download:

Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE

Full analysis: https://app.any.run/tasks/f9bdffac-1300-4921-a9dd-28b6da058772
Verdict: Malicious activity
Analysis date: January 09, 2022, 09:54:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BFA43AE7542497702DA5B82651F3F678

SHA1:

3FBFF2846B8E7002F324AD4F688EC0E9CEAAD0E5

SHA256:

F17212130E94D789C73E7B59C86679D3916329AAB0F58D5B87AEEA4CCEB96DEB

SSDEEP:

393216:w1xCVNxTFXGaAOaoXq1imrg5secyHVTr/NL9Q/i/fLwFqENsIt3g:3TxTFWj8q1usU1nY/Kzwcst3g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • miniunz.exe (PID: 3636)
      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
      • rundll32.exe (PID: 4020)
      • msiexec.exe (PID: 3044)
      • rundll32.exe (PID: 560)
    • Loads dropped or rewritten executable

      • miniunz.exe (PID: 3636)
      • DellOSRecoveryTool.exe (PID: 1976)
      • MsiExec.exe (PID: 3376)
      • DellOSRecoveryTool.exe (PID: 2328)
      • rundll32.exe (PID: 560)
      • rundll32.exe (PID: 4020)
      • MsiExec.exe (PID: 2640)
    • Application was dropped or rewritten from another process

      • miniunz.exe (PID: 3636)
      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 2328)
      • DellOSRecoveryTool.exe (PID: 3492)
    • Changes the autorun value in the registry

      • DellOSRecoveryTool.exe (PID: 3188)
    • Changes settings of System certificates

      • DellOSRecoveryTool.exe (PID: 2328)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • miniunz.exe (PID: 3636)
      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
      • rundll32.exe (PID: 4020)
      • msiexec.exe (PID: 3044)
      • rundll32.exe (PID: 560)
    • Executable content was dropped or overwritten

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
      • miniunz.exe (PID: 3636)
      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
      • rundll32.exe (PID: 4020)
      • rundll32.exe (PID: 560)
      • msiexec.exe (PID: 3044)
    • Creates files in the program directory

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
      • DellOSRecoveryTool.exe (PID: 3188)
      • DellOSRecoveryTool.exe (PID: 2328)
      • msiexec.exe (PID: 3044)
    • Reads Microsoft Outlook installation path

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
    • Reads internet explorer settings

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
    • Checks supported languages

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
      • miniunz.exe (PID: 3636)
      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
      • DellOSRecoveryTool.exe (PID: 2328)
    • Reads the computer name

      • Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE (PID: 2880)
      • DellOSRecoveryTool.exe (PID: 3188)
      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 2328)
    • Creates files in the Windows directory

      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
    • Searches for installed software

      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
    • Starts itself from another location

      • DellOSRecoveryTool.exe (PID: 1976)
    • Executed as Windows Service

      • vssvc.exe (PID: 3968)
      • msiexec.exe (PID: 3044)
    • Reads Environment values

      • vssvc.exe (PID: 3968)
      • DellOSRecoveryTool.exe (PID: 2328)
    • Creates a software uninstall entry

      • DellOSRecoveryTool.exe (PID: 3188)
      • msiexec.exe (PID: 3044)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3044)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3044)
    • Application launched itself

      • msiexec.exe (PID: 3044)
    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 3376)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3044)
    • Drops a file with a compile date too recent

      • msiexec.exe (PID: 3044)
    • Removes files from Windows directory

      • DellOSRecoveryTool.exe (PID: 2616)
      • DellOSRecoveryTool.exe (PID: 1976)
    • Adds / modifies Windows certificates

      • DellOSRecoveryTool.exe (PID: 2328)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • DellOSRecoveryTool.exe (PID: 1976)
      • DellOSRecoveryTool.exe (PID: 3188)
    • Reads the computer name

      • vssvc.exe (PID: 3968)
      • MsiExec.exe (PID: 3376)
      • msiexec.exe (PID: 3044)
      • rundll32.exe (PID: 4020)
      • rundll32.exe (PID: 560)
      • MsiExec.exe (PID: 2640)
      • WISPTIS.EXE (PID: 1392)
    • Checks supported languages

