| File name: | ProtonVPN_win_v1.17.3.exe |
| Full analysis: | https://app.any.run/tasks/b4f81c25-25cf-46f9-9422-0edaa7ad68a6 |
| Verdict: | Malicious activity |
| Analysis date: | October 02, 2020, 20:10:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E646791ACB573A3145BC1D839DD0AF92 |
| SHA1: | D39D0251ECDB9BA7E1735C3972349C8D7DE9616F |
| SHA256: | E9B3592076E5DB50BC946A852EC289DF90F44E26191120F5944CD731485CEC94 |
| SSDEEP: | 393216:qB4h5YFJ/ofHnqTlHWluY1WeglCp+7XWATzazo8787iHgwk:I4hsSfHneHCuY1Wgp+7X/zM7esgwk |
| .exe | | | Win32 EXE PECompact compressed (generic) (53.4) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (35.5) |
| .exe | | | Win32 Executable (generic) (5.8) |
| .exe | | | Generic Win/DOS Executable (2.5) |
| .exe | | | DOS Executable Generic (2.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:04:27 15:06:19+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.25 |
| CodeSize: | 1515008 |
| InitializedDataSize: | 596480 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1205cc |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.17.3.0 |
| ProductVersionNumber: | 1.17.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Proton Technologies AG |
| FileDescription: | ProtonVPN Installer f44b0e4e |
| FileVersion: | 1.17.3 |
| InternalName: | ProtonVPN_win_v1.17.3 |
| LegalCopyright: | Copyright (C) 2020 Proton Technologies AG |
| OriginalFileName: | ProtonVPN_win_v1.17.3.exe |
| ProductName: | ProtonVPN |
| ProductVersion: | 1.17.3 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 27-Apr-2020 13:06:19 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Proton Technologies AG |
| FileDescription: | ProtonVPN Installer f44b0e4e |
| FileVersion: | 1.17.3 |
| InternalName: | ProtonVPN_win_v1.17.3 |
| LegalCopyright: | Copyright (C) 2020 Proton Technologies AG |
| OriginalFileName: | ProtonVPN_win_v1.17.3.exe |
| ProductName: | ProtonVPN |
| ProductVersion: | 1.17.3 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 27-Apr-2020 13:06:19 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00171D3F | 0x00171E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.45128 |
.rdata | 0x00173000 | 0x0005D87C | 0x0005DA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.61049 |
.data | 0x001D1000 | 0x00006CF0 | 0x00005400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.05514 |
.rsrc | 0x001D8000 | 0x000153E0 | 0x00015400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.79618 |
.reloc | 0x001EE000 | 0x00019664 | 0x00019800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.55644 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.18998 | 1909 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.2982 | 2440 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 5.19797 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.93168 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 7.96069 | 17118 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 3.37783 | 1116 | Latin 1 / Western European | English - United States | RT_STRING |
10 | 3.35254 | 1888 | Latin 1 / Western European | English - United States | RT_STRING |
11 | 3.31743 | 760 | Latin 1 / Western European | English - United States | RT_STRING |
12 | 3.23118 | 1432 | Latin 1 / Western European | English - United States | RT_STRING |
13 | 3.35766 | 820 | Latin 1 / Western European | English - United States | RT_STRING |
KERNEL32.dll |
msi.dll (delay-loaded) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Users\admin\AppData\Local\Temp\ProtonVPN_win_v1.17.3.exe" | C:\Users\admin\AppData\Local\Temp\ProtonVPN_win_v1.17.3.exe | explorer.exe | ||||||||||||
User: admin Company: Proton Technologies AG Integrity Level: HIGH Description: ProtonVPN Installer f44b0e4e Exit code: 0 Version: 1.17.3 Modules
| |||||||||||||||
| 1840 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2060 | cmd /c ""C:\Users\admin\AppData\Local\Temp\{283F9E05-90FB-4E8F-B0A0-38324927385B}\check-KB3033929.bat" " | C:\Windows\system32\cmd.exe | — | ProtonVPN_win_v1.17.3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2228 | wmic qfe get hotfixid | C:\Windows\System32\Wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2712 | wmic qfe get hotfixid | C:\Windows\System32\Wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2924 | cmd /c ""C:\Users\admin\AppData\Local\Temp\{283F9E05-90FB-4E8F-B0A0-38324927385B}\check-KB2992611.bat" " | C:\Windows\system32\cmd.exe | — | ProtonVPN_win_v1.17.3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2948 | "C:\Users\admin\AppData\Local\Temp\ProtonVPN_win_v1.17.3.exe" | C:\Users\admin\AppData\Local\Temp\ProtonVPN_win_v1.17.3.exe | — | explorer.exe | |||||||||||
User: admin Company: Proton Technologies AG Integrity Level: MEDIUM Description: ProtonVPN Installer f44b0e4e Exit code: 3221226540 Version: 1.17.3 Modules
| |||||||||||||||
| 3004 | FindStr "KB3033929 KB4019264 KB4022719 KB4025341 KB4034664 KB4038777 KB4041681 KB4343900 KB4457144 KB4462923 KB4467107 KB4471318 KB4480970 KB4486563 KB4489878 KB4474419 KB4493472 KB4499164 KB4499175 KB4503292 KB4503269 KB4507449 KB4507456 KB4512506 KB4516065 KB4519976 KB4524157 KB4015549 KB3197868 KB3185330" | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3172 | C:\Windows\system32\MsiExec.exe -Embedding E1857671E97DBAD089DD294EB03185D7 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3328 | FindStr "KB2992611" | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 |
