| File name: | Yandex.exe |
| Full analysis: | https://app.any.run/tasks/389fb04d-01c4-458b-9c46-5e3c41a7cba3 |
| Verdict: | Malicious activity |
| Analysis date: | October 20, 2020, 03:28:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D5270D5FABF01E912CCA740398716D32 |
| SHA1: | E8F2A988AE9D0C093E10942E3025B3DDACE470E6 |
| SHA256: | F4252FF60CCF2519F48803C0B29FED6BCDC89B7473CB9D4F8986DD8204FED488 |
| SSDEEP: | 49152:Kw0UHgKGYkxDFVDT4ryX9DdW+bZkAJDgQxYB0TqBu4FisGH4rW51UryiySLA5A:Kpb5X9DdWyZJBgQxcg+5maMWuiymA5 |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:09:24 16:19:10+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 886272 |
| InitializedDataSize: | 1424384 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb1420 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 20.9.1.68 |
| ProductVersionNumber: | 20.9.1.68 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | YANDEX LLC |
| FileDescription: | Yandex |
| FileVersion: | 20.9.1.68 |
| InternalName: | lite_installer |
| LegalCopyright: | Copyright (c) 2012-2020 YANDEX LLC. All Rights Reserved. |
| ProductName: | Yandex |
| ProductVersion: | 20.9.1.68 |
| ProductChromiumVersion: | 85.0.4183.102 |
| ProductYandexVersion: | 20.9.1.68 |
| CompanyShortName: | YANDEX LLC |
| ProductShortName: | Yandex Installer |
| LastChange: | 93e1663902ab082626206d904205e340531558a0 |
| OfficialBuild: | 1 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 24-Sep-2020 14:19:10 |
| Detected languages: |
|
| TLS Callbacks: | 2 callback(s) detected. |
| Debug artifacts: |
|
| CompanyName: | YANDEX LLC |
| FileDescription: | Yandex |
| FileVersion: | 20.9.1.68 |
| InternalName: | lite_installer |
| LegalCopyright: | Copyright (c) 2012-2020 YANDEX LLC. All Rights Reserved. |
| ProductName: | Yandex |
| ProductVersion: | 20.9.1.68 |
| ProductChromiumVersion: | 85.0.4183.102 |
| ProductYandexVersion: | 20.9.1.68 |
| CompanyShortName: | YANDEX LLC |
| ProductShortName: | Yandex Installer |
| LastChange: | 93e1663902ab082626206d904205e340531558a0 |
| Official Build: | 1 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0078 |
| Pages in file: | 0x0001 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0x0000 |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x0000 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000078 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 10 |
| Time date stamp: | 24-Sep-2020 14:19:10 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000D8452 | 0x000D8600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66129 |
.rdata | 0x000DA000 | 0x00024B78 | 0x00024C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.76514 |
.data | 0x000FF000 | 0x00005D58 | 0x00003000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.56803 |
.00cfg | 0x00105000 | 0x00000004 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0611629 |
.tls | 0x00106000 | 0x00000009 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0203931 |
.voltbl | 0x00107000 | 0x00000134 | 0x00000200 | 4.58776 | |
SHARED | 0x00108000 | 0x00000004 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_WRITE | 0 |
Shared | 0x00109000 | 0x000010D6 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0010B000 | 0x0012A3A8 | 0x0012A400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.93346 |
.reloc | 0x00236000 | 0x00008218 | 0x00008400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.64825 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.1744 | 2002 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.44702 | 9832 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 4.58339 | 4392 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 4.56164 | 2488 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 4.80269 | 1128 | Latin 1 / Western European | UNKNOWN | RT_ICON |
26 | 3.34409 | 1120 | Latin 1 / Western European | Spanish - Spain (International sort) | RT_STRING |
27 | 3.2921 | 1658 | Latin 1 / Western European | Spanish - Spain (International sort) | RT_STRING |
28 | 3.21322 | 672 | Latin 1 / Western European | Spanish - Spain (International sort) | RT_STRING |
128 | 2.68263 | 76 | Latin 1 / Western European | UNKNOWN | RT_GROUP_ICON |
129 | 2.11614 | 406 | Latin 1 / Western European | UNKNOWN | RT_DIALOG |
ADVAPI32.dll (delay-loaded) |
KERNEL32.dll |
Title | Ordinal | Address |
|---|---|---|
0 | 0x00000000 | |
GetHandleVerifier | 1 | 0x0007F260 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 492 | "C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe" --statistics=https://api.browser.yandex.ru/installstats/send/dtype=stred/pid=457/cid=72992/path=extended_stat/vars=-action=version_folder_files_check_unused,-brand_id=unknown,-error=FONT_NOT_FOUND,-files_mask=402390367,-installer_type=service_audit,-launched=false,-old_style=0,-old_ver=,-result=0,-stage=error,-target=version_folder_files_check,-ui=13AC80E2_DF12_43B3_86AE_DF39CAFC575E/* | C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe | service_update.exe | ||||||||||||
User: SYSTEM Company: YANDEX LLC Integrity Level: SYSTEM Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 540 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\20.9.1.68\service_update.exe" --setup | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\20.9.1.68\service_update.exe | setup.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: HIGH Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 1176 | "C:\Users\admin\AppData\Local\Temp\YB_30B32.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\YB_30B32.tmp\BROWSER.PACKED.7Z" --searchband-file="C:\Users\admin\AppData\Local\Temp\YB_30B32.tmp\SEARCHBAND.EXE" --brand-name=int --brand-package="C:\Users\admin\AppData\Local\Temp\BrandFile" --clids-file="C:\Users\admin\AppData\Local\Temp\clids.xml" --clids-searchband-file="C:\Users\admin\AppData\Local\Temp\clids_searchband.xml" --distr-info-file="C:\Users\admin\AppData\Local\Temp\distrib_info" --distribution-channel=beta --histogram-download-time=92 --install-start-time-no-uac=2986097656 --installerdata="C:\Users\admin\AppData\Local\Temp\master_preferences" --ok-button-pressed-time=2985191406 --partner-package="C:\Users\admin\AppData\Local\Temp\PartnerFile" --progress-window=786734 --source=lite --variations-update-path="C:\Users\admin\AppData\Local\Temp\51b9c59a-c387-4b28-90fb-2aa96bd2ac80.tmp" --verbose-logging | C:\Users\admin\AppData\Local\Temp\YB_30B32.tmp\setup.exe | yb43B5.tmp | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: HIGH Description: Yandex Exit code: 1 Version: 20.9.1.68 Modules
| |||||||||||||||
| 1752 | "C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe" --install | C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe | service_update.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: HIGH Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe" --run-as-service | C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe | services.exe | ||||||||||||
User: SYSTEM Company: YANDEX LLC Integrity Level: SYSTEM Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 2100 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --progress-window=786734 --ok-button-pressed-time=2985191406 --install-start-time-no-uac=2986097656 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | explorer.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: MEDIUM Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 2488 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=searchband --vendor-xml-path="C:\Users\admin\AppData\Local\Temp\clids_searchband.xml" | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe | setup.exe | ||||||||||||
User: admin Company: Yandex Integrity Level: HIGH Description: ClidManagerModule Exit code: 4294967293 Version: 1,0,0,44 Modules
| |||||||||||||||
| 2500 | "C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe" --update-scheduler | C:\Program Files\Yandex\YandexBrowser\20.9.1.68\service_update.exe | service_update.exe | ||||||||||||
User: SYSTEM Company: YANDEX LLC Integrity Level: SYSTEM Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| 2516 | "C:\Users\admin\AppData\Local\Temp\Yandex.exe" | C:\Users\admin\AppData\Local\Temp\Yandex.exe | explorer.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: MEDIUM Description: Yandex Exit code: 0 Version: 20.9.1.68 Modules
| |||||||||||||||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\AppDataLow\Yandex |
| Operation: | write | Name: | UICreated_admin |
Value: 1 | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | DistribInfoParams |
Value: win10pin=1&vup=1&browser=GoogleChrome/64/78.0.3904.97&banerid=6302000000:5f75697989dc98001eaeaf79&zih=1&pps=installID%3D5117201051601530228_1601530233351&yandexuid=5117201051601530228&download_date=1601530233 | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | lang |
Value: en | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | InstallerData |
Value: C:\Users\admin\AppData\Local\Temp\master_preferences | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | ClidsFile |
Value: C:\Users\admin\AppData\Local\Temp\clids.xml | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | ClidsSearchbandFile |
Value: C:\Users\admin\AppData\Local\Temp\clids_searchband.xml | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | YandexWebsiteIconFile |
Value: C:\Users\admin\AppData\Local\Temp\website.ico | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | brand |
Value: int | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | BrandFile |
Value: C:\Users\admin\AppData\Local\Temp\BrandFile | |||
| (PID) Process: | (2516) Yandex.exe | Key: | HKEY_CURRENT_USER\Software\Yandex\YandexBrowser |
| Operation: | write | Name: | PartnerFile |
