| File name: | pkeyconfig-office.xrm-ms |
| Full analysis: | https://app.any.run/tasks/f9db7322-c801-413c-9b8b-823641560417 |
| Verdict: | No threats detected |
| Analysis date: | March 26, 2018, 17:50:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators |
| MD5: | 3DCFF1DCDEB1B837EC8F13351C8A92AC |
| SHA1: | 110132BD71AF7EF15FD8FABCB5BAA16085148D2E |
| SHA256: | EDFB49CD35FE352A1D29DB39BAA949AC23B06795C31F417816185B0C04C82F07 |
| SSDEEP: | 3072:wqqhYLNaC3gxS4hriMkDxPTe8dlmPAJCissBaPwqWCRzFh6vyxgvdMGnl1eQeNSB:Zvq4AvfWQK+DU/Sa |
| .xrm-ms | | | Microsoft security certificate (Unicode) (96) |
|---|---|---|
| .xml | | | Generic XML (UTF-8) (2.8) |
| .txt | | | Text - UTF-8 encoded (1) |
| LicenseGroupLicenseLicenseId: | {8d0bdca0-33c9-43bd-8729-9871bba08c71} |
|---|---|
| LicenseGroupLicenseTitle: | XrML 2.1 License - Product Key Configuration |
| LicenseGroupLicenseIssuerSignatureXmlns: | http://www.w3.org/2000/09/xmldsig# |
| LicenseGroupLicenseIssuerSignatureSignedInfoCanonicalizationMethodAlgorithm: | http://www.microsoft.com/xrml/lwc14n |
| LicenseGroupLicenseIssuerSignatureSignedInfoSignatureMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#rsa-sha1 |
| LicenseGroupLicenseIssuerSignatureSignedInfoReferenceTransformsTransformAlgorithm: | urn:mpeg:mpeg21:2003:01-REL-R-NS:licenseTransform |
| LicenseGroupLicenseIssuerSignatureSignedInfoReferenceDigestMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#sha1 |
| LicenseGroupLicenseIssuerSignatureSignedInfoReferenceDigestValue: | 9m4QA5xAOsHKAD0Q1Rtm2+o2et4= |
| LicenseGroupLicenseIssuerSignatureSignatureValue: | TvF6blODGNigv6S8Y80r2K4jLPgw0U7ugU24QDjiK3Llvg+Qvc017SPMRX31KAlGfRGrNcPEp0gwN83pUX79ht5qdglqXx/3vhkQPR/u0S7MKs/U+xF1Mz6EKHxb6uoIuy1emeWWWcQT6Tf87QiRnoGUW2cDEIwfFPB/XVU1eui6WyYkThTtEGYYpjitHGDwlxkv3Qk26btt1X+pjBJ4mxutn7X3VPo0OGJpsApNdVBcB50WR3h2OwOdo7E8CVpzSLD/Y0Z6HG/upSaMK8WHFv9opdFJdZorlX8w0olOqM15UcvHxTXKAP4U4bnOF8lvOyVwyMx0fZbHVXCexJt3hg== |
| LicenseGroupLicenseIssuerSignatureKeyInfoKeyValueRSAKeyValueModulus: | 1N+QaYteSIjGmRMzTkxCE+5oiPoLk2Fq+RA9GLnl+dHOcyxt2a/0HvUdagaL/NwDquzOef4JOMMuVavd4PtWQiO/aBLvxVv7yIhUhhB6PEsw59mhbVlT/Z5OGkp6gfzH9ezZ+qHHFHo0cloAAu5QGUeuYCPLheVK7X3+syHE1qXagfRa5m0xG+770FyPeMKazK+keeQ/goW+nt2wTM9Pofj4yTGCbn6Fc6EpKdyHmzrzQDc5FjZemXP2PbGjS6iPC7l3+Ut5JPL66ZUZzCs5qRc+/wRODknUWAcqURJWP79knfPhf3/dvbytHpr64wFfpBNDSbNVubol0E8oTa/NYw== |
| LicenseGroupLicenseIssuerSignatureKeyInfoKeyValueRSAKeyValueExponent: | AQAB |
| LicenseGroupLicenseOtherInfoInfoTablesInfoListTag: | #global |
| LicenseGroupLicenseOtherInfoInfoTablesInfoListInfoStrName: | licenseType |
| LicenseGroupLicenseOtherInfoInfoTablesInfoListInfoStr: | msft:sl/PKEYCONFIG/SIGNED |
| LicenseGroupLicenseOtherInfoInfoTablesInfoListInfoBinName: | pkeyConfigData |
| LicenseGroupLicenseOtherInfoInfoTablesInfoListInfoBin: | (Binary data 713512 bytes, use -b option to extract) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2780 | "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Users\admin\AppData\Local\Temp\pkeyconfig-office.xrm-ms" | C:\Program Files\Internet Explorer\iexplore.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3160 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2780 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D00000009000000000000000000000000000000040000000000000090CE7F108CAFD301000000000000000000000000020000001700000000000000FE80000000000000D45917EAB3ED3D860B000000000000001700000000000000FE80000000000000D45917EAB3ED3D860B000000000000001C00000000000000000000000000000000000000000000000000000000000000170000000000000000000000000000000000FFFFC0A8640B000000000000000002000000C0A864640000000000000000000000000000000000000000000000000C00000C37D0000010A73800D8703600000000000000000000000000000000000000000000000000000000000000000000000000000000000000000081F800009000230090002300380023000000000000702C000A00000000000000F8412C00 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {287133CF-311E-11E8-943E-5254004AAD21} |
Value: 0 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 1 | |||
| (PID) Process: | (2780) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E207030001001A00110032001800BB01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZH9GIXH\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF60453E2060B50F43.TMP | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF9E2E4C9D9A762A22.TMP | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF5CCF034D3772C5A1.TMP | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{287133D0-311E-11E8-943E-5254004AAD21}.dat | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TOH6XLJASIIRWT8271WX.temp | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFEC488B00870AA586.TMP | — | |
MD5:— | SHA256:— | |||
| 2780 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{287133CF-311E-11E8-943E-5254004AAD21}.dat | — | |
MD5:— | SHA256:— | |||
| 3160 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018032620180327\index.dat | dat | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |