File name:

BootstrapperV1.22.exe

Full analysis: https://app.any.run/tasks/b069a8fa-54a8-4a6a-b87a-fae05f3b70c7
Verdict: Malicious activity
Analysis date: October 20, 2024, 13:27:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
arch-doc
arch-scr
arch-exec
pastebin
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows
MD5:

2A4DCF20B82896BE94EB538260C5FB93

SHA1:

21F232C2FD8132F8677E53258562AD98B455E679

SHA256:

EBBCB489171ABFCFCE56554DBAEACD22A15838391CBC7C756DB02995129DEF5A

SSDEEP:

6144:LQ3tXkS2NIikH1izJZ3e82Zavp/ijHrGEW1IhThuENaDffKTghOpDozwKdVuaQ:LiMIikViCocauhu6TghOpDkwKdw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 5172)
    • Starts CMD.EXE for commands execution

      • BootstrapperV1.22.exe (PID: 6224)
    • Uses WMIC.EXE to obtain information about the network interface controller

      • cmd.exe (PID: 3648)
    • Reads security settings of Internet Explorer

      • BootstrapperV1.22.exe (PID: 6224)
      • msiexec.exe (PID: 612)
    • Reads the date of Windows installation

      • BootstrapperV1.22.exe (PID: 6224)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6176)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6176)
    • Executable content was dropped or overwritten

      • BootstrapperV1.22.exe (PID: 6224)
      • MicrosoftEdgeUpdate.exe (PID: 2652)
      • RobloxPlayerInstaller.exe (PID: 1048)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7084)
    • The process drops C-runtime libraries

      • BootstrapperV1.22.exe (PID: 6224)
      • RobloxPlayerInstaller.exe (PID: 1048)
    • Process drops legitimate windows executable

      • BootstrapperV1.22.exe (PID: 6224)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7084)
      • MicrosoftEdgeUpdate.exe (PID: 2652)
      • RobloxPlayerInstaller.exe (PID: 1048)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2652)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 2652)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 4112)
      • MicrosoftEdgeUpdate.exe (PID: 4136)
    • Uses WEVTUTIL.EXE to install publishers and event logs from the manifest

      • msiexec.exe (PID: 3004)
      • wevtutil.exe (PID: 5508)
    • Executes application which crashes

      • Solara.exe (PID: 7752)
  • INFO

    • Reads the computer name

      • BootstrapperV1.22.exe (PID: 6224)
      • msiexec.exe (PID: 6176)
      • msiexec.exe (PID: 1700)
      • msiexec.exe (PID: 612)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 6720)
      • Taskmgr.exe (PID: 3156)
    • Disables trace logs

      • BootstrapperV1.22.exe (PID: 6224)
    • Checks supported languages

      • BootstrapperV1.22.exe (PID: 6224)
      • msiexec.exe (PID: 6176)
      • msiexec.exe (PID: 1700)
      • msiexec.exe (PID: 612)
    • Reads the software policy settings

      • msiexec.exe (PID: 6176)
      • BootstrapperV1.22.exe (PID: 6224)
    • Checks proxy server information

      • BootstrapperV1.22.exe (PID: 6224)
    • Reads the machine GUID from the registry

      • BootstrapperV1.22.exe (PID: 6224)
      • msiexec.exe (PID: 6176)
    • Reads Environment values

      • BootstrapperV1.22.exe (PID: 6224)
    • Create files in a temporary directory

      • BootstrapperV1.22.exe (PID: 6224)
    • Process checks computer location settings

      • BootstrapperV1.22.exe (PID: 6224)
    • The process uses the downloaded file

      • BootstrapperV1.22.exe (PID: 6224)
    • Manual execution by a user

      • Taskmgr.exe (PID: 6708)
      • Taskmgr.exe (PID: 3156)
      • msedge.exe (PID: 4312)
      • MicrosoftEdgeUpdateCore.exe (PID: 6204)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4312)
      • msiexec.exe (PID: 6176)
      • msedge.exe (PID: 5172)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6176)
    • Application launched itself

      • msiexec.exe (PID: 6176)
      • msedge.exe (PID: 4312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:10:04 22:29:32+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 816640
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0xc949a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows command line
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: SolaraBootstrapper
FileVersion: 1.0.0.0
InternalName: SolaraBootstrapper.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: SolaraBootstrapper.exe
ProductName: SolaraBootstrapper
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
360
Monitored processes
96
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bootstrapperv1.22.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs taskmgr.exe no specs taskmgr.exe sppextcomobj.exe no specs slui.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs robloxplayerinstaller.exe msedge.exe no specs msiexec.exe no specs wevtutil.exe no specs conhost.exe no specs wevtutil.exe no specs solara.exe werfault.exe robloxplayerinstaller.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wermgr.exe no specs plugscheduler.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdatecore.exe no specs microsoftedgeupdate.exe no specs bootstrapperv1.22.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
608ipconfig /allC:\Windows\System32\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
612C:\Windows\syswow64\MsiExec.exe -Embedding 59017A4EB88F533845B4257B0FCE1E23C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
780"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=32 --mojo-platform-channel-handle=7936 --field-trial-handle=2408,i,6947662047898109269,7090722023529626518,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1048"C:\Users\admin\Downloads\RobloxPlayerInstaller.exe" C:\Users\admin\Downloads\RobloxPlayerInstaller.exe
msedge.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
1073807364
Version:
1, 6, 0, 6470717
Modules
Images
c:\users\admin\downloads\robloxplayerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\comctl32.dll
c:\windows\syswow64\msvcrt.dll
1280"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8816 --field-trial-handle=2408,i,6947662047898109269,7090722023529626518,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1700C:\Windows\System32\MsiExec.exe -Embedding 9F7B9EEFC2F8C366505778693AB02F19C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7588 --field-trial-handle=2408,i,6947662047898109269,7090722023529626518,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2236"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.171.39\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
2416"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3520 --field-trial-handle=2408,i,6947662047898109269,7090722023529626518,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2652C:\Users\admin\AppData\Local\Temp\EU5638.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU5638.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
1073807364
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\temp\eu5638.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
Total events
32 725
Read events
29 588
Write events
3 074
Delete events
63

