File name:

filerenamerturbo-setup.exe

Full analysis: https://app.any.run/tasks/1c5f9404-3c32-45ae-9727-4be7e152dab4
Verdict: Malicious activity
Analysis date: May 29, 2025, 00:57:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

6D917F44CBF98173F2348D07021D8AC4

SHA1:

4D1D785205B6CA665B217908F0E1BF6B81029C71

SHA256:

F5389039B1B25EAED88E84EC8D22510D616348110D4B01F4178F712658BCF4EB

SSDEEP:

98304:NxVI2rfvncnSydo4FQCBrZAi4azWQEyvJlu6SnSYxPuyEZsgqG3MHmeqJSKWGwQF:61leWmwV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • filerenamerturbo-setup.exe (PID: 976)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • filerenamerturbo-setup.exe (PID: 976)
    • Executable content was dropped or overwritten

      • filerenamerturbo-setup.exe (PID: 976)
    • Reads security settings of Internet Explorer

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
    • Adds/modifies Windows certificates

      • File Renamer Turbo.exe (PID: 4740)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2096)
    • The process creates files with name similar to system file names

      • filerenamerturbo-setup.exe (PID: 976)
    • There is functionality for taking screenshot (YARA)

      • filerenamerturbo-setup.exe (PID: 976)
    • Creates a software uninstall entry

      • filerenamerturbo-setup.exe (PID: 976)
  • INFO

    • The sample compiled with english language support

      • filerenamerturbo-setup.exe (PID: 976)
    • Checks supported languages

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
      • identity_helper.exe (PID: 7252)
      • identity_helper.exe (PID: 5392)
    • Application launched itself

      • msedge.exe (PID: 2108)
      • msedge.exe (PID: 3096)
      • msedge.exe (PID: 7796)
    • Reads the machine GUID from the registry

      • File Renamer Turbo.exe (PID: 4740)
    • Manual execution by a user

      • msedge.exe (PID: 3096)
    • Create files in a temporary directory

      • filerenamerturbo-setup.exe (PID: 976)
    • Reads the computer name

      • filerenamerturbo-setup.exe (PID: 976)
      • File Renamer Turbo.exe (PID: 4740)
      • identity_helper.exe (PID: 7252)
      • identity_helper.exe (PID: 5392)
    • Creates files in the program directory

      • filerenamerturbo-setup.exe (PID: 976)
    • Creates files or folders in the user directory

      • File Renamer Turbo.exe (PID: 4740)
      • filerenamerturbo-setup.exe (PID: 976)
    • Checks proxy server information

      • File Renamer Turbo.exe (PID: 4740)
    • Reads the software policy settings

      • File Renamer Turbo.exe (PID: 4740)
    • Reads Environment values

      • identity_helper.exe (PID: 7252)
      • identity_helper.exe (PID: 5392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:53:24+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 169984
UninitializedDataSize: 1024
EntryPoint: 0x355e
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Kristanix Software
FileDescription: File Renamer Turbo
FileVersion: 01.00.00.00
LegalCopyright: © 2013 Kristanix Software
ProductName: File Renamer Turbo
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
53
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start filerenamerturbo-setup.exe sppextcomobj.exe no specs slui.exe no specs regsvr32.exe no specs regsvr32.exe no specs msedge.exe no specs file renamer turbo.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs filerenamerturbo-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3752 --field-trial-handle=2444,i,9718602690257878373,15939932061601445275,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4528 --field-trial-handle=2444,i,9718602690257878373,15939932061601445275,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
976"C:\Users\admin\AppData\Local\Temp\filerenamerturbo-setup.exe" C:\Users\admin\AppData\Local\Temp\filerenamerturbo-setup.exe
explorer.exe
User:
admin
Company:
Kristanix Software
Integrity Level:
HIGH
Description:
File Renamer Turbo
Exit code:
0
Version:
01.00.00.00
Modules
Images
c:\users\admin\appdata\local\temp\filerenamerturbo-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2096 /s "C:\Program Files (x86)\File Renamer Turbo\shell.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2108"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.kristanixsoftware.com/getstarted.php?id=FRTC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exefilerenamerturbo-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2316"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3904 --field-trial-handle=2356,i,5710175533958983673,11090194009888501342,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x314,0x318,0x31c,0x310,0x324,0x7ffc89985fd8,0x7ffc89985fe4,0x7ffc89985ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x1e0,0x294,0x298,0x290,0x2a0,0x7ffc89985fd8,0x7ffc89985fe4,0x7ffc89985ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument http://www.kristanixsoftware.com/getstarted.php?id=FRTC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
13 952
Read events
13 896
Write events
50
Delete events
6

Modification events

(PID) Process:(2096) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{7E3131FF-1322-22E5-9E3B-555664651111}
Value:
FileRenamerTurboShell extension
(PID) Process:(2096) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E3131FF-1322-22E5-9E3B-555664651111}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\File Renamer Turbo
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\File Renamer Turbo
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayName
Value:
File Renamer Turbo
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\File Renamer Turbo\uninstall.exe
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\File Renamer Turbo\File Renamer Turbo.exe
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:DisplayVersion
Value:
01.00.00.00
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:Publisher
Value:
Kristanix Software
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Renamer Turbo
Operation:writeName:URLInfoAbout
Value:
http://www.kristanixsoftware.com/redirect.php?f=PL-FR001&t=HP-FR
(PID) Process:(976) filerenamerturbo-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
22
Suspicious files
108
Text files
70
Unknown types
1

Dropped files

PID
Process
Filename
Type
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\GetVersion.dllexecutable
MD5:DC9562578490DF8BC464071F125BFC19
SHA256:0351FE33A6EB13417437C1BAAEE248442FB1ECC2C65940C9996BCDA574677C3F
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Add width x height to video file names.frptext
MD5:278EC0205D02D3D6E8D4716046C45FE4
SHA256:3F500DA224E8028FCD0BC20982A2B3C7D4F590175423273B32D18EC9EC4297A5
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Clean-up file names.frptext
MD5:9AEA8C722816A44423CC46866643FB1C
SHA256:3BC0431CE4F79B5444ED15AE78CE9D462E5794EC60614935A28F984A64316303
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\Helpfile.chmchm
MD5:FEADE66E3A3A12C9A1D8126D3DFBAB64
SHA256:7AC5F3FB7E6726B7BEA2D633A3555B9DA8894981BCA064034465B3C0F84C0DBF
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Roaming\Kristanix Software\File Renamer Turbo\1.0.0.0\Profiles\Search Music Album Online.frptext
MD5:308D1A9F044CEFFCA0BDD4F0DBCE2AAF
SHA256:C2A63DA2AE3AE9FDB733A3713CEFAE20C30DC7FD0289973FDCADE88AB7172C99
976filerenamerturbo-setup.exeC:\Users\admin\AppData\Local\Temp\nsqB921.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\DevExpress.XtraBars.v8.1.dllexecutable
MD5:92858AA4361C9E48E1A6E04A0B2111E1
SHA256:57EF03BE94AD1D4E9971E96960D8F7B99F17100F3726B13100551D7A5BB0A8C3
976filerenamerturbo-setup.exeC:\Program Files (x86)\File Renamer Turbo\DevExpress.Utils.v8.1.dllexecutable
MD5:7E4C8FD90DEAEAA313EE1C1A2E7E4676
SHA256:7F88E09F6753FDE4ACAC64A62C073DF2A631E07A903F54BDD70EDE83FF80C71C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
45
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEC58h8wOk0pS%2FpT9HLfNNK8%3D
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSSdxXdG447ymkRNPVViULv3rkBzQQUKZFg%2F4pN%2Buv5pmq4z%2FnmS71JzhICEGZ4dc3zLKJSn6OiIb4illk%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D
unknown
whitelisted
3304
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4740
File Renamer Turbo.exe
GET
404
172.64.149.23:80
http://crl.usertrust.com/AddTrustExternalCARoot.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
4
System
192.168.100.255:138
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.67
  • 20.190.160.2
  • 20.190.160.64
  • 20.190.160.4
  • 20.190.160.130
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.kristanixsoftware.com
  • 209.59.160.25
unknown
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted

Threats

No threats detected
No debug info