File name:

Shift - Manuals_eq1bs.exe

Full analysis: https://app.any.run/tasks/a8d189cf-093d-45c5-8ab2-0948e9aaf072
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: December 11, 2024, 15:47:04
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

BEDEBC982FFC6A53BAC8378708BFDF4B

SHA1:

B6BEBF2F6FDC59F0EFD5EB475540602D121545CB

SHA256:

E513FF0A7568EC29FA809F87B69368B3FB3CA8096FBC1E8DA10B9BAB082C8360

SSDEEP:

98304:s+cD4dnHwICNdt3uwdN5hcQeXsQpZX5vEVpyQn6hHzwOeNO4SPvsm6Puq/GpBjNO:ErKaBb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • shift.exe (PID: 6068)
      • shift.exe (PID: 6788)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Shift - Manuals_eq1bs.exe (PID: 1576)
      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
      • Shift Setup_eq1bs.exe (PID: 5208)
      • Shift Setup_eq1bs.tmp (PID: 5696)
      • Shift - Manuals_eq1bs.exe (PID: 7140)
    • Reads the Windows owner or organization settings

      • Shift - Manuals_eq1bs.tmp (PID: 7160)
      • Shift - Manuals_eq1bs.tmp (PID: 1544)
    • There is functionality for taking screenshot (YARA)

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
    • Reads security settings of Internet Explorer

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Uses TASKKILL.EXE to kill process

      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 1744)
    • Process drops legitimate windows executable

      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Uses ICACLS.EXE to modify access control lists

      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Executes application which crashes

      • Shift Setup_eq1bs.tmp (PID: 5696)
      • shift.exe (PID: 6788)
    • Application launched itself

      • shift.exe (PID: 6068)
  • INFO

    • Create files in a temporary directory

      • Shift - Manuals_eq1bs.exe (PID: 1576)
      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
      • Shift Setup_eq1bs.tmp (PID: 5696)
      • shift.exe (PID: 6788)
    • Reads the computer name

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
      • Shift Setup_eq1bs.tmp (PID: 5696)
      • shift.exe (PID: 6788)
      • shift.exe (PID: 4052)
    • Checks supported languages

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift - Manuals_eq1bs.exe (PID: 1576)
      • Shift - Manuals_eq1bs.exe (PID: 7140)
      • Shift Setup_eq1bs.tmp (PID: 5696)
      • Shift Setup_eq1bs.exe (PID: 5208)
      • shift.exe (PID: 6068)
      • shift.exe (PID: 6764)
      • shift.exe (PID: 6900)
      • shift.exe (PID: 1572)
      • shift.exe (PID: 3296)
      • shift.exe (PID: 5400)
      • shift.exe (PID: 4816)
      • shift.exe (PID: 6276)
      • shift.exe (PID: 6432)
      • shift.exe (PID: 5964)
      • shift.exe (PID: 5472)
      • shift.exe (PID: 6208)
      • shift.exe (PID: 3884)
      • shift.exe (PID: 5316)
      • shift.exe (PID: 3364)
      • shift.exe (PID: 6184)
      • shift.exe (PID: 6420)
      • Shift - Manuals_eq1bs.tmp (PID: 7160)
    • Checks proxy server information

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • WerFault.exe (PID: 5460)
      • WerFault.exe (PID: 1580)
      • shift.exe (PID: 6068)
    • Process checks computer location settings

      • Shift - Manuals_eq1bs.tmp (PID: 1544)
      • Shift Setup_eq1bs.tmp (PID: 5696)
      • shift.exe (PID: 3884)
      • shift.exe (PID: 5316)
      • shift.exe (PID: 6184)
    • The process uses the downloaded file

      • Shift - Manuals_eq1bs.tmp (PID: 7160)
    • Reads the software policy settings

      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Creates files or folders in the user directory

      • Shift Setup_eq1bs.tmp (PID: 5696)
      • shift.exe (PID: 6764)
      • shift.exe (PID: 6068)
    • The sample compiled with english language support

