File name:

bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe

Full analysis: https://app.any.run/tasks/de735c05-bd3d-42d7-aae8-e65c608b7d25
Verdict: Malicious activity
Analysis date: December 13, 2024, 19:40:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

53E8BA5D0383C919E1318FB44435CA6C

SHA1:

33A36729AD0F1846D3602CD7CD73E546277C545C

SHA256:

EDF957AD742B7BFC1EE764DD477053B1C33D251CA14F1EDA711EE10D71E65480

SSDEEP:

98304:tyRr3UJ1IqsdPDMJoPvpyUwyFgS8S7ce/Unba+O+CB3jD9hlw:5L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_setup.exe (PID: 396)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
    • Reads security settings of Internet Explorer

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • saBSI.exe (PID: 1580)
    • Checks Windows Trust Settings

      • saBSI.exe (PID: 1580)
    • The process verifies whether the antivirus software is installed

      • saBSI.exe (PID: 1580)
      • icarus.exe (PID: 6172)
      • icarus.exe (PID: 6168)
    • Starts itself from another location

      • icarus.exe (PID: 5880)
    • Process checks presence of unattended files

      • icarus.exe (PID: 6168)
    • Process drops legitimate windows executable

      • icarus.exe (PID: 6168)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 6168)
    • The process drops C-runtime libraries

      • icarus.exe (PID: 6168)
    • Drops a system driver (possible attempt to evade defenses)

      • icarus.exe (PID: 6168)
  • INFO

    • Sends debugging messages

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • saBSI.exe (PID: 1580)
    • Reads the machine GUID from the registry

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_setup.exe (PID: 396)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • saBSI.exe (PID: 1580)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
      • SearchApp.exe (PID: 5064)
    • Checks supported languages

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • SearchApp.exe (PID: 5064)
      • avg_antivirus_free_setup.exe (PID: 396)
      • saBSI.exe (PID: 1580)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
    • The sample compiled with english language support

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_setup.exe (PID: 396)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
    • Reads the computer name

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • saBSI.exe (PID: 1580)
      • avg_antivirus_free_setup.exe (PID: 396)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
    • Checks proxy server information

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • saBSI.exe (PID: 1580)
    • Reads the software policy settings

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_setup.exe (PID: 396)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • saBSI.exe (PID: 1580)
      • SearchApp.exe (PID: 5064)
    • Create files in a temporary directory

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
    • The process uses the downloaded file

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
    • Creates files in the program directory

      • saBSI.exe (PID: 1580)
      • avg_antivirus_free_online_setup.exe (PID: 6028)
      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6168)
      • icarus.exe (PID: 6172)
    • Process checks computer location settings

      • bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe (PID: 6528)
      • SearchApp.exe (PID: 5064)
    • Reads CPU info

      • icarus.exe (PID: 5880)
      • icarus.exe (PID: 6172)
      • icarus.exe (PID: 6168)
    • Reads Environment values

      • icarus.exe (PID: 6168)
    • The sample compiled with czech language support

      • icarus.exe (PID: 6168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:14 12:00:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 2145792
InitializedDataSize: 2305536
UninitializedDataSize: -
EntryPoint: 0x1c2253
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.9.1
ProductVersionNumber: 3.0.9.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Softonic
FileDescription: Softonic
FileVersion: 3.0.9.1
LegalCopyright: (c) Softonic. All rights reserved.
ProductName: Softonic
ProductVersion: 3.0.9.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
9
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start searchapp.exe bluetooth-driver-5.0.1.1500-installer_1d2xv-1.exe no specs bluetooth-driver-5.0.1.1500-installer_1d2xv-1.exe sabsi.exe avg_antivirus_free_setup.exe avg_antivirus_free_online_setup.exe icarus.exe icarus.exe icarus.exe

