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 7780)
      • DevManView.exe (PID: 2896)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 2236)
      • DevManView.exe (PID: 896)
      • DevManView.exe (PID: 6424)
      • DevManView.exe (PID: 716)
      • DevManView.exe (PID: 7184)
      • DevManView.exe (PID: 5176)
      • DevManView.exe (PID: 5728)
      • DevManView.exe (PID: 4376)
      • DevManView.exe (PID: 6708)
      • DevManView.exe (PID: 7240)
      • DevManView.exe (PID: 7576)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 5936)
      • DevManView.exe (PID: 5036)
      • DevManView.exe (PID: 3300)
      • DevManView.exe (PID: 7952)
      • DevManView.exe (PID: 7652)
      • DevManView.exe (PID: 484)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 7624)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 3620)
      • DevManView.exe (PID: 1348)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 6384)
      • DevManView.exe (PID: 4844)
      • DevManView.exe (PID: 7408)
      • DevManView.exe (PID: 5416)
      • DevManView.exe (PID: 7036)
      • DevManView.exe (PID: 2268)
      • DevManView.exe (PID: 6516)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 2772)
      • DevManView.exe (PID: 3796)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 516)
      • DevManView.exe (PID: 3156)
      • DevManView.exe (PID: 1176)
      • DevManView.exe (PID: 6612)
      • DevManView.exe (PID: 4012)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 7820)
      • DevManView.exe (PID: 7360)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 1600)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7892)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 5720)
      • DevManView.exe (PID: 5512)
      • DevManView.exe (PID: 4976)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 7944)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 6136)
      • DevManView.exe (PID: 6560)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 7084)
      • DevManView.exe (PID: 6632)
      • DevManView.exe (PID: 7540)
      • DevManView.exe (PID: 7412)
      • DevManView.exe (PID: 6124)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 7984)
      • DevManView.exe (PID: 7888)
      • DevManView.exe (PID: 6852)
      • DevManView.exe (PID: 2840)
      • DevManView.exe (PID: 4280)
      • DevManView.exe (PID: 540)
      • DevManView.exe (PID: 832)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 7240)
      • DevManView.exe (PID: 2216)
      • DevManView.exe (PID: 7276)
      • DevManView.exe (PID: 6708)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 7652)
      • DevManView.exe (PID: 5776)
      • DevManView.exe (PID: 4920)
      • DevManView.exe (PID: 1128)
      • DevManView.exe (PID: 2344)
      • DevManView.exe (PID: 7784)
      • DevManView.exe (PID: 5708)
      • DevManView.exe (PID: 2700)
      • DevManView.exe (PID: 2476)
      • DevManView.exe (PID: 3684)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 908)
      • DevManView.exe (PID: 6216)
      • DevManView.exe (PID: 3024)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 2108)
      • DevManView.exe (PID: 2408)
      • DevManView.exe (PID: 4244)
      • DevManView.exe (PID: 4308)
      • DevManView.exe (PID: 6456)
      • DevManView.exe (PID: 6072)
      • DevManView.exe (PID: 8132)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 6256)
      • DevManView.exe (PID: 4016)
      • DevManView.exe (PID: 4180)
      • DevManView.exe (PID: 6960)
      • DevManView.exe (PID: 1348)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 1852)
      • cmd.exe (PID: 1532)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7180)
      • cmd.exe (PID: 7972)
      • cmd.exe (PID: 7836)
      • cmd.exe (PID: 7884)
      • cmd.exe (PID: 4208)
      • cmd.exe (PID: 5232)
      • cmd.exe (PID: 2084)
      • cmd.exe (PID: 484)
      • cmd.exe (PID: 6516)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 5136)
      • cmd.exe (PID: 7556)
      • cmd.exe (PID: 6640)
      • cmd.exe (PID: 7776)
      • cmd.exe (PID: 6960)
      • cmd.exe (PID: 7476)
    • Application launched itself

