File name:

CCSetup.exe

Full analysis: https://app.any.run/tasks/49a54401-f763-43da-9f94-b47258dd8b91
Verdict: Malicious activity
Analysis date: November 20, 2023, 14:47:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B56A43DE95057FEFDCD9294F028022BE

SHA1:

B152B1AE2891A518941DA1F99D56456249BAFF4A

SHA256:

F4EF5BB5A9F9EC95087F69BE76914C829FC6A6EE5B01C0EF06BD46D5E323738D

SSDEEP:

98304:e9t0taQEx5Tf+S+PI6zxZmDFuN9fLlcYk4LwkYcMiNJ7kx9I5isSaf9TYcNfI+4v:6euB7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CCSetup.exe (PID: 3504)
      • CCSetup.exe (PID: 3524)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • msiexec.exe (PID: 2460)
    • Creates a writable file in the system directory

      • msiexec.exe (PID: 2460)
  • SUSPICIOUS

    • Starts itself from another location

      • CCSetup.exe (PID: 3504)
    • Reads the Internet Settings

      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
    • Reads settings of System Certificates

      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
    • Reads security settings of Internet Explorer

      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
    • Checks Windows Trust Settings

      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
      • msiexec.exe (PID: 2460)
    • Process drops legitimate windows executable

      • CCSetup.exe (PID: 3524)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • msiexec.exe (PID: 2460)
    • Adds/modifies Windows certificates

      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2460)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2460)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 2460)
  • INFO

    • Checks supported languages

      • CCSetup.exe (PID: 3504)
      • CCSetup.exe (PID: 3524)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • wmpnscfg.exe (PID: 3876)
      • SetupUtility.exe (PID: 968)
      • Setup.exe (PID: 1576)
      • msiexec.exe (PID: 2460)
      • msiexec.exe (PID: 2292)
      • SetupUtility.exe (PID: 3340)
      • msiexec.exe (PID: 2132)
    • Reads the computer name

      • CCSetup.exe (PID: 3504)
      • CCSetup.exe (PID: 3524)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • wmpnscfg.exe (PID: 3876)
      • SetupUtility.exe (PID: 968)
      • Setup.exe (PID: 1576)
      • SetupUtility.exe (PID: 3340)
      • msiexec.exe (PID: 2460)
      • msiexec.exe (PID: 2132)
      • msiexec.exe (PID: 2292)
    • Create files in a temporary directory

      • CCSetup.exe (PID: 3504)
      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
      • SetupUtility.exe (PID: 968)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • msiexec.exe (PID: 2460)
    • Checks proxy server information

      • CCSetup.exe (PID: 3524)
    • Reads the machine GUID from the registry

      • CCSetup.exe (PID: 3524)
      • ndp472-kb4054530-x86-x64-allos-enu.exe (PID: 2900)
      • wmpnscfg.exe (PID: 3876)
      • Setup.exe (PID: 1576)
      • SetupUtility.exe (PID: 968)
      • msiexec.exe (PID: 2460)
      • msiexec.exe (PID: 2132)
      • msiexec.exe (PID: 2292)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3876)
      • msedge.exe (PID: 3912)
    • Creates files or folders in the user directory

      • CCSetup.exe (PID: 3524)
      • Setup.exe (PID: 1576)
    • Application launched itself

      • msedge.exe (PID: 3912)
      • msiexec.exe (PID: 2460)
    • Reads CPU info

      • Setup.exe (PID: 1576)
    • Reads Environment values

      • Setup.exe (PID: 1576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:20 21:44:34+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 622080
InitializedDataSize: 780288
UninitializedDataSize: -
EntryPoint: 0x59e5a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.59.0
ProductVersionNumber: 1.0.59.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: RCS LT
FileDescription: Combo Cleaner
FileVersion: 1.0.59.0
InternalName: Setup
LegalCopyright: Copyright (c) 2021 RCS LT, UAB. All Rights Reserved.
OriginalFileName: CCSetup.exe
ProductName: Combo Cleaner
ProductVersion: 1.0.59.0
InternalBuildNumber: 202227
ISInternalVersion: 26.0.720
ISInternalDescription: Setup Launcher Unicode
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
79
Monitored processes
41
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ccsetup.exe ccsetup.exe wmpnscfg.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ndp472-kb4054530-x86-x64-allos-enu.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe setuputility.exe no specs setuputility.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ccsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3620 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
300"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2292 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
368"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=5168 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968SetupUtility.exe /aupauseC:\1999dcf6b371d6fd43e4\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.7.3081.0 built by: NET472REL1
Modules
Images
c:\1999dcf6b371d6fd43e4\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=1268 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1576C:\1999dcf6b371d6fd43e4\\Setup.exe /q /norestart /x86 /x64 /redistC:\1999dcf6b371d6fd43e4\Setup.exe
ndp472-kb4054530-x86-x64-allos-enu.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
14.7.3081.0 built by: NET472REL1
Modules
Images
c:\1999dcf6b371d6fd43e4\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\1999dcf6b371d6fd43e4\setupengine.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1824"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=3756 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4240 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1864"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=3572 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1924"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1576 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
22 724
Read events
22 630
Write events
90
Delete events
4

Modification events

(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3524) CCSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3524) CCSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3876) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{6C86B798-E2D3-4EB1-A431-64569648B915}\{F3B0F564-FD34-438F-ADED-D1486CD96820}
Operation:delete keyName:(default)
Value:
Executable files
818
Suspicious files
1 174
Text files
290
Unknown types
0