Modification events

(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6224) BootstrapperV1.22.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperV1_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
259
Suspicious files
1 581
Text files
2 343
Unknown types
7

Dropped files

PID
Process
Filename
Type
6224BootstrapperV1.22.exeC:\Users\admin\AppData\Local\Temp\node-v18.16.0-x64.msi
MD5:
SHA256:
6176msiexec.exeC:\Windows\Installer\904d6.msi
MD5:
SHA256:
6176msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5binary
MD5:CCC43D30FB2436BB67BF9A93E2254A1B
SHA256:557CCC4FFF7582926907DB722DDE886271640B7AFE61AD737651EAB2B501B117
6176msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5binary
MD5:ED6E1CD67298339D2B6A17F5CD6ABC2A
SHA256:DD2AFC0DB6BD3DE82322FC16D034A81A295E6E106A29C1DBEA8487161F7C02BF
6176msiexec.exeC:\Program Files\nodejs\corepack.cmdtext
MD5:C046E14548EBB384EF71C0EFEA0E857A
SHA256:920630A1D1EC47AEDEA7345E3C868ECDC07E191373497BBF47FBBF5942FBAD4F
3156Taskmgr.exeC:\Users\admin\AppData\Local\D3DSCache\ecbf0d5a3a180bb\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.locktext
MD5:F49655F856ACB8884CC0ACE29216F511
SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA
6176msiexec.exeC:\Windows\Temp\~DFBA2EDDE15DFBCD3C.TMPbinary
MD5:8B2180139D07EE1654DB63CC5ABF3B13
SHA256:2CA2219186412AB5796446248CA110E734A695D6E12B1856BF236A6033ADBA46
6176msiexec.exeC:\Windows\Installer\MSI2536.tmpexecutable
MD5:7A86CE1A899262DD3C1DF656BFF3FB2C
SHA256:B8F2D0909D7C2934285A8BE010D37C0609C7854A36562CBFCBCE547F4F4C7B0C
6176msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:8B2180139D07EE1654DB63CC5ABF3B13
SHA256:2CA2219186412AB5796446248CA110E734A695D6E12B1856BF236A6033ADBA46
6176msiexec.exeC:\Windows\Installer\MSI1620.tmpexecutable
MD5:7A86CE1A899262DD3C1DF656BFF3FB2C
SHA256:B8F2D0909D7C2934285A8BE010D37C0609C7854A36562CBFCBCE547F4F4C7B0C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
243
DNS requests
119
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6176
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAOO2y%2FG5AVzGnYPFRYUTIU%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6176
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.23.176.163:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1500
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1500
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6808
svchost.exe
HEAD
200
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1729821457&P2=404&P3=2&P4=FDSE7a2KzhuP%2bnyRx2CoB46lGJTE95RPsDhYhloDKeZrRtVQbKmVJF4Edw4eWV%2bDHETrnGOZLqQRWQ749ke6tg%3d%3d
unknown
whitelisted
1112
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4080
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2172
svchost.exe
224.0.0.251:5353
unknown
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2172
svchost.exe
224.0.0.252:5355
whitelisted
6224
BootstrapperV1.22.exe
104.21.93.27:443
getsolara.dev
CLOUDFLARENET
malicious
6944
svchost.exe
2.23.176.163:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 2.16.204.142
  • 2.16.204.155
  • 2.16.204.134
  • 2.16.204.150
  • 2.16.204.160
  • 2.16.204.146
  • 2.16.204.157
  • 2.16.204.153
  • 2.16.204.143
whitelisted
google.com
  • 142.250.186.174
whitelisted
getsolara.dev
  • 104.21.93.27
  • 172.67.203.125
malicious
crl.microsoft.com
  • 2.23.176.163
  • 2.23.176.189
whitelisted
www.microsoft.com
  • 2.16.253.202
  • 2.23.181.156
whitelisted
clientsettings.roblox.com
  • 128.116.123.4
whitelisted
www.nodejs.org
  • 104.20.22.46
  • 104.20.23.46
whitelisted
nodejs.org
  • 104.20.22.46
  • 104.20.23.46
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 2.16.204.153
  • 2.16.204.148
  • 2.16.204.135
  • 2.16.204.142
  • 2.16.204.141
  • 2.16.204.150
  • 2.16.204.146
  • 2.16.204.143
  • 2.16.204.138
  • 2.16.204.157
  • 2.16.204.160
  • 2.16.204.145
  • 2.16.204.149
  • 2.16.204.139
  • 2.16.204.151
  • 2.16.204.159
  • 2.16.204.134
  • 2.16.204.161
  • 2.16.204.156
  • 2.16.204.155
whitelisted

Threats

PID
Process
Class
Message
5892
msedge.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
2172
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
2172
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Online Pastebin Text Storage
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.