      • cmd.exe (PID: 7304)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 7304)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 7648)
      • cmd.exe (PID: 8172)
    • Uses WMIC.EXE to obtain physical disk drive information

      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7188)
    • Manipulates environment variables

      • powershell.exe (PID: 8188)
    • Stops a currently running service

      • sc.exe (PID: 896)
      • sc.exe (PID: 1276)
    • Reads the BIOS version

      • AppleCleaner.exe (PID: 7944)
    • Hides command output

      • cmd.exe (PID: 7792)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 1532)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 3032)
      • cmd.exe (PID: 896)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 2244)
      • cmd.exe (PID: 2980)
      • cmd.exe (PID: 8048)
      • cmd.exe (PID: 4268)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 5600)
      • cmd.exe (PID: 3300)
      • cmd.exe (PID: 7384)
      • cmd.exe (PID: 6404)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 1852)
      • cmd.exe (PID: 1532)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7836)
      • cmd.exe (PID: 7884)
      • cmd.exe (PID: 4208)
      • cmd.exe (PID: 7972)
      • cmd.exe (PID: 2084)
      • cmd.exe (PID: 5232)
      • cmd.exe (PID: 7180)
      • cmd.exe (PID: 484)
      • cmd.exe (PID: 6516)
      • cmd.exe (PID: 7556)
      • cmd.exe (PID: 5136)
      • cmd.exe (PID: 6640)
      • cmd.exe (PID: 7776)
      • cmd.exe (PID: 8092)
      • cmd.exe (PID: 6960)
      • cmd.exe (PID: 7476)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 8052)
      • cmd.exe (PID: 8080)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 7792)
      • cmd.exe (PID: 1532)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 7188)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7188)
    • Reads the Windows owner or organization settings

      • AppleCleaner.exe (PID: 7944)
    • Detected use of alternative data streams (AltDS)

      • AppleCleaner.exe (PID: 7944)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 3032)
      • cmd.exe (PID: 896)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 2344)
    • Process uses IPCONFIG to discard the IP address configuration

      • cmd.exe (PID: 2244)
      • cmd.exe (PID: 7396)
    • Process uses NBTSTAT to discover network configuration

      • cmd.exe (PID: 8048)
    • Process uses IPCONFIG to clear DNS cache

      • cmd.exe (PID: 2980)
    • Uses WMIC.EXE

      • cmd.exe (PID: 3300)
      • cmd.exe (PID: 7384)
      • cmd.exe (PID: 6404)
      • cmd.exe (PID: 8052)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 8092)
    • Process uses ARP to discover network configuration

      • cmd.exe (PID: 8180)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7188)
  • INFO

    • Checks supported languages

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
      • extd.exe (PID: 7328)
      • extd.exe (PID: 7388)
      • extd.exe (PID: 7468)
      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
      • extd.exe (PID: 5204)
      • devcon.exe (PID: 7656)
      • AppleCleaner.exe (PID: 7944)
      • Volumeid64.exe (PID: 7920)
      • identity_helper.exe (PID: 7880)
    • Create files in a temporary directory

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
      • reset2-Hardware Rescan after Adapter reset.exe (PID: 7508)
    • Creates files or folders in the user directory

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • The sample compiled with english language support

      • MasculineUnban_EARLY_BETA.exe (PID: 7204)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7676)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 1052)
      • WMIC.exe (PID: 4448)
      • WMIC.exe (PID: 7320)
      • WMIC.exe (PID: 5020)
      • WMIC.exe (PID: 2244)
      • WMIC.exe (PID: 7836)
      • WMIC.exe (PID: 7888)
    • Process checks whether UAC notifications are on

      • AppleCleaner.exe (PID: 7944)
    • Reads the computer name

      • extd.exe (PID: 5204)
      • AppleCleaner.exe (PID: 7944)
      • identity_helper.exe (PID: 7880)
    • Reads the machine GUID from the registry