Dropped files

PID
Process
Filename
Type
3504CCSetup.exeC:\Users\admin\AppData\Local\Temp\~73BE.tmptext
MD5:C8C14AE5FB013DA397AD84646E33AC83
SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223
3504CCSetup.exeC:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\_ISMSIDEL.INItext
MD5:09BAA35A458DA1A18CD15D3F8975D9CD
SHA256:7222F6DEAD4BAE3FFAA6B9D1A609CBC44B6AE12E26C68B332A2227B28393815F
3504CCSetup.exeC:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\CCSetup.exeexecutable
MD5:B56A43DE95057FEFDCD9294F028022BE
SHA256:F4EF5BB5A9F9EC95087F69BE76914C829FC6A6EE5B01C0EF06BD46D5E323738D
3524CCSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:EF059695552DB202EA425D04B7B14C02
SHA256:A97209B39043D80EB4FE3E5B44417C8F0744D80F38831DFC60DE2E63F315814A
3524CCSetup.exeC:\Users\admin\AppData\Local\Temp\~77A5.tmptext
MD5:C8C14AE5FB013DA397AD84646E33AC83
SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223
3524CCSetup.exeC:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\Setup.INItext
MD5:C8C14AE5FB013DA397AD84646E33AC83
SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223
3504CCSetup.exeC:\Users\admin\AppData\Local\Temp\~73AE.tmptext
MD5:C8C14AE5FB013DA397AD84646E33AC83
SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223
3524CCSetup.exeC:\Users\admin\AppData\Local\Temp\~77A6.tmptext
MD5:C8C14AE5FB013DA397AD84646E33AC83
SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223
3524CCSetup.exeC:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\0x0409.initext
MD5:A108F0030A2CDA00405281014F897241
SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
3524CCSetup.exeC:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\Microsoft .NET Framework 4.7.2 Full.prqxml
MD5:742F35470542E0F3B871918C6A10ABB2
SHA256:880DF4512FFA3353A9658C8FCF0927F9E285B2E41905864EA0A04661C0649BBA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
100
DNS requests
207
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4036
msedge.exe
GET
204
13.107.6.158:80
http://edge-http.microsoft.com/captiveportal/generate_204
unknown
unknown
1576
Setup.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
binary
1.11 Kb
unknown
4036
msedge.exe
GET
301
192.0.66.233:80
http://malwarebytes.com/download
unknown
html
162 b
unknown
3524
CCSetup.exe
GET
200
64.14.29.56:80
http://saturn.installshield.com/is/prerequisites/Microsoft%20.NET%20Framework%204.7.2%20Full.prq
unknown
xml
1.64 Kb
unknown
3524
CCSetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1576
Setup.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
binary
519 b
unknown
1576
Setup.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
binary
767 b
unknown
3524
CCSetup.exe
GET
200
8.253.95.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d19af1718ae57980
unknown
compressed
4.66 Kb
unknown
1576
Setup.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
binary
1.05 Kb
unknown
3524
CCSetup.exe
GET
200
64.14.29.56:80
http://saturn.installshield.com/is/prerequisites/Microsoft%20.NET%20Framework%204.7.2%20Full.prq
unknown
xml
1.64 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3524
CCSetup.exe
64.14.29.56:80
saturn.installshield.com
FLEXERA-SC4
US
unknown
3524
CCSetup.exe
68.232.34.200:443
download.visualstudio.microsoft.com
EDGECAST
US
whitelisted
3524
CCSetup.exe
8.253.95.120:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3524
CCSetup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3912
msedge.exe
239.255.255.250:1900
whitelisted
4036
msedge.exe
204.79.197.203:443
ntp.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
saturn.installshield.com
  • 64.14.29.56
unknown
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted
ctldl.windowsupdate.com
  • 8.253.95.120
  • 67.27.159.254
  • 67.27.233.126
  • 67.26.83.254
  • 8.253.95.121
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ntp.msn.com
  • 204.79.197.203
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
  • 131.253.33.239
  • 13.107.22.239
whitelisted
assets.msn.com
  • 2.23.209.39
  • 2.23.209.42
  • 2.23.209.40
  • 2.23.209.41
  • 2.23.209.48
  • 2.23.209.51
  • 2.23.209.50
  • 2.23.209.45
  • 2.23.209.43
  • 2.23.209.6
  • 2.23.209.5
  • 2.23.209.52
  • 2.23.209.54
  • 2.23.209.55
  • 2.23.209.57
  • 2.23.209.4
  • 2.23.209.7
  • 23.53.42.128
  • 23.53.42.186
  • 23.53.42.144
  • 23.53.42.171
  • 23.53.42.187
  • 23.53.42.179
  • 23.53.42.201
  • 23.53.42.120
  • 23.53.42.147
  • 23.53.42.115
  • 23.53.42.177
  • 23.53.42.210
  • 23.53.42.113
  • 23.53.42.194
  • 92.123.12.168
  • 92.123.12.157
  • 92.123.12.160
  • 92.123.12.149
  • 92.123.12.167
  • 92.123.12.154
  • 92.123.12.152
  • 92.123.12.170
  • 92.123.12.159
whitelisted
img-s-msn-com.akamaized.net
  • 2.19.126.157
  • 2.19.126.146
  • 2.16.164.32
  • 2.16.164.74
  • 2.21.20.136
  • 2.21.20.134
whitelisted
sb.scorecardresearch.com
  • 13.32.121.37
  • 13.32.121.72
  • 13.32.121.17
  • 13.32.121.21
  • 13.249.9.34
  • 13.249.9.35
  • 13.249.9.65
  • 13.249.9.46
  • 65.9.25.30
  • 65.9.25.49
  • 65.9.25.86
  • 65.9.25.34
shared

Threats

PID
Process
Class
Message
3524
CCSetup.exe
Misc activity
ET INFO Installshield One Click Install User-Agent Toys File
3524
CCSetup.exe
Misc activity
ET INFO Installshield One Click Install User-Agent Toys File
No debug info