File name:

diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe

Full analysis: https://app.any.run/tasks/a943ad79-0c19-4e6c-a8ff-af5dd4f7d790
Verdict: Malicious activity
Analysis date: February 03, 2025, 19:15:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

53E8BA5D0383C919E1318FB44435CA6C

SHA1:

33A36729AD0F1846D3602CD7CD73E546277C545C

SHA256:

EDF957AD742B7BFC1EE764DD477053B1C33D251CA14F1EDA711EE10D71E65480

SSDEEP:

98304:tyRr3UJ1IqsdPDMJoPvpyUwyFgS8S7ce/Unba+O+CB3jD9hlw:5L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • saBSI.exe (PID: 5712)
      • saBSI.exe (PID: 6004)
    • Executable content was dropped or overwritten

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_setup.exe (PID: 5684)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • diner-dash-flo-on-the-go-0-installer.exe (PID: 3152)
      • saBSI.exe (PID: 6004)
      • saBSI.exe (PID: 5712)
      • DinerDashFloOnTheGoSetup26342.exe (PID: 5300)
      • icarus.exe (PID: 1224)
      • is-A5S6N.tmp (PID: 848)
      • icarus.exe (PID: 7108)
    • Checks Windows Trust Settings

      • saBSI.exe (PID: 6004)
      • saBSI.exe (PID: 5712)
    • The process verifies whether the antivirus software is installed

      • saBSI.exe (PID: 5712)
      • icarus.exe (PID: 7108)
    • Adds/modifies Windows certificates

      • saBSI.exe (PID: 6004)
    • Process drops legitimate windows executable

      • is-A5S6N.tmp (PID: 848)
      • icarus.exe (PID: 7108)
    • Starts itself from another location

      • icarus.exe (PID: 1224)
    • There is functionality for taking screenshot (YARA)

      • avg_antivirus_free_setup.exe (PID: 5684)
    • The process drops C-runtime libraries

      • icarus.exe (PID: 7108)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 7108)
  • INFO

    • The sample compiled with english language support

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_setup.exe (PID: 5684)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • diner-dash-flo-on-the-go-0-installer.exe (PID: 3152)
      • saBSI.exe (PID: 6004)
      • DinerDashFloOnTheGoSetup26342.exe (PID: 5300)
      • is-A5S6N.tmp (PID: 848)
      • icarus.exe (PID: 1224)
      • icarus.exe (PID: 7108)
    • Reads the machine GUID from the registry

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_setup.exe (PID: 5684)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • saBSI.exe (PID: 6004)
      • saBSI.exe (PID: 5712)
      • icarus.exe (PID: 1224)
      • icarus.exe (PID: 7108)
    • Checks supported languages

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • saBSI.exe (PID: 6004)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • diner-dash-flo-on-the-go-0-installer.exe (PID: 3152)
      • is-A5S6N.tmp (PID: 848)
      • saBSI.exe (PID: 5712)
      • icarus.exe (PID: 1224)
      • icarus.exe (PID: 7108)
      • icarus.exe (PID: 7104)
    • Reads the software policy settings

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • saBSI.exe (PID: 5712)
      • saBSI.exe (PID: 6004)
    • Reads the computer name

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • saBSI.exe (PID: 6004)
      • avg_antivirus_free_setup.exe (PID: 5684)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • diner-dash-flo-on-the-go-0-installer.exe (PID: 3152)
      • is-A5S6N.tmp (PID: 848)
      • saBSI.exe (PID: 5712)
      • icarus.exe (PID: 1224)
      • icarus.exe (PID: 7104)
    • Checks proxy server information

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • saBSI.exe (PID: 6004)
      • saBSI.exe (PID: 5712)
    • Creates files in the program directory

      • saBSI.exe (PID: 6004)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • diner-dash-flo-on-the-go-0-installer.exe (PID: 3152)
      • icarus.exe (PID: 1224)
      • is-A5S6N.tmp (PID: 848)
      • icarus.exe (PID: 7108)
    • Create files in a temporary directory

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
      • avg_antivirus_free_online_setup.exe (PID: 6208)
      • DinerDashFloOnTheGoSetup26342.exe (PID: 5300)
      • saBSI.exe (PID: 5712)
      • is-A5S6N.tmp (PID: 848)
    • Process checks computer location settings

      • diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe (PID: 6708)
    • Reads CPU info

      • icarus.exe (PID: 7104)
      • icarus.exe (PID: 7108)
    • The sample compiled with czech language support