      • AppleCleaner.exe (PID: 7944)
    • Reads Environment values

      • AppleCleaner.exe (PID: 7944)
      • identity_helper.exe (PID: 7880)
    • Reads the time zone

      • AppleCleaner.exe (PID: 7944)
    • Application launched itself

      • msedge.exe (PID: 8096)
      • msedge.exe (PID: 4040)
    • Manual execution by a user

      • msedge.exe (PID: 4040)
    • Themida protector has been detected

      • AppleCleaner.exe (PID: 7944)
    • Reads Windows Product ID

      • AppleCleaner.exe (PID: 7944)
    • Disables trace logs

      • netsh.exe (PID: 7316)
      • netsh.exe (PID: 2568)
      • netsh.exe (PID: 7824)
      • netsh.exe (PID: 7604)
      • netsh.exe (PID: 8080)
    • NirSoft software is detected

      • DevManView.exe (PID: 660)
      • DevManView.exe (PID: 7968)
      • DevManView.exe (PID: 4572)
      • DevManView.exe (PID: 2568)
      • DevManView.exe (PID: 7660)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 968)
      • DevManView.exe (PID: 8004)
      • DevManView.exe (PID: 7600)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 7868)
      • DevManView.exe (PID: 8040)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 8056)
      • DevManView.exe (PID: 6468)
      • DevManView.exe (PID: 7596)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 6048)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 2568)
      • DevManView.exe (PID: 6700)
      • DevManView.exe (PID: 7584)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 7772)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 7476)
      • DevManView.exe (PID: 2084)
      • DevManView.exe (PID: 5408)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 7840)
      • DevManView.exe (PID: 924)
      • DevManView.exe (PID: 668)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 1912)
      • DevManView.exe (PID: 8044)
      • DevManView.exe (PID: 6620)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 4868)
      • DevManView.exe (PID: 8168)
      • DevManView.exe (PID: 7152)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 7620)
      • DevManView.exe (PID: 5232)
      • DevManView.exe (PID: 4024)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7256)
      • DevManView.exe (PID: 7244)
      • DevManView.exe (PID: 2192)
      • DevManView.exe (PID: 7884)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 7888)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7716)
      • DevManView.exe (PID: 4336)
      • DevManView.exe (PID: 7980)
      • DevManView.exe (PID: 2108)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 7968)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 3768)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 6248)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 7860)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 3304)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 2104)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 7936)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 6416)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 5116)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 7496)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 7680)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 7776)
      • DevManView.exe (PID: 8076)
      • DevManView.exe (PID: 2332)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 6404)
      • DevManView.exe (PID: 420)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7896)
      • DevManView.exe (PID: 5744)
      • DevManView.exe (PID: 2268)
      • DevManView.exe (PID: 7860)
      • DevManView.exe (PID: 7848)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 2564)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 3156)
      • DevManView.exe (PID: 6048)
      • DevManView.exe (PID: 728)
      • DevManView.exe (PID: 6392)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 2084)
      • DevManView.exe (PID: 2656)
      • DevManView.exe (PID: 3768)
      • DevManView.exe (PID: 6252)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 5324)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 4944)
      • DevManView.exe (PID: 7784)
      • DevManView.exe (PID: 3968)
      • DevManView.exe (PID: 5892)
      • DevManView.exe (PID: 8036)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 5116)
      • DevManView.exe (PID: 8028)
      • DevManView.exe (PID: 8068)
      • DevManView.exe (PID: 7428)
      • DevManView.exe (PID: 7944)