Process information

PID
CMD
Path
Indicators
Parent process
5064"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6376"C:\Users\admin\AppData\Local\Temp\bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe" C:\Users\admin\AppData\Local\Temp\bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exeexplorer.exe
User:
admin
Company:
Softonic
Integrity Level:
MEDIUM
Description:
Softonic
Exit code:
3221226540
Version:
3.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\bluetooth-driver-5.0.1.1500-installer_1d2xv-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6528"C:\Users\admin\AppData\Local\Temp\bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe" C:\Users\admin\AppData\Local\Temp\bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
explorer.exe
User:
admin
Company:
Softonic
Integrity Level:
HIGH
Description:
Softonic
Exit code:
0
Version:
3.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\bluetooth-driver-5.0.1.1500-installer_1d2xv-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1580"C:\Users\admin\AppData\Local\Temp\ISV5660.tmp\saBSI.exe" /affid {aflt} PaidDistribution=true CountryCode=USC:\Users\admin\AppData\Local\Temp\ISV5660.tmp\saBSI.exe
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
0
Version:
4,1,1,865
Modules
Images
c:\users\admin\appdata\local\temp\isv5660.tmp\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
396"C:\Users\admin\AppData\Local\Temp\ISV5660.tmp\avg_antivirus_free_setup.exe" /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llMoJnz29aC8LenAC:\Users\admin\AppData\Local\Temp\ISV5660.tmp\avg_antivirus_free_setup.exe
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
User:
admin
Company:
AVG Technologies CZ, s.r.o.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\isv5660.tmp\avg_antivirus_free_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6028"C:\WINDOWS\Temp\asw.1b43d0e87413df98\avg_antivirus_free_online_setup.exe" /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llMoJnz29aC8LenA /cookie:mmm_irs_ppi_902_451_o /ga_clientid:4f234029-407c-4efe-a662-abc07f6b0182 /edat_dir:C:\WINDOWS\Temp\asw.1b43d0e87413df98C:\Windows\Temp\asw.1b43d0e87413df98\avg_antivirus_free_online_setup.exe
avg_antivirus_free_setup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Self-Extract Package
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw.1b43d0e87413df98\avg_antivirus_free_online_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5880C:\WINDOWS\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\common\icarus.exe /icarus-info-path:C:\WINDOWS\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\icarus-info.xml /install /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llMoJnz29aC8LenA /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\WINDOWS\Temp\asw.1b43d0e87413df98 /track-guid:4f234029-407c-4efe-a662-abc07f6b0182C:\Windows\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\common\icarus.exe
avg_antivirus_free_online_setup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\common\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
6168C:\WINDOWS\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av\icarus.exe /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llMoJnz29aC8LenA /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\WINDOWS\Temp\asw.1b43d0e87413df98 /track-guid:4f234029-407c-4efe-a662-abc07f6b0182 /er_master:master_ep_fde5b924-0f75-410e-a852-f7f9064b09b6 /er_ui:ui_ep_301fccc9-d827-45f7-a642-65fa08737e52 /er_slave:avg-av_slave_ep_59f4a364-787c-46fd-8f2e-6de3ab5a77d9 /slave:avg-avC:\Windows\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\winhttp.dll
6172C:\WINDOWS\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av-vps\icarus.exe /silent /ws /psh:hIA7qv6y4LnyhZ8uUg5ES7NJSv5xFxjsl6RHqJGR35jKfB2LkrE9eOjWN5xgM0llMoJnz29aC8LenA /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\WINDOWS\Temp\asw.1b43d0e87413df98 /track-guid:4f234029-407c-4efe-a662-abc07f6b0182 /er_master:master_ep_fde5b924-0f75-410e-a852-f7f9064b09b6 /er_ui:ui_ep_301fccc9-d827-45f7-a642-65fa08737e52 /er_slave:avg-av-vps_slave_ep_c65f4fe5-7927-4a4a-b2d3-995551b8b303 /slave:avg-av-vpsC:\Windows\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av-vps\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.12.8365.0
Modules
Images
c:\windows\temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\avg-av-vps\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
13 724
Read events
13 329
Write events
386
Delete events
9

Modification events

(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicText
Value:
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB
Operation:writeName:DynamicTextTruncated
Value:
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\DynamicSearchBox
Operation:writeName:TelemetryID
Value:
0000E5D260EB964DDB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\DynamicSearchBox
Operation:writeName:TelemetryID
Value:
00008C676AEB964DDB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Explorer\DOMStorage\bing.com
Operation:writeName:Total
Value:
929
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D00000065342EED964DDB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00320064003000610066006600370038002D0061003000610066002D0034006400340063002D0062003000610033002D003900300036006400360035006600320063003900380034007D00000065342EED964DDB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LastConstraintIndexBuildCompleted
Value:
A04D2FED964DDB0165342EED964DDB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{832b68d2-7fe2-4e71-a3ad-26166b656ec6}
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{2d0aff78-a0af-4d4c-b0a3-906d65f2c984}
Executable files
591
Suspicious files
824
Text files
404
Unknown types
97

Dropped files

PID
Process
Filename
Type
6528bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exeC:\Users\admin\Downloads\bluetooth-driver-5.0.1.1500-installer.exe
MD5:
SHA256:
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{2d0aff78-a0af-4d4c-b0a3-906d65f2c984}\0.1.filtertrie.intermediate.txttext
MD5:34BD1DFB9F72CF4F86E6DF6DA0A9E49A
SHA256:8E1E6A3D56796A245D0C7B0849548932FEE803BBDB03F6E289495830E017F14C
1580saBSI.exeC:\ProgramData\McAfee\WebAdvisor\saBSI.exe\log_00000057003F001D0006.txttext
MD5:E12611C571DE49B07899A8F2854C4DDD
SHA256:D73D44B84E9564B08E6FC513FBE0D46EB6BECB8774E15A1BC0AFB20C50EA9AE6
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{2d0aff78-a0af-4d4c-b0a3-906d65f2c984}\0.2.filtertrie.intermediate.txttext
MD5:C204E9FAAF8565AD333828BEFF2D786E
SHA256:D65B6A3BF11A27A1CED1F7E98082246E40CF01289FD47FE4A5ED46C221F2F73F
6028avg_antivirus_free_online_setup.exeC:\Users\admin\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3binary
MD5:51CACEA0FBAE8346C20FB94EFEEF8809
SHA256:5749457FC3E5EE160FE41B6BC0743A890B38FD3F09965828BD19FE269E5BD434
396avg_antivirus_free_setup.exeC:\Windows\Temp\asw.1b43d0e87413df98\ecoo.edattext
MD5:3F44A3C655AC2A5C3AB32849ECB95672
SHA256:51516A61A1E25124173DEF4EF68A6B8BABEDC28CA143F9EEE3E729EBDC1EF31F
6028avg_antivirus_free_online_setup.exeC:\Windows\Temp\asw-53c68e96-ed84-4093-b32e-9dc29cb46b2f\common\product-info.xmlxml
MD5:CCF949A4A69D800C27E9C1DD02761E4A
SHA256:15AE44E231B80A492A89EDB222499154511C854834A25D1CC4E22E8C42337AF3
6528bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exeC:\Users\admin\AppData\Local\Temp\ISV5660.tmp\saBSI.exeexecutable
MD5:143255618462A577DE27286A272584E1
SHA256:F5AA950381FBCEA7D730AA794974CA9E3310384A95D6CF4D015FBDBD9797B3E4
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{2d0aff78-a0af-4d4c-b0a3-906d65f2c984}\Apps.ftbinary
MD5:AB5CF5D309581951ACE7978FF8DF0FF0
SHA256:CA45CAA7DE38CB805EC43EDC8B9332E1E95124A27FBB6E5BD3DDD5E8A526AFC7
6528bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exeC:\Users\admin\AppData\Local\Temp\ISV5660.tmp\avg.zipcompressed
MD5:56B0D3E1B154AE65682C167D25EC94A6
SHA256:434BFC9E005A7C8EE249B62F176979F1B4CDE69484DB1683EA07A63E6C1E93DE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
101
DNS requests
94
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5736
svchost.exe
GET
200
23.32.238.155:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
5736
svchost.exe
GET
200
23.38.73.129:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6628
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6388
SIHClient.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6388
SIHClient.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6628
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5736
svchost.exe
23.32.238.155:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5736
svchost.exe
23.38.73.129:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.21.110.139:443
www.bing.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
23.218.210.69:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.32.238.155
  • 2.19.198.56
  • 2.19.198.42
  • 2.19.198.49
  • 23.32.238.115
  • 2.19.198.43
  • 2.19.198.40
  • 23.32.238.123
  • 23.32.238.153
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 23.38.73.129
  • 23.215.121.133
whitelisted
www.bing.com
  • 2.21.110.139
  • 2.21.110.146
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.185
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.187
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.0
  • 20.190.159.75
  • 40.126.31.71
whitelisted
di7e1j5f1plfo.cloudfront.net
  • 18.245.78.212
  • 18.245.78.145
  • 18.245.78.188
  • 18.245.78.185
whitelisted
images.sftcdn.net
  • 151.101.129.91
  • 151.101.193.91
  • 151.101.1.91
  • 151.101.65.91
whitelisted

Threats

No threats detected
Process
Message
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
LoadingPage
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
WelcomePage
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
ProductPage
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
ProductPage
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
DownloadPageDLM
bluetooth-driver-5.0.1.1500-installer_1D2XV-1.exe
FinishPageDLM
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\ISV5660.tmp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\ISV5660.tmp\mfeaaca.dll, WinVerifyTrust failed with 80092003