| Operation: | write | Name: | Blob |
Value: 04000000010000001000000087CE0B7B2A0E4900E158719B37A893720F00000001000000140000006DCA5BD00DCF1C0F327059D374B29CA6E3C50AA60300000001000000140000000563B8630D62D75ABBC8AB1E4BDFB5A899B24D431D00000001000000100000004F5F106930398D09107B40C3C7CA8F1C0B000000010000001200000044006900670069004300650072007400000014000000010000001400000045EBA2AFF492CB82312D518BA7A7219DF36DC80F6200000001000000200000003E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308190000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000BB030000308203B73082029FA00302010202100CE7E0E517D846FE8FE560FC1BF03039300D06092A864886F70D01010505003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3036313131303030303030305A170D3331313131303030303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AD0E15CEE443805CB187F3B760F97112A5AEDC269488AAF4CEF520392858600CF880DAA9159532613CB5B128848A8ADC9F0A0C83177A8F90AC8AE779535C31842AF60F98323676CCDEDD3CA8A2EF6AFB21F25261DF9F20D71FE2B1D9FE1864D2125B5FF9581835BC47CDA136F96B7FD4B0383EC11BC38C33D9D82F18FE280FB3A783D6C36E44C061359616FE599C8B766DD7F1A24B0D2BFF0B72DA9E60D08E9035C678558720A1CFE56D0AC8497C3198336C22E987D0325AA2BA138211ED39179D993A72A1E6FAA4D9D5173175AE857D22AE3F014686F62879C8B1DAE45717C47E1C0EB0B492A656B3BDB297EDAAA7F0B7C5A83F9516D0FFA196EB085F18774F0203010001A3633061300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041445EBA2AFF492CB82312D518BA7A7219DF36DC80F301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010505000382010100A20EBCDFE2EDF0E372737A6494BFF77266D832E4427562AE87EBF2D5D9DE56B39FCCCE1428B90D97605C124C58E4D33D834945589735691AA847EA56C679AB12D8678184DF7F093C94E6B8262C20BD3DB32889F75FFF22E297841FE965EF87E0DFC16749B35DEBB2092AEB26ED78BE7D3F2BF3B726356D5F8901B6495B9F01059BAB3D25C1CCB67FC2F16F86C6FA6468EB812D94EB42B7FA8C1EDD62F1BE5067B76CBDF3F11F6B0C3607167F377CA95B6D7AF112466083D72704BE4BCE97BEC3672A6811DF80E70C3366BF130D146EF37F1F63101EFA8D1B256D6C8FA5B76101B1D2A326A110719DADE2C3F9C39951B72B0708CE2EE650B2A7FA0A452FA2F0F2 | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0280F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA9531400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B5300000001000000230000003021301F06092B06010401A032010130123010060A2B0601040182373C0101030200C00B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B06010505070307190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F2000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (556) ProtonVPN_win_v1.17.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\{283F9E05-90FB-4E8F-B0A0-38324927385B}\holder0.aiph | — | |
MD5:— | SHA256:— | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\{283F9E05-90FB-4E8F-B0A0-38324927385B}\927385B\ProtonVPN_win_v1.17.3.msi | — | |
MD5:— | SHA256:— | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\MSI9443.tmp | — | |
MD5:— | SHA256:— | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_556\TapInstaller.CA.dll | executable | |
MD5:— | SHA256:— | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_556\ProtonVPN.InstallActions.dll | executable | |
MD5:— | SHA256:— | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_556\New | image | |
MD5:C23CBF002D82192481B61ED7EC0890F4 | SHA256:4F92E804A11453382EBFF7FB0958879BAE88FE3366306911DEC9D811CD306EED | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_556\completi | image | |
MD5:45B0E074F96A859ADAE198187AB9FA11 | SHA256:050282E679AC80F6A357FFF92F1E7A95D30A06B35247E25CBFD2DD8CEEE1A412 | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_556\removico | image | |
MD5:20D25E871A244B94574C47726DE745D6 | SHA256:88DD7EE9FA22ECDBDC6B3D47DB83BC3D72360AEB43588E6A9A008B224389CB1C | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\{283F9E05-90FB-4E8F-B0A0-38324927385B}\decoder.dll | executable | |
MD5:FC136D5C16573D1D1A64B0A62B586235 | SHA256:5A12236A02BA2984B62D7ACFE5AFB048E461FC4C76989D055FFE8965F212EBBF | |||
| 556 | ProtonVPN_win_v1.17.3.exe | C:\Users\admin\AppData\Local\Temp\Cab33A2.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
556 | ProtonVPN_win_v1.17.3.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
556 | ProtonVPN_win_v1.17.3.exe | 104.108.144.114:443 | download.microsoft.com | TOT Public Company Limited | US | unknown |
556 | ProtonVPN_win_v1.17.3.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| shared |
ocsp.digicert.com |
| whitelisted |
Process | Message |
|---|---|
ProtonVPN_win_v1.17.3.exe | DBGHELP: Symbol Search Path: .
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: SymSrv load failure: symsrv.dll
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: Symbol Search Path: C:\Users\admin\AppData\Local\Temp
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb - file not found
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: C:\Users\admin\AppData\Local\Temp\exe\ExternalUi.pdb - file not found
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb - file not found
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: Symbol Search Path: C:\Users\admin\AppData\Local\Temp
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: ProtonVPN_win_v1.17.3 - no symbols loaded
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: ProtonVPN_win_v1.17.3 - no symbols loaded
|
ProtonVPN_win_v1.17.3.exe | DBGHELP: C:\Users\admin\AppData\Local\Temp\exe\ExternalUi.pdb - file not found
|