      • DevManView.exe (PID: 7048)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 6620)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 7664)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 7524)
      • DevManView.exe (PID: 2284)
      • DevManView.exe (PID: 2600)
      • DevManView.exe (PID: 7824)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 6988)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 5408)
      • DevManView.exe (PID: 8160)
      • DevManView.exe (PID: 2644)
      • DevManView.exe (PID: 896)
      • DevManView.exe (PID: 236)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 4000)
      • DevManView.exe (PID: 7268)
      • DevManView.exe (PID: 2240)
      • DevManView.exe (PID: 7988)
      • DevManView.exe (PID: 5744)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 1096)
      • DevManView.exe (PID: 240)
      • DevManView.exe (PID: 1348)
      • DevManView.exe (PID: 8088)
      • DevManView.exe (PID: 2776)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 7288)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 7936)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 7372)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 7856)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 7416)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 8148)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 8164)
      • DevManView.exe (PID: 7424)
      • DevManView.exe (PID: 4944)
      • DevManView.exe (PID: 7180)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 6124)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 5200)
      • DevManView.exe (PID: 6988)
      • DevManView.exe (PID: 7476)
      • DevManView.exe (PID: 2832)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 7696)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 5548)
      • DevManView.exe (PID: 5452)
      • DevManView.exe (PID: 7520)
      • DevManView.exe (PID: 1384)
      • DevManView.exe (PID: 5112)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 5328)
      • DevManView.exe (PID: 300)
      • DevManView.exe (PID: 7492)
      • DevManView.exe (PID: 7048)
      • DevManView.exe (PID: 7972)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 7612)
      • DevManView.exe (PID: 7964)
      • DevManView.exe (PID: 5608)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 2064)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 7360)
      • DevManView.exe (PID: 7372)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 8032)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 1616)
      • DevManView.exe (PID: 7856)
      • DevManView.exe (PID: 5552)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 7256)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 1096)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 3300)
      • DevManView.exe (PID: 7968)
      • DevManView.exe (PID: 1384)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 4244)
      • DevManView.exe (PID: 5328)
      • DevManView.exe (PID: 7424)
      • DevManView.exe (PID: 6248)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 1196)
      • DevManView.exe (PID: 240)
      • DevManView.exe (PID: 7512)
      • DevManView.exe (PID: 872)
      • DevManView.exe (PID: 6136)
      • DevManView.exe (PID: 7084)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 4164)
      • DevManView.exe (PID: 6516)
      • DevManView.exe (PID: 7156)
      • DevManView.exe (PID: 3028)
      • DevManView.exe (PID: 7996)
      • DevManView.exe (PID: 1676)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 2236)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 2896)
      • DevManView.exe (PID: 3304)
      • DevManView.exe (PID: 6416)
      • DevManView.exe (PID: 7980)
      • DevManView.exe (PID: 2600)
      • DevManView.exe (PID: 2796)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 632)
      • DevManView.exe (PID: 8068)
      • DevManView.exe (PID: 7924)
      • DevManView.exe (PID: 7272)
      • DevManView.exe (PID: 5936)
      • DevManView.exe (PID: 6640)
      • DevManView.exe (PID: 4336)
      • DevManView.exe (PID: 3176)
      • DevManView.exe (PID: 2692)
      • DevManView.exe (PID: 300)
      • DevManView.exe (PID: 3100)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 7496)
      • DevManView.exe (PID: 7620)
      • DevManView.exe (PID: 7988)
      • DevManView.exe (PID: 3672)
      • DevManView.exe (PID: 7976)
      • DevManView.exe (PID: 8092)
      • DevManView.exe (PID: 8072)
      • DevManView.exe (PID: 672)
      • DevManView.exe (PID: 4016)
      • DevManView.exe (PID: 7896)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 5112)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 6072)
      • DevManView.exe (PID: 7696)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 6940)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 7504)
      • DevManView.exe (PID: 5024)
      • DevManView.exe (PID: 2096)
      • DevManView.exe (PID: 7136)
      • DevManView.exe (PID: 5172)
      • DevManView.exe (PID: 7100)
      • DevManView.exe (PID: 8132)
      • DevManView.exe (PID: 4180)
      • DevManView.exe (PID: 7796)
      • DevManView.exe (PID: 6760)
      • DevManView.exe (PID: 5216)
      • DevManView.exe (PID: 3796)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 976)
      • DevManView.exe (PID: 7320)
      • DevManView.exe (PID: 7932)
      • DevManView.exe (PID: 7480)
      • DevManView.exe (PID: 1348)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 4560)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 4400)
      • DevManView.exe (PID: 484)
      • DevManView.exe (PID: 6960)
      • DevManView.exe (PID: 8052)
      • DevManView.exe (PID: 7984)
      • DevManView.exe (PID: 7556)
      • DevManView.exe (PID: 7184)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 8136)
      • DevManView.exe (PID: 4488)
      • DevManView.exe (PID: 4220)
      • DevManView.exe (PID: 7632)
      • DevManView.exe (PID: 7180)
      • DevManView.exe (PID: 3992)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 7312)
      • DevManView.exe (PID: 7868)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 7412)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 3900)
      • DevManView.exe (PID: 5756)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 2664)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 6272)
      • DevManView.exe (PID: 8164)
      • DevManView.exe (PID: 2656)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 4868)
      • DevManView.exe (PID: 7592)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 232)
      • DevManView.exe (PID: 7820)
      • DevManView.exe (PID: 5624)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 7816)
      • DevManView.exe (PID: 4012)
      • DevManView.exe (PID: 7956)
      • DevManView.exe (PID: 3784)
      • DevManView.exe (PID: 516)
      • DevManView.exe (PID: 5728)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 5608)
      • DevManView.exe (PID: 8032)
      • DevManView.exe (PID: 7352)
      • DevManView.exe (PID: 5556)
      • DevManView.exe (PID: 7808)
      • DevManView.exe (PID: 3976)
      • DevManView.exe (PID: 2384)
      • DevManView.exe (PID: 7260)
      • DevManView.exe (PID: 8144)
      • DevManView.exe (PID: 7928)
      • DevManView.exe (PID: 6192)
      • DevManView.exe (PID: 5056)
      • DevManView.exe (PID: 2852)
      • DevManView.exe (PID: 716)
      • DevManView.exe (PID: 3572)
      • DevManView.exe (PID: 6532)
      • DevManView.exe (PID: 6820)
      • DevManView.exe (PID: 8168)
      • DevManView.exe (PID: 4988)
      • DevManView.exe (PID: 4476)
      • DevManView.exe (PID: 7632)
      • DevManView.exe (PID: 7036)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 7276)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 8088)
      • DevManView.exe (PID: 7292)
      • DevManView.exe (PID: 8136)
      • DevManView.exe (PID: 4488)
      • DevManView.exe (PID: 8120)
      • DevManView.exe (PID: 7648)
      • DevManView.exe (PID: 3804)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 5988)
      • DevManView.exe (PID: 3016)
      • DevManView.exe (PID: 4560)
      • DevManView.exe (PID: 8124)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 668)
      • DevManView.exe (PID: 3992)
      • DevManView.exe (PID: 6904)
      • DevManView.exe (PID: 6456)
      • DevManView.exe (PID: 7268)
      • DevManView.exe (PID: 2980)
      • DevManView.exe (PID: 7572)
      • DevManView.exe (PID: 5508)
      • DevManView.exe (PID: 7592)
      • DevManView.exe (PID: 236)
      • DevManView.exe (PID: 6208)
      • DevManView.exe (PID: 7456)
      • DevManView.exe (PID: 7916)
      • DevManView.exe (PID: 7520)
      • DevManView.exe (PID: 7348)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 8016)
      • DevManView.exe (PID: 5892)
      • DevManView.exe (PID: 3396)
      • DevManView.exe (PID: 7892)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 7796)
      • DevManView.exe (PID: 6972)
      • DevManView.exe (PID: 2316)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 7600)
      • DevManView.exe (PID: 2344)