      • icarus.exe (PID: 7108)
    • Reads Environment values

      • icarus.exe (PID: 7108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:14 12:00:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 2145792
InitializedDataSize: 2305536
UninitializedDataSize: -
EntryPoint: 0x1c2253
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.9.1
ProductVersionNumber: 3.0.9.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Softonic
FileDescription: Softonic
FileVersion: 3.0.9.1
LegalCopyright: (c) Softonic. All rights reserved.
ProductName: Softonic
ProductVersion: 3.0.9.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
12
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start diner-dash-flo-on-the-go-0-installer_xf-m0p1.exe sabsi.exe avg_antivirus_free_setup.exe avg_antivirus_free_online_setup.exe diner-dash-flo-on-the-go-0-installer.exe sabsi.exe dinerdashfloonthegosetup26342.exe is-a5s6n.tmp icarus.exe icarus.exe no specs icarus.exe diner-dash-flo-on-the-go-0-installer_xf-m0p1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Users\admin\AppData\Local\Temp\is-JI7U5.tmp\is-A5S6N.tmp" /SL4 $C02C2 C:\Users\admin\AppData\Local\Temp\DinerDashFloOnTheGoSetup26342.exe 10564476 51200 ""C:\Users\admin\AppData\Local\Temp\is-JI7U5.tmp\is-A5S6N.tmp
DinerDashFloOnTheGoSetup26342.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.34.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ji7u5.tmp\is-a5s6n.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1224C:\WINDOWS\Temp\asw-b775835f-bf74-4079-86d6-1c2930d60e9d\common\icarus.exe /icarus-info-path:C:\WINDOWS\Temp\asw-b775835f-bf74-4079-86d6-1c2930d60e9d\icarus-info.xml /install /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llSpYRKd8PSkORjj /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\WINDOWS\Temp\asw.fd76dcb28cfdec55 /track-guid:bc2da3f7-0e91-43ba-aa75-7cbc49946edcC:\Windows\Temp\asw-b775835f-bf74-4079-86d6-1c2930d60e9d\common\icarus.exe
avg_antivirus_free_online_setup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw-b775835f-bf74-4079-86d6-1c2930d60e9d\common\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\ucrtbase.dll
3152"C:\Users\admin\Downloads\diner-dash-flo-on-the-go-0-installer.exe" C:\Users\admin\Downloads\diner-dash-flo-on-the-go-0-installer.exe
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\downloads\diner-dash-flo-on-the-go-0-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5300"C:\Users\admin\AppData\Local\Temp\DinerDashFloOnTheGoSetup26342.exe" ""C:\Users\admin\AppData\Local\Temp\DinerDashFloOnTheGoSetup26342.exe
diner-dash-flo-on-the-go-0-installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Diner Dash Flo On The Go Setup
Version:
Modules
Images
c:\users\admin\appdata\local\temp\dinerdashfloonthegosetup26342.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5684"C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\avg_antivirus_free_setup.exe" /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llSpYRKd8PSkORjjC:\Users\admin\AppData\Local\Temp\ISV713B.tmp\avg_antivirus_free_setup.exe
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
User:
admin
Company:
AVG Technologies CZ, s.r.o.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\isv713b.tmp\avg_antivirus_free_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5712"C:\ProgramData\McAfee\WebAdvisor\saBSI\saBSI.exe" /install /affid {aflt} PaidDistribution=true saBsiVersion=4.1.1.865 CountryCode=US /no_self_updateC:\ProgramData\McAfee\WebAdvisor\saBSI\saBSI.exe
saBSI.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
0
Version:
4,1,1,1006
Modules
Images
c:\programdata\mcafee\webadvisor\sabsi\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6004"C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.exe" /affid {aflt} PaidDistribution=true CountryCode=USC:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.exe
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
0
Version:
4,1,1,865
Modules
Images
c:\users\admin\appdata\local\temp\isv713b.tmp\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6208"C:\WINDOWS\Temp\asw.fd76dcb28cfdec55\avg_antivirus_free_online_setup.exe" /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llSpYRKd8PSkORjj /cookie:mmm_irs_ppi_902_451_o /ga_clientid:bc2da3f7-0e91-43ba-aa75-7cbc49946edc /edat_dir:C:\WINDOWS\Temp\asw.fd76dcb28cfdec55C:\Windows\Temp\asw.fd76dcb28cfdec55\avg_antivirus_free_online_setup.exe
avg_antivirus_free_setup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Self-Extract Package
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw.fd76dcb28cfdec55\avg_antivirus_free_online_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6544"C:\Users\admin\AppData\Local\Temp\diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe" C:\Users\admin\AppData\Local\Temp\diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeexplorer.exe
User:
admin
Company:
Softonic
Integrity Level:
MEDIUM
Description:
Softonic
Exit code:
3221226540
Version:
3.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\diner-dash-flo-on-the-go-0-installer_xf-m0p1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6708"C:\Users\admin\AppData\Local\Temp\diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe" C:\Users\admin\AppData\Local\Temp\diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
explorer.exe
User:
admin
Company:
Softonic
Integrity Level:
HIGH
Description:
Softonic
Exit code:
0
Version:
3.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\diner-dash-flo-on-the-go-0-installer_xf-m0p1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
8 942
Read events
8 920
Write events
19
Delete events
3