      • vssvc.exe (PID: 3968)
      • msiexec.exe (PID: 3044)
      • MsiExec.exe (PID: 3376)
      • rundll32.exe (PID: 4020)
      • rundll32.exe (PID: 560)
      • MsiExec.exe (PID: 2640)
      • WISPTIS.EXE (PID: 1392)
    • Manual execution by user

      • DellOSRecoveryTool.exe (PID: 3492)
      • DellOSRecoveryTool.exe (PID: 2328)
    • Reads settings of System Certificates

      • DellOSRecoveryTool.exe (PID: 2328)
    • Checks Windows Trust Settings

      • DellOSRecoveryTool.exe (PID: 2328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

ProductVersion: 2.3.7010.0
ProductName: USB Recovery Tool Application, 2.3.7010.0, A00
OriginalFileName: DUPFramework.exe
LegalCopyright: Copyright (C) Dell Inc. 2021. All rights reserved.
InternalName: DUPFramework.exe
FileVersion: 004.008.007.000
FileDescription: Dell Update Package: USB Recovery Tool Application, 2.3.7010.0, A00
CompanyName: Dell Inc.
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 4.8.7.0
FileVersionNumber: 4.8.9.106
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x1fb4a
UninitializedDataSize: -
InitializedDataSize: 3305984
CodeSize: 5544960
LinkerVersion: 14
PEType: PE32
TimeStamp: 2021:07:29 07:14:55+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
16
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start dell-usb-recovery-tool-application_x3vk8_win_2.3.7010.0_a00.exe miniunz.exe dellosrecoverytool.exe dellosrecoverytool.exe dellosrecoverytool.exe vssvc.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe rundll32.exe msiexec.exe no specs dellosrecoverytool.exe no specs dellosrecoverytool.exe wisptis.exe no specs wisptis.exe no specs dell-usb-recovery-tool-application_x3vk8_win_2.3.7010.0_a00.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
484"C:\Users\admin\AppData\Local\Temp\Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE" C:\Users\admin\AppData\Local\Temp\Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEExplorer.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
MEDIUM
Description:
Dell Update Package: USB Recovery Tool Application, 2.3.7010.0, A00
Exit code:
3221226540
Version:
004.008.007.000
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\dell-usb-recovery-tool-application_x3vk8_win_2.3.7010.0_a00.exe
560rundll32.exe "C:\Windows\Installer\MSIC002.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1163375 8 InstallerAction!InstallerAction.CustomActions.RenameProductNameC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1392"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEDellOSRecoveryTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1976"C:\Windows\Temp\{C7576E13-75D9-4AC8-9C36-837D63DD52CF}\.cr\DellOSRecoveryTool.exe" -burn.clean.room="C:\ProgramData\Dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\DellOSRecoveryTool.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 /quiet /lv "C:\ProgramData\dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\DUP8E14.tmp"C:\Windows\Temp\{C7576E13-75D9-4AC8-9C36-837D63DD52CF}\.cr\DellOSRecoveryTool.exe
DellOSRecoveryTool.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell OS Recovery Tool
Exit code:
0
Version:
2.3.7010
Modules
Images
c:\windows\temp\{c7576e13-75d9-4ac8-9c36-837d63dd52cf}\.cr\dellosrecoverytool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2208"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEDellOSRecoveryTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2328"C:\Program Files\Dell\OS Recovery Tool\DellOSRecoveryTool.exe" C:\Program Files\Dell\OS Recovery Tool\DellOSRecoveryTool.exe
Explorer.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell OS Recovery Tool
Exit code:
0
Version:
2.3.7010
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\dell\os recovery tool\dellosrecoverytool.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2616"C:\ProgramData\Dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\DellOSRecoveryTool.exe" /quiet /lv "C:\ProgramData\dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\DUP8E14.tmp"C:\ProgramData\Dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\DellOSRecoveryTool.exe
Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell OS Recovery Tool
Exit code:
0
Version:
2.3.7010
Modules
Images
c:\programdata\dell\drivers\34f6983e-4c30-415d-a2ec-6dc7504851e0\dellosrecoverytool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2640C:\Windows\system32\MsiExec.exe -Embedding 24AAB6CF12C10E9ED0159127295EB11C E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2880"C:\Users\admin\AppData\Local\Temp\Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE" C:\Users\admin\AppData\Local\Temp\Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXE
Explorer.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Update Package: USB Recovery Tool Application, 2.3.7010.0, A00
Exit code:
0
Version:
004.008.007.000
Modules
Images
c:\users\admin\appdata\local\temp\dell-usb-recovery-tool-application_x3vk8_win_2.3.7010.0_a00.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3044C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
12 770
Read events
11 942
Write events
814
Delete events
14