      • DevManView.exe (PID: 5044)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 2284)
      • DevManView.exe (PID: 896)
      • DevManView.exe (PID: 7780)
      • DevManView.exe (PID: 2896)
      • DevManView.exe (PID: 7536)
      • DevManView.exe (PID: 2236)
      • DevManView.exe (PID: 5176)
      • DevManView.exe (PID: 716)
      • DevManView.exe (PID: 6708)
      • DevManView.exe (PID: 5728)
      • DevManView.exe (PID: 4376)
      • DevManView.exe (PID: 6424)
      • DevManView.exe (PID: 7240)
      • DevManView.exe (PID: 5036)
      • DevManView.exe (PID: 7576)
      • DevManView.exe (PID: 7652)
      • DevManView.exe (PID: 7184)
      • DevManView.exe (PID: 7148)
      • DevManView.exe (PID: 5936)
      • DevManView.exe (PID: 3300)
      • DevManView.exe (PID: 7624)
      • DevManView.exe (PID: 7368)
      • DevManView.exe (PID: 484)
      • DevManView.exe (PID: 7196)
      • DevManView.exe (PID: 7952)
      • DevManView.exe (PID: 1348)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 3620)
      • DevManView.exe (PID: 7604)
      • DevManView.exe (PID: 6384)
      • DevManView.exe (PID: 4844)
      • DevManView.exe (PID: 7408)
      • DevManView.exe (PID: 5416)
      • DevManView.exe (PID: 7720)
      • DevManView.exe (PID: 7036)
      • DevManView.exe (PID: 3796)
      • DevManView.exe (PID: 6516)
      • DevManView.exe (PID: 2772)
      • DevManView.exe (PID: 7668)
      • DevManView.exe (PID: 7360)
      • DevManView.exe (PID: 516)
      • DevManView.exe (PID: 3156)
      • DevManView.exe (PID: 2268)
      • DevManView.exe (PID: 1176)
      • DevManView.exe (PID: 6612)
      • DevManView.exe (PID: 2244)
      • DevManView.exe (PID: 5720)
      • DevManView.exe (PID: 7692)
      • DevManView.exe (PID: 4012)
      • DevManView.exe (PID: 4108)
      • DevManView.exe (PID: 3140)
      • DevManView.exe (PID: 7820)
      • DevManView.exe (PID: 1600)
      • DevManView.exe (PID: 7892)
      • DevManView.exe (PID: 4152)
      • DevManView.exe (PID: 5512)
      • DevManView.exe (PID: 8064)
      • DevManView.exe (PID: 7488)
      • DevManView.exe (PID: 7804)
      • DevManView.exe (PID: 7568)
      • DevManView.exe (PID: 664)
      • DevManView.exe (PID: 7084)
      • DevManView.exe (PID: 7944)
      • DevManView.exe (PID: 4976)
      • DevManView.exe (PID: 6136)
      • DevManView.exe (PID: 6560)
      • DevManView.exe (PID: 6388)
      • DevManView.exe (PID: 6632)
      • DevManView.exe (PID: 7540)
      • DevManView.exe (PID: 7412)
      • DevManView.exe (PID: 7888)
      • DevManView.exe (PID: 7396)
      • DevManView.exe (PID: 7984)
      • DevManView.exe (PID: 6852)
      • DevManView.exe (PID: 2840)
      • DevManView.exe (PID: 6124)
      • DevManView.exe (PID: 832)
      • DevManView.exe (PID: 4280)
      • DevManView.exe (PID: 6148)
      • DevManView.exe (PID: 7852)
      • DevManView.exe (PID: 540)
      • DevManView.exe (PID: 7240)
      • DevManView.exe (PID: 2216)
      • DevManView.exe (PID: 7276)
      • DevManView.exe (PID: 7652)
      • DevManView.exe (PID: 3012)
      • DevManView.exe (PID: 6708)
      • DevManView.exe (PID: 5776)
      • DevManView.exe (PID: 4920)
      • DevManView.exe (PID: 1128)
      • DevManView.exe (PID: 2344)
      • DevManView.exe (PID: 7784)
      • DevManView.exe (PID: 5708)
      • DevManView.exe (PID: 2700)
      • DevManView.exe (PID: 2476)
      • DevManView.exe (PID: 4976)
      • DevManView.exe (PID: 7460)
      • DevManView.exe (PID: 3684)
      • DevManView.exe (PID: 908)
      • DevManView.exe (PID: 6216)
      • DevManView.exe (PID: 5740)
      • DevManView.exe (PID: 3024)
      • DevManView.exe (PID: 2108)
      • DevManView.exe (PID: 2408)
      • DevManView.exe (PID: 4244)
      • DevManView.exe (PID: 4308)
      • DevManView.exe (PID: 6456)
      • DevManView.exe (PID: 6072)
      • DevManView.exe (PID: 7792)
      • DevManView.exe (PID: 8140)
      • DevManView.exe (PID: 6512)
      • DevManView.exe (PID: 6960)
      • DevManView.exe (PID: 8132)
      • DevManView.exe (PID: 6256)
      • DevManView.exe (PID: 4016)
      • DevManView.exe (PID: 4180)
      • DevManView.exe (PID: 3800)
      • DevManView.exe (PID: 2284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.2)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2019:07:30 08:52:08+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware
PEType: PE32+
LinkerVersion: 2.5
CodeSize: 92672
InitializedDataSize: 6263296
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
941
Monitored processes
793
Malicious processes
7
Suspicious processes
4

Behavior graph

Click at the process to see the details
start THREAT masculineunban_early_beta.exe conhost.exe no specs cmd.exe no specs extd.exe no specs sppextcomobj.exe no specs extd.exe no specs slui.exe no specs extd.exe no specs reset2-hardware rescan after adapter reset.exe no specs conhost.exe no specs reg.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs cmd.exe no specs devcon.exe no specs powershell.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs findstr.exe no specs choice.exe no specs wmic.exe no specs extd.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs sc.exe no specs sc.exe no specs volumeid64.exe no specs applecleaner.exe cmd.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs cmd.exe no specs netsh.exe cmd.exe no specs netsh.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs nbtstat.exe no specs cmd.exe no specs nbtstat.exe no specs cmd.exe no specs arp.exe no specs cmd.exe no specs arp.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs slui.exe no specs slui.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs devicecleanupcmd.exe no specs conhost.exe no specs drivecleanup.exe no specs conhost.exe no specs ping.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs slui.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs rundll32.exe no specs slui.exe no specs Virtual Factory for Windows Defender Firewall Cpl no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs msedge.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs msedge.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs wmic.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs devmanview.exe no specs ping.exe no specs masculineunban_early_beta.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232""DevManView.exe /uninstall "WAN Miniport*" /use_wildcard""C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
236""DevManView.exe /uninstall "SCSI\Disk*" /use_wildcard""C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
236""DevManView.exe /uninstall "C:\"C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
240""DevManView.exe /uninstall "Standard*" /use_wildcard""C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
240""DevManView.exe /uninstall "disk"C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
300taskkill /f /im FortniteClient-Win64-Shipping.exe C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
300""DevManView.exe /uninstall "WAN Miniport*" /use_wildcard""C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
300""DevManView.exe /uninstall "ACPI\*" /use_wildcard""C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
420""DevManView.exe /uninstall "D:\"C:\Users\admin\AppData\Roaming\DevManView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Exit code:
0
Version:
1.76
Modules
Images
c:\users\admin\appdata\roaming\devmanview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
484C:\WINDOWS\system32\cmd.exe /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0012 /v NetworkAddress /t REG_SZ /d 000000000000 /f >nul 2>&1C:\Windows\System32\cmd.exeAppleCleaner.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
911 344
Read events
910 643
Write events
535
Delete events
166

Modification events

(PID) Process:(7548) reg.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Power
Operation:writeName:HiberbootEnabled
Value:
0
(PID) Process:(7920) Volumeid64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Sysinternals\VolumeID
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(7876) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7876) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7876) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8096) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(8096) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(8096) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(8096) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(8096) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
4A6CFFDBD8932F00
Executable files
26
Suspicious files
255
Text files
60
Unknown types
0

Dropped files

PID
Process
Filename
Type
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Local\Temp\BC0E.tmp\BC0F.tmp\extd.exeexecutable
MD5:C14CE13AB09B4829F67A879D735A10A1
SHA256:EF2699BA677FCDB8A3B70A711A59A5892D8439E108E3AC4D27A7F946C4D01A4A
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\cleanerOLD1.exeexecutable
MD5:59A7CE7A4D30E28E6BC356263693EB98
SHA256:390257A0360C025E42F0DB4C4826C3EA192E99A68C7AFCC548A8956F828F6379
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\dd.dllexecutable
MD5:CBE4163CAAB5AE09FA1E03B87B491380
SHA256:E982CB681DD366D5F83FA3C17C2E1929611479507C9247D063E47ACE0C971ACA
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\DeviceCleanupCmd.exeexecutable
MD5:030180CC1C3299E061D1B6F5B1754297
SHA256:878AAF3A5283F1403552909E42558FC24C90D8EEEB66527EAEDD8555F9E117C9
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\ddc.exeexecutable
MD5:97B963FD85FF4CC2A3B0DA8164593CFC
SHA256:AF219747072341760396D686F2FE7350EC2DCE713F1EC1977C21F8BE7B9197D5
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\AMIDEWINx64.EXEexecutable
MD5:F17ECF761E70FEB98C7F628857EEDFE7
SHA256:311F5C844746D4270B5B971CCEF8D74DDEDCA873EB45F34A1A55F1EA4A3BAFCF
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\moreCLEANhardware.exeexecutable
MD5:F0774075F208E06CB4FA5449720A9BCE
SHA256:D6624BDB30189E618CBCAF195A06CC6A20BAA114C727B301319864E8B3366A9E
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Local\Temp\BC0E.tmp\BC0F.tmp\BC10.battext
MD5:BC2ED860A1A9BF14ED3E76F9A6A43D21
SHA256:F5905687F5587F9A6E355A9F9CFCCF4308D17E64A358E255106D754635CAAA32
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\1-RUNFIRST.exeexecutable
MD5:6FBE881F1D6480E2E15D3EBE0F493D2D
SHA256:49B84540D5B4B8D2344C25EDB042E216592DD1DC78A5C00F2AD9457442C4581C
7204MasculineUnban_EARLY_BETA.exeC:\Users\admin\AppData\Roaming\Cleaner8.exeexecutable
MD5:3546548BE0B0940C52EC881D48404818
SHA256:DEC2A16531A09D05F1AE64A21C35D53CEC5998BE22C16A88B2E8B4A36878DB9A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
49
DNS requests
44
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4208
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4208
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5256
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 172.217.16.142
whitelisted
crl.microsoft.com
  • 23.216.77.21
  • 23.216.77.28
  • 23.216.77.22
  • 23.216.77.37
  • 23.216.77.8
  • 23.216.77.38
  • 23.216.77.35
  • 23.216.77.31
  • 23.216.77.15
whitelisted
www.microsoft.com
  • 69.192.161.161
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.129
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.128
  • 40.126.31.3
  • 20.190.159.73
  • 40.126.31.0
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
applecheats.cc
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.64.1
  • 104.21.48.1
  • 104.21.112.1
  • 104.21.32.1
  • 104.21.96.1
unknown
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted

Threats

PID
Process
Class
Message
5640
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
5640
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
5640
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5640
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5640
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
No debug info