      • Shift Setup_eq1bs.tmp (PID: 5696)
    • Reads Environment values

      • shift.exe (PID: 6068)
    • Sends debugging messages

      • shift.exe (PID: 5400)
    • Creates a software uninstall entry

      • Shift Setup_eq1bs.tmp (PID: 5696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 421888
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 127.8.0.0
ProductVersionNumber: 127.8.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shift
FileDescription: Shift Setup
FileVersion: 127.8.0
LegalCopyright: Copyright Shift. All rights reserved.
OriginalFileName:
ProductName: Shift
ProductVersion: 127.8.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
41
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start shift - manuals_eq1bs.exe shift - manuals_eq1bs.tmp shift - manuals_eq1bs.exe shift - manuals_eq1bs.tmp shift setup_eq1bs.exe shift setup_eq1bs.tmp taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs shift.exe shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe shift.exe no specs shift.exe no specs shift.exe no specs werfault.exe werfault.exe shift.exe no specs werfault.exe shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs shift.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1544"C:\Users\admin\AppData\Local\Temp\is-LE5JH.tmp\Shift - Manuals_eq1bs.tmp" /SL5="$60300,1489872,1164800,C:\Users\admin\Downloads\Shift - Manuals_eq1bs.exe" C:\Users\admin\AppData\Local\Temp\is-LE5JH.tmp\Shift - Manuals_eq1bs.tmp
Shift - Manuals_eq1bs.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-le5jh.tmp\shift - manuals_eq1bs.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1572"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=4156,i,16572842064983048419,8908021097678801589,262144 --variations-seed-version --mojo-platform-channel-handle=4168 /prefetch:2C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
127.8.0.1555
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\127.8.0.1555\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1576"C:\Users\admin\Downloads\Shift - Manuals_eq1bs.exe" C:\Users\admin\Downloads\Shift - Manuals_eq1bs.exe
explorer.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift Setup
Exit code:
0
Version:
127.8.0
Modules
Images
c:\users\admin\downloads\shift - manuals_eq1bs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1580\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1580C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5696 -s 2464C:\Windows\SysWOW64\WerFault.exe
Shift Setup_eq1bs.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1744"schtasks" /delete /tn ShiftLaunchTask /fC:\Windows\System32\schtasks.exeShift Setup_eq1bs.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"icacls" "C:\Users\admin\AppData\Local\Shift\chromium" /grant *S-1-15-3-1024-3424233489-972189580-2057154623-747635277-1604371224-316187997-3786583170-1043257646:(OI)(CI)(RX) /tC:\Windows\System32\icacls.exeShift Setup_eq1bs.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3296"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=4752,i,16572842064983048419,8908021097678801589,262144 --variations-seed-version --mojo-platform-channel-handle=4120 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
127.8.0.1555
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\127.8.0.1555\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
3364"C:\Users\admin\AppData\Local\Shift\chromium\shift.exe" --type=renderer --instant-process --enable-dinosaur-easter-egg-alt-images --start-stack-profiler --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=5456,i,16572842064983048419,8908021097678801589,262144 --variations-seed-version --mojo-platform-channel-handle=5476 /prefetch:1C:\Users\admin\AppData\Local\Shift\chromium\shift.exeshift.exe
User:
admin
Company:
Shift
Integrity Level:
LOW
Description:
Shift
Version:
127.8.0.1555
Modules
Images
c:\users\admin\appdata\local\shift\chromium\shift.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\shift\chromium\127.8.0.1555\shift_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
3524C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5696 -s 2464C:\Windows\SysWOW64\WerFault.exe
Shift Setup_eq1bs.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
15 723
Read events
15 631
Write events
91
Delete events
1

Modification events

(PID) Process:(7160) Shift - Manuals_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
3A9D6129356EDB642C748F1E4CF0AF1EE78A80715BFD19DCB8204387ECC5B3B4
(PID) Process:(7160) Shift - Manuals_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(7160) Shift - Manuals_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
F81B00002767530DE44BDB01
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:pv
Value:
127.8.0.1555
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift
Operation:writeName:EnterpriseProduct<{95fcf903-63b1-44bd-ab77-358a5bd30aae}_is1>
Value:
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CLASSES_ROOT\CLSID\{E797BF82-EFC0-4B94-A059-AA797B10D29C}\LocalServer32
Operation:writeName:ServerExecutable
Value:
C:\Users\admin\AppData\Local\Shift\chromium\127.8.0.1555\notification_helper.exe
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationDescription
Value:
Shift Browser
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability
Operation:writeName:ApplicationName
Value:
Shift Browser
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.htm
Value:
ShiftHTML
(PID) Process:(5696) Shift Setup_eq1bs.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Shift\Browser\Capability\FileAssociations
Operation:writeName:.html
Value:
ShiftHTML
Executable files
39
Suspicious files
354
Text files
294
Unknown types
149

