URL:

download01.logi.com/web/ftp/pub/techsupport/optionsplus/logioptionsplus_installer.exe

Full analysis: https://app.any.run/tasks/08cce484-21c4-4211-bc71-c78a2e2907cc
Verdict: Malicious activity
Analysis date: September 16, 2024, 18:03:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

3459789E69891106613A1B7C4B989291

SHA1:

569D36891A64FE2F4F5AD0826CE4037D135B2ACA

SHA256:

F515151242CB9AB8DFD000E46309DA404B313EFDBA6182151409DCB523646C64

SSDEEP:

3:ZKIV2OD6GmKO8gKd0kOXLNn:Z7V2a6P9kOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
    • Reads the date of Windows installation

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
    • Executable content was dropped or overwritten

      • logioptionsplus_setup.exe (PID: 6644)
      • vc_redist.x64.exe (PID: 4064)
      • vc_redist.x64.exe (PID: 6576)
    • Searches for installed software

      • vc_redist.x64.exe (PID: 6576)
    • Starts a Microsoft application from unusual location

      • vc_redist.x64.exe (PID: 6576)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 532)
    • The process uses the downloaded file

      • chrome.exe (PID: 1944)
      • chrome.exe (PID: 532)
      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
    • Checks supported languages

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
      • vc_redist.x64.exe (PID: 4064)
      • vc_redist.x64.exe (PID: 6576)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 532)
      • chrome.exe (PID: 1932)
    • Reads the computer name

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
      • vc_redist.x64.exe (PID: 6576)
    • Create files in a temporary directory

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
      • vc_redist.x64.exe (PID: 6576)
    • Process checks computer location settings

      • logioptionsplus_installer.exe (PID: 1332)
      • logioptionsplus_setup.exe (PID: 6644)
    • Reads the machine GUID from the registry

      • logioptionsplus_setup.exe (PID: 6644)
    • Creates files or folders in the user directory

      • logioptionsplus_setup.exe (PID: 6644)
    • Reads Environment values

      • logioptionsplus_setup.exe (PID: 6644)
    • Creates files in the program directory

      • logioptionsplus_setup.exe (PID: 6644)
    • Sends debugging messages

      • logioptionsplus_setup.exe (PID: 6644)
    • Disables trace logs

      • logioptionsplus_setup.exe (PID: 6644)
    • Reads the software policy settings

      • slui.exe (PID: 2008)
      • logioptionsplus_setup.exe (PID: 6644)
      • slui.exe (PID: 1436)
    • Checks proxy server information

      • logioptionsplus_setup.exe (PID: 6644)
      • slui.exe (PID: 1436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
28
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs logioptionsplus_installer.exe no specs logioptionsplus_setup.exe no specs logioptionsplus_setup.exe vc_redist.x64.exe vc_redist.x64.exe sppextcomobj.exe no specs slui.exe chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "download01.logi.com/web/ftp/pub/techsupport/optionsplus/logioptionsplus_installer.exe"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1332"C:\Users\admin\Downloads\logioptionsplus_installer.exe" C:\Users\admin\Downloads\logioptionsplus_installer.exechrome.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logi Options+ Installer
Version:
1.82.618412
Modules
Images
c:\users\admin\downloads\logioptionsplus_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\combase.dll
c:\windows\system32\win32u.dll
1436C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1640"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4472 --field-trial-handle=1956,i,17538408286028399939,2196818523444581385,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1932"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5316 --field-trial-handle=1956,i,17538408286028399939,2196818523444581385,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1944"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5328 --field-trial-handle=1956,i,17538408286028399939,2196818523444581385,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2008"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2456"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x21c,0x220,0x224,0x1fc,0x228,0x7fffd23fdc40,0x7fffd23fdc4c,0x7fffd23fdc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2484"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5520 --field-trial-handle=1956,i,17538408286028399939,2196818523444581385,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3876"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5840 --field-trial-handle=1956,i,17538408286028399939,2196818523444581385,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
16 310
Read events
15 587
Write events
716
Delete events
7

Modification events

(PID) Process:(532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(532) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(1944) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
010000000000000071A151D46208DB01
(PID) Process:(6644) logioptionsplus_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\logioptionsplus_setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6644) logioptionsplus_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\logioptionsplus_setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6644) logioptionsplus_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\logioptionsplus_setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6644) logioptionsplus_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\logioptionsplus_setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
169
Suspicious files
920
Text files
896
Unknown types
10

Dropped files

PID
Process
Filename
Type
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF12b33b.TMP
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF12b33b.TMP
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:FC81892AC822DCBB09441D3B58B47125
SHA256:FB077C966296D02D50CCBF7F761D2A3311A206A784A7496F331C2B0D6AD205C8
532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\df3a7c2a-f577-430b-96c7-f1629693bcb5.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
75
DNS requests
37
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
5612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
1764
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6332
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6332
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
532
chrome.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAEboSlx5RDqds3OEWVr%2Fn4%3D
unknown
whitelisted
532
chrome.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
5612
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/V3P1l2hLvLw_7/7_all_sslErrorAssistant.crx3
unknown
whitelisted
768
lsass.exe
GET
200
108.156.23.221:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6516
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
532
chrome.exe
239.255.255.250:1900
whitelisted
4444
chrome.exe
52.222.214.93:80
download01.logi.com
AMAZON-02
US
shared
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4444
chrome.exe
52.222.214.93:443
download01.logi.com
AMAZON-02
US
shared
4444
chrome.exe
74.125.133.84:443
accounts.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 52.167.17.97
  • 20.44.239.154
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 172.217.18.14
whitelisted
download01.logi.com
  • 52.222.214.93
  • 52.222.214.123
  • 52.222.214.6
  • 52.222.214.7
shared
client.wns.windows.com
  • 40.113.103.199
whitelisted
accounts.google.com
  • 74.125.133.84
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.71
  • 40.126.31.67
  • 20.190.159.73
  • 40.126.31.69
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.google.com
  • 142.250.184.228
whitelisted
sb-ssl.google.com
  • 142.250.181.238
whitelisted

Threats

No threats detected
Process
Message
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - MainWindow - Start
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - SetupLogging - Logging path is not specified explicitly by user, using temporary one: C:\Users\admin\AppData\Local\Temp\1.82.618412_126d9f26-337d-4ed7-b42d-ea7828ee4b21
logioptionsplus_setup.exe
09/16/2024 18:04:21 - Core - UnpackResource - PageInstalled.gif
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - FocusExistingApp - Start
logioptionsplus_setup.exe
09/16/2024 18:04:21 - Core - UnpackResource - PageUnsupportedOs.gif
logioptionsplus_setup.exe
09/16/2024 18:04:21 - Core - UnpackResource - PageLegacyOptions.gif
logioptionsplus_setup.exe
09/16/2024 18:04:21 - Core - UnpackResource - crashpad_handler.exe
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - MainWindow - FormatAdminCommandLineParams: --install-event=4817ac1c-8284-4da3-ba5f-e9b7e5a72abb.optionsplus_install_finish_event
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - FormatAdminCommandLineParams - Not recognized param: install-event=4817ac1c-8284-4da3-ba5f-e9b7e5a72abb.optionsplus_install_finish_event
logioptionsplus_setup.exe
09/16/2024 18:04:21 - MainWindow - MainWindow - Admin command line arguments: --analytics Yes --flow Yes --sso Yes --update Yes --dfu Yes --backlight Yes --logivoice Yes --aipromptbuilder Yes --device-recommendation Yes --no-keys-sync-on-install No