Modification events

(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2880) Dell-USB-Recovery-Tool-Application_X3VK8_WIN_2.3.7010.0_A00.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1976) DellOSRecoveryTool.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1976) DellOSRecoveryTool.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1976) DellOSRecoveryTool.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
162
Suspicious files
9
Text files
107
Unknown types
9

Dropped files

PID
Process
Filename
Type
3636miniunz.exeC:\PROGRA~2\dell\drivers\34F698~1\package.xmlbinary
MD5:
SHA256:
3636miniunz.exeC:\PROGRA~2\dell\drivers\34F698~1\mup.xmlxml
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\fi\WixBA.resources.dllexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\pt-PT\WixBA.resources.dllexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\WixBA.dllexecutable
MD5:
SHA256:
3636miniunz.exeC:\PROGRA~2\dell\drivers\34F698~1\DellOSRecoveryTool.exeexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\el\WixBA.resources.dllexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\en\WixBA.resources.dllexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\zh-SG\WixBA.resources.dllexecutable
MD5:
SHA256:
1976DellOSRecoveryTool.exeC:\Windows\Temp\{BDAC7B9D-6FB4-48C8-9390-F6F8311A86A7}\.ba\zh-TW\WixBA.resources.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2328
DellOSRecoveryTool.exe
2.18.232.9:443
dellupdater.dell.com
Akamai International B.V.
whitelisted
2328
DellOSRecoveryTool.exe
143.166.28.87:443
apigtwb2c.us.dell.com
Dell, Inc.
US
suspicious
2328
DellOSRecoveryTool.exe
104.109.77.137:443
i.dell.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
dellupdater.dell.com
  • 2.18.232.9
unknown
apigtwb2c.us.dell.com
  • 143.166.28.87
suspicious
i.dell.com
  • 104.109.77.137
whitelisted

Threats

No threats detected
Process
Message
DellOSRecoveryTool.exe
no configuration section <common/logging> found - suppressing logging output
DellOSRecoveryTool.exe
DellOSRecoveryTool.exe Information: 0 :
DellOSRecoveryTool.exe
Job To Be Executed: jobs.sendMessages
DellOSRecoveryTool.exe
DellOSRecoveryTool.exe Information: 0 :
DellOSRecoveryTool.exe
Job To Be Executed: jobs.refreshProfile
DellOSRecoveryTool.exe
DellOSRecoveryTool.exe Error: 0 :
DellOSRecoveryTool.exe
Send Batch Events:Build File Paths|System.IO.DirectoryNotFoundException: Could not find a part of the path 'C:\ProgramData\Dell\OS Recovery Tool\data\84C50487-D17A-445E-8A9B-4F4165B9F657'. at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileSystemEnumerableIterator`1.CommonInit() at System.IO.FileSystemEnumerableIterator`1..ctor(String path, String originalUserPath, String searchPattern, SearchOption searchOption, SearchResultHandler`1 resultHandler, Boolean checkHost) at System.IO.DirectoryInfo.InternalGetDirectories(String searchPattern, SearchOption searchOption) at System.IO.DirectoryInfo.GetDirectories() at Dell.Pla.P1.MessageClient.FileHelper.GetNextEventFileDetails(Int32 size, String folderPath) at Dell.Pla.P1.MessageClient.MessageHelper.SendBatchEvents(MessageClientConfiguration configuration, Int32 batchSize, DecryptionHelper helper, DeviceProfile customerDeviceProfile)
DellOSRecoveryTool.exe
DellOSRecoveryTool.exe Error: 0 :
DellOSRecoveryTool.exe
System.NullReferenceException: Object reference not set to an instance of an object. at Dell.Pla.P1.MessageClient.DeviceProfileHelper.GetProfile()
DellOSRecoveryTool.exe
DellOSRecoveryTool.exe Information: 0 :