Dropped files

PID
Process
Filename
Type
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-KSS51.tmp\is-NF71Q.tmp
MD5:
SHA256:
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-KSS51.tmp\Shift Setup.exe
MD5:
SHA256:
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup.exe
MD5:
SHA256:
7160Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\Shift Setup_eq1bs.exe
MD5:
SHA256:
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-KSS51.tmp\Win32Library.dllexecutable
MD5:D82B30898C428A7DBEE81CECEA520F68
SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198
5696Shift Setup_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-4Q02R.tmp\Win32Library.dllexecutable
MD5:D82B30898C428A7DBEE81CECEA520F68
SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198
1576Shift - Manuals_eq1bs.exeC:\Users\admin\AppData\Local\Temp\is-LE5JH.tmp\Shift - Manuals_eq1bs.tmpexecutable
MD5:54E4A0791B6EEA7C98FADB1185A0DEF5
SHA256:DF6334633D5FFCB426A601E57503FD0F9BBB3DB5B3229C7CA5FC5CC9069380C9
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-KSS51.tmp\min-rest.bmpimage
MD5:2484489C7443EC4745488A77ED084D80
SHA256:70B6921812F29B698F454927802DB818C1625402BAEFD53CED1BFB9135C17D5A
1544Shift - Manuals_eq1bs.tmpC:\Users\admin\AppData\Local\Temp\is-KSS51.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
7140Shift - Manuals_eq1bs.exeC:\Users\admin\AppData\Local\Temp\is-JQBFG.tmp\Shift - Manuals_eq1bs.tmpexecutable
MD5:54E4A0791B6EEA7C98FADB1185A0DEF5
SHA256:DF6334633D5FFCB426A601E57503FD0F9BBB3DB5B3229C7CA5FC5CC9069380C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
258
DNS requests
359
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6740
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6740
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6164
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7088
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqjryjt7u4rtmqdh7hterk4nrwq_2024.12.5.0/niikhdgajlphfehepabhhblakbdgeefj_2024.12.05.00_all_ecfpr7pro3eukvu6c4juxxpgoe.crx3
unknown
whitelisted
5460
WerFault.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5460
WerFault.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
372
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
1544
Shift - Manuals_eq1bs.tmp
3.17.117.110:443
attribution.shiftapis.com
AMAZON-02
US
unknown
1544
Shift - Manuals_eq1bs.tmp
3.20.96.32:443
updates.shiftapis.com
AMAZON-02
US
unknown
5064
SearchApp.exe
2.23.209.149:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
  • 23.48.23.156
  • 23.48.23.166
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.35.229.160
whitelisted
attribution.shiftapis.com
  • 3.17.117.110
  • 3.147.219.42
  • 18.189.246.163
unknown
updates.shiftapis.com
  • 3.20.96.32
  • 3.136.43.96
  • 3.146.213.231
unknown
www.bing.com
  • 2.23.209.149
  • 2.23.209.162
  • 2.23.209.156
  • 2.23.209.182
  • 2.23.209.158
  • 2.23.209.143
  • 2.23.209.161
  • 2.23.209.173
  • 2.23.209.175
  • 2.23.209.150
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.177
  • 2.23.209.185
  • 92.123.104.43
  • 92.123.104.37
  • 92.123.104.42
  • 92.123.104.41
  • 92.123.104.36
  • 92.123.104.39
  • 92.123.104.45
  • 92.123.104.38
  • 92.123.104.44
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.73
  • 20.190.159.71
  • 40.126.31.73
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
6764
shift.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
Process
Message
shift.exe
[1211/154823.757:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\Shift\User Data\Crashpad: The system cannot find the path specified. (0x3)