Modification events

(PID) Process:(6708) diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E907020001000300130010000500B101010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(6708) diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000002E2461127076DB01
(PID) Process:(6004) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:UUID
Value:
{70718B72-1111-433A-8309-8743722337D4}
(PID) Process:(6004) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallerFlags
Value:
1
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:8C5CFDF4-AB05-4EB0-8EF6-7B4620DC2CF3
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAIV3hJgpU4kemmHGPypDnGQQAAAACAAAAAAAQZgAAAAEAACAAAAB4m903uQ4xyAekNEs1jBtndIlkfkoKFCMu3+lBMVil1AAAAAAOgAAAAAIAACAAAADdSc2nor1Fr6av/l/K8AiLcwRzugix5YTvMU0Qt1wDw1AAAAAkh7pdoU4bRj9tDXuNDbKEPNkSYWIKPC7OYnRadFwlgmjEGyles68RM/7BL2zoPxmKDq0T7W0IDZvSknOqfoIRtUf4OjFeWunjd9fwQXLF3UAAAAAsCOmd+lK0KPjGr+H/cnhHHP2fWcfHWukHnOtjDa+TxL8plRHJ7moZIN0mhBv3tOQj2Gm0g6ElF2alRXtLhjts
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:5E1D6A55-0134-486E-A166-38C2E4919BB1
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAIV3hJgpU4kemmHGPypDnGQQAAAACAAAAAAAQZgAAAAEAACAAAAB4m903uQ4xyAekNEs1jBtndIlkfkoKFCMu3+lBMVil1AAAAAAOgAAAAAIAACAAAADdSc2nor1Fr6av/l/K8AiLcwRzugix5YTvMU0Qt1wDw1AAAAAkh7pdoU4bRj9tDXuNDbKEPNkSYWIKPC7OYnRadFwlgmjEGyles68RM/7BL2zoPxmKDq0T7W0IDZvSknOqfoIRtUf4OjFeWunjd9fwQXLF3UAAAAAsCOmd+lK0KPjGr+H/cnhHHP2fWcfHWukHnOtjDa+TxL8plRHJ7moZIN0mhBv3tOQj2Gm0g6ElF2alRXtLhjts
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:144807F0-DE37-4C62-9C05-EB4CC64A7A2F
Value:
ff3f0dde-4533-49ca-98ea-85985b3b3593
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:56C7A9DA-4B11-406A-8B1A-EFF157C294D6
Value:
ff3f0dde-4533-49ca-98ea-85985b3b3593
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:5FD38555-4B16-40AE-9A09-E2C969CB74AF
Value:
F6D4F52220BB5A3D7246A004278BB23F
(PID) Process:(6208) avg_antivirus_free_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:7CCD586D-2ABC-42FF-A23B-3731F4F183D9
Value:
F6D4F52220BB5A3D7246A004278BB23F
Executable files
298
Suspicious files
337
Text files
208
Unknown types
0