Value: C:\Users\admin\AppData\Local\Temp\PartnerFile | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\website.ico | — | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\Cab4C80.tmp | — | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\Tar4C81.tmp | — | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\lite_installer.log | text | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Roaming\Yandex\ui | text | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\68FAF71AF355126BCA00CE2E73CC7374_77B682CF3AAC7B00161DFFF7DEA4CC8C | der | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E887E036775F4159E2816B7B9E527E5F_828EEC3D8758CDCDD51D2DE3EBDD6B52 | der | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E887E036775F4159E2816B7B9E527E5F_B3EA9A25C9F1E2AEBB837D78798C3446 | binary | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\master_preferences | text | |
MD5:— | SHA256:— | |||
| 2516 | Yandex.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\browser[1].proto | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2516 | Yandex.exe | GET | 200 | 151.139.236.246:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | US | der | 1.58 Kb | whitelisted |
2516 | Yandex.exe | GET | 200 | 5.45.205.243:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEDNM55%2BDg81RdfcQe7CLguA%3D | RU | der | 1.48 Kb | whitelisted |
2516 | Yandex.exe | GET | 200 | 5.45.205.243:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEDPsoYYqql5ITGW13mI%2FVzY%3D | RU | der | 1.48 Kb | whitelisted |
2516 | Yandex.exe | GET | 200 | 5.45.205.243:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEEl1t5jSFZZ1pakW2ipzwrY%3D | RU | der | 1.48 Kb | whitelisted |
2516 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://secure.globalsign.com/cacert/gscodesigng3ocsp.crt | US | der | 1.14 Kb | whitelisted |
2516 | Yandex.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFDxAmS5JEAmWxO0Ue9OdQ9z7zPAQUFQASKxOYspkH7R7for5XDStnAs0CEAMBmgI6%2F1ixa9bV6uYX8GY%3D | US | der | 471 b | whitelisted |
2516 | Yandex.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkfDD%2F78IrsoD5b%2Bp1JR | US | der | 1.49 Kb | whitelisted |
492 | service_update.exe | GET | 200 | 5.45.205.242:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEDNM55%2BDg81RdfcQe7CLguA%3D | RU | der | 1.48 Kb | whitelisted |
2028 | service_update.exe | GET | 200 | 104.18.20.226:80 | http://secure.globalsign.com/cacert/gscodesigng3ocsp.crt | US | der | 1.14 Kb | whitelisted |
492 | service_update.exe | GET | 200 | 151.139.236.246:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | US | der | 1.58 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2516 | Yandex.exe | 5.45.205.241:443 | download.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 213.180.193.234:443 | api.browser.yandex.ru | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 151.139.236.246:80 | subca.ocsp-certum.com | netDNA | US | unknown |
2516 | Yandex.exe | 5.45.205.243:80 | download.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 37.9.96.15:443 | cache-mskstoredata04.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 5.45.222.25:443 | cache-mskmar01.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 5.45.222.89:443 | cache-mskmar14.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 5.45.222.32:443 | cache-mskmar08.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 5.45.222.27:443 | cache-mskmar03.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2516 | Yandex.exe | 5.45.222.34:443 | cache-mskmar10.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.browser.yandex.ru |
| whitelisted |
download.cdn.yandex.net |
| whitelisted |
api.browser.yandex.net |
| whitelisted |
subca.ocsp-certum.com |
| whitelisted |
yandex.ocsp-responder.com |
| whitelisted |
cache-mskstoredata04.cdn.yandex.net |
| whitelisted |
cache-mskmar01.cdn.yandex.net |
| unknown |
cache-mskmar14.cdn.yandex.net |
| whitelisted |
cache-mskmar08.cdn.yandex.net |
| unknown |
cache-mskmar03.cdn.yandex.net |
| whitelisted |
Process | Message |
|---|---|
clidmgr.exe | GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = USER-PC, dwSessionId = 0
|
clidmgr.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
clidmgr.exe | GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = USER-PC, dwSessionId = 0
|
clidmgr.exe | GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1302019708-1500728564-335382590-1000
|
clidmgr.exe | GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = USER-PC, dwSessionId = 0
|
clidmgr.exe | GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = USER-PC, dwSessionId = 1
|
clidmgr.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
clidmgr.exe | GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1302019708-1500728564-335382590-1000
|
clidmgr.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
clidmgr.exe | GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = USER-PC, dwSessionId = 1
|