File name:

filerenamerturbo-setup.exe

Full analysis: https://app.any.run/tasks/1c5f9404-3c32-45ae-9727-4be7e152dab4
Verdict: Malicious activity
Analysis date: May 29, 2025, 00:57:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

6D917F44CBF98173F2348D07021D8AC4

SHA1:

4D1D785205B6CA665B217908F0E1BF6B81029C71

SHA256:

F5389039B1B25EAED88E84EC8D22510D616348110D4B01F4178F712658BCF4EB

SSDEEP:

98304:NxVI2rfvncnSydo4FQCBrZAi4azWQEyvJlu6SnSYxPuyEZsgqG3MHmeqJSKWGwQF:61leWmwV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • filerenamerturbo-setup.exe (PID: 976)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • filerenamerturbo-setup.exe (PID: 976)
    • The process creates files with name similar to system file names

      • filerenamerturbo-setup.exe (PID: 976)
    • Executable content was dropped or overwritten

      • filerenamerturbo-setup.exe (PID: 976)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2096)
    • Creates a software uninstall entry

      • filerenamerturbo-setup.exe (PID: 976)
    • There is functionality for taking screenshot (YARA)

      • filerenamerturbo-setup.exe (PID: 976)
    • Reads security settings of Internet Explorer

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
    • Adds/modifies Windows certificates

      • File Renamer Turbo.exe (PID: 4740)
  • INFO

    • The sample compiled with english language support

      • filerenamerturbo-setup.exe (PID: 976)
    • Reads the computer name

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
      • identity_helper.exe (PID: 7252)
      • identity_helper.exe (PID: 5392)
    • Creates files or folders in the user directory

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
    • Checks supported languages

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
      • identity_helper.exe (PID: 5392)
      • identity_helper.exe (PID: 7252)
    • Creates files in the program directory

      • filerenamerturbo-setup.exe (PID: 976)
    • Create files in a temporary directory

      • filerenamerturbo-setup.exe (PID: 976)
    • Application launched itself

      • msedge.exe (PID: 2108)
      • msedge.exe (PID: 3096)
      • msedge.exe (PID: 7796)
    • Manual execution by a user

      • msedge.exe (PID: 3096)
    • Reads the machine GUID from the registry

      • File Renamer Turbo.exe (PID: 4740)
    • Reads the software policy settings

      • File Renamer Turbo.exe (PID: 4740)
    • Checks proxy server information

      • File Renamer Turbo.exe (PID: 4740)
    • Reads Environment values

      • identity_helper.exe (PID: 7252)
      • identity_helper.exe (PID: 5392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:53:24+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 169984
UninitializedDataSize: 1024
EntryPoint: 0x355e
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Kristanix Software
FileDescription: File Renamer Turbo
FileVersion: 01.00.00.00
LegalCopyright: © 2013 Kristanix Software
ProductName: File Renamer Turbo
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
53
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start filerenamerturbo-setup.exe sppextcomobj.exe no specs slui.exe no specs regsvr32.exe no specs regsvr32.exe no specs msedge.exe no specs file renamer turbo.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs filerenamerturbo-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3752 --field-trial-handle=2444,i,9718602690257878373,15939932061601445275,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4528 --field-trial-handle=2444,i,9718602690257878373,15939932061601445275,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
976"C:\Users\admin\AppData\Local\Temp\filerenamerturbo-setup.exe" C:\Users\admin\AppData\Local\Temp\filerenamerturbo-setup.exe
explorer.exe
User:
admin
Company:
Kristanix Software
Integrity Level:
HIGH
Description:
File Renamer Turbo
Exit code:
0
Version:
01.00.00.00
Modules
Images
c:\users\admin\appdata\local\temp\filerenamerturbo-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2096 /s "C:\Program Files (x86)\File Renamer Turbo\shell.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2108"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.kristanixsoftware.com/getstarted.php?id=FRTC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exefilerenamerturbo-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2316"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3904 --field-trial-handle=2356,i,5710175533958983673,11090194009888501342,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x314,0x318,0x31c,0x310,0x324,0x7ffc89985fd8,0x7ffc89985fe4,0x7ffc89985ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x1e0,0x294,0x298,0x290,0x2a0,0x7ffc89985fd8,0x7ffc89985fe4,0x7ffc89985ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument http://www.kristanixsoftware.com/getstarted.php?id=FRTC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
13 952
Read events
13 896
Write events
50
Delete events
6

Modification events

(PID) Process:(2096) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{7E3131FF-1322-22E5-9E3B-555664651111}
Value:
FileRenamerTurboShell extension
(PID) Process:(2096) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E3131FF-1322-22E5-9E3B-555664651111}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\File Renamer Turbo
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\File Renamer Turbo
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayName
Value:
File Renamer Turbo
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\File Renamer Turbo\uninstall.exe
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\File Renamer Turbo\File Renamer Turbo.exe
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayVersion
Value:
01.00.00.00
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:Publisher
Value:
Kristanix Software
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:URLInfoAbout
Value:
http://www.kristanixsoftware.com/redirect.php?f=PL-FR001&t=HP-FR
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
22
Suspicious files
108
Text files
70
Unknown types
1

Dropped files

PID
Process
Filename
Type
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\DevExpress.Utils.v8.1.dllexecutable
MD5:7E4C8FD90DEAEAA313EE1C1A2E7E4676
SHA256:7F88E09F6753FDE4ACAC64A62C073DF2A631E07A903F54BDD70EDE83FF80C71C
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\casinglist-example.txttext
MD5:B8F4F103C47749E23FD24557D7076049
SHA256:0945427B4595FA58BB4CF708F81A0A7F7322ED39BDDBEA6B78C8C8317155452E
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Add today's date to file names.frptext
MD5:DA9D40E5B4C8442CD04467924AFF368C
SHA256:EEB65EF81CD0A47A96B085ABB7835A0D35AA592842706879DF4526A015273A76
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Search Music Album Online.frptext
MD5:308D1A9F044CEFFCA0BDD4F0DBCE2AAF
SHA256:C2A63DA2AE3AE9FDB733A3713CEFAE20C30DC7FD0289973FDCADE88AB7172C99
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\DevExpress.Data.v8.1.dllexecutable
MD5:A249B79E943CB33256C76824E3442141
SHA256:BCD3BA66B163835C951BA5CEA17357709A08820331BD791DF768F627206EC9C7
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Clean-up file names.frptext
MD5:9AEA8C722816A44423CC46866643FB1C
SHA256:3BC0431CE4F79B5444ED15AE78CE9D462E5794EC60614935A28F984A64316303
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
45
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
404
172.64.149.23:80
http://crl.usertrust.com/AddTrustExternalCARoot.crl
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEC58h8wOk0pS%2FpT9HLfNNK8%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSSdxXdG447ymkRNPVViULv3rkBzQQUKZFg%2F4pN%2Buv5pmq4z%2FnmS71JzhICEGZ4dc3zLKJSn6OiIb4illk%3D
unknown
whitelisted
3304
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
4
System
192.168.100.255:138
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.67
  • 20.190.160.2
  • 20.190.160.64
  • 20.190.160.4
  • 20.190.160.130
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.kristanixsoftware.com
  • 209.59.160.25
unknown
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted

Threats

No threats detected
No debug info