Dropped files

PID
Process
Filename
Type
5684avg_antivirus_free_setup.exeC:\Windows\Temp\asw.fd76dcb28cfdec55\avg_antivirus_free_online_setup.exeexecutable
MD5:6EBB043BC04784DBC6DF3F4C52391CD0
SHA256:A599608AA42D0E334E6001CC9B90C0A0672F506B9459246F4A7B53D4AC5D2410
6708diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeC:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.exeexecutable
MD5:143255618462A577DE27286A272584E1
SHA256:F5AA950381FBCEA7D730AA794974CA9E3310384A95D6CF4D015FBDBD9797B3E4
6708diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeC:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.zipcompressed
MD5:F68008B70822BD28C82D13A289DEB418
SHA256:CC6F4FAF4E8A9F4D2269D1D69A69EA326F789620FB98078CC98597F3CB998589
6708diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeC:\Users\admin\Downloads\diner-dash-flo-on-the-go-0-installer.exeexecutable
MD5:B03E2CE6E4CD072BA0CED5D9F7161D7F
SHA256:061A965A78587781F91B6C19D13F2C551566089E7BEFCBA29F7BAE80A745CFFB
6708diner-dash-flo-on-the-go-0-installer_xF-M0p1.exeC:\Users\admin\AppData\Local\Temp\ISV713B.tmp\avg_antivirus_free_setup.exeexecutable
MD5:26816AF65F2A3F1C61FB44C682510C97
SHA256:2025C8C2ACC5537366E84809CB112589DDC9E16630A81C301D24C887E2D25F45
5684avg_antivirus_free_setup.exeC:\Windows\Temp\asw.fd76dcb28cfdec55\ecoo.edattext
MD5:3F44A3C655AC2A5C3AB32849ECB95672
SHA256:51516A61A1E25124173DEF4EF68A6B8BABEDC28CA143F9EEE3E729EBDC1EF31F
6208avg_antivirus_free_online_setup.exeC:\Users\admin\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3binary
MD5:51CACEA0FBAE8346C20FB94EFEEF8809
SHA256:5749457FC3E5EE160FE41B6BC0743A890B38FD3F09965828BD19FE269E5BD434
6208avg_antivirus_free_online_setup.exeC:\Users\admin\AppData\Local\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0binary
MD5:72FE6B795571F8FB0E3612A485419DF7
SHA256:FAD6C1AD27263AC52A614C79B2821C1E3C158F60637551786A1C832CC3900395
6208avg_antivirus_free_online_setup.exeC:\Users\admin\AppData\Local\Temp\6358C710-B89F-46B9-93F2-F6CAC44F5286binary
MD5:36E184D58707DFF1DBBFF8A9EE12AB55
SHA256:9895E2381D351C4053E4F9AD91EA9845593B83DD97A8ED5231691070F9AE4F87
6004saBSI.exeC:\ProgramData\McAfee\WebAdvisor\saBSI.exe\log_00000057003F001D0006.txttext
MD5:B81D316CCE8E5B981BBED2D2366A9691
SHA256:6C358E0C7DF9634DE390CC25DC0D54D322C4EF022C90E95E8F82E7BCB94F5736
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
68
DNS requests
68
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2212
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2212
RUXIMICS.exe
GET
200
95.101.78.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5684
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
whitelisted
5684
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
whitelisted
5684
avg_antivirus_free_setup.exe
POST
200
142.250.181.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
6264
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5684
avg_antivirus_free_setup.exe
POST
200
142.250.181.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
4672
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
1176
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6708
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
54.239.192.151:443
di7e1j5f1plfo.cloudfront.net
AMAZON-02
US
whitelisted
6708
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
151.101.1.91:443
images.sftcdn.net
FASTLY
US
whitelisted
2212
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2212
RUXIMICS.exe
95.101.78.42:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
login.live.com
  • 40.126.32.138
  • 20.190.160.2
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.14
  • 20.190.160.130
  • 20.190.160.132
whitelisted
di7e1j5f1plfo.cloudfront.net
  • 54.239.192.151
  • 54.239.192.79
  • 54.239.192.166
  • 54.239.192.192
whitelisted
images.sftcdn.net
  • 151.101.1.91
  • 151.101.65.91
  • 151.101.193.91
  • 151.101.129.91
whitelisted
gsf-fl.softonic.com
  • 151.101.1.91
  • 151.101.65.91
  • 151.101.193.91
  • 151.101.129.91
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 95.101.78.42
  • 95.101.78.32
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
analytics.apis.mcafee.com
  • 44.227.11.208
  • 54.71.63.252
  • 35.161.5.254
  • 44.238.122.66
  • 54.202.182.135
  • 44.241.14.223
  • 52.41.171.173
  • 44.235.234.38
unknown

Threats

No threats detected
Process
Message
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
LoadingPage
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
WelcomePage
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
ProductPage
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
ProductPage
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
DownloadPageDLM
diner-dash-flo-on-the-go-0-installer_xF-M0p1.exe
FinishPageDLM
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\ISV713B.tmp\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory