File name:

rcsetup153.exe

Full analysis: https://app.any.run/tasks/e2de6591-4f9b-4cad-aba1-49bcbaff3068
Verdict: Malicious activity
Analysis date: December 14, 2023, 22:40:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A8B8AB47CB3124FB373D526E0992EDBC

SHA1:

6309FF089057DF60264689DC8B201A0E2DCE967C

SHA256:

F5463E767123F678C2B8DC71738696A24C6F8E5286D8BB98B9A0D81E4375EEA7

SSDEEP:

393216:gbTkXmQB3tw5Xctkv7Kog1taovYKbjNiyPUgluL:gbwGquXg1AaNmglu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • taskhost.exe (PID: 3740)
      • rcsetup153.exe (PID: 1152)
    • Actions looks like stealing of personal data

      • rcsetup153.exe (PID: 1152)
    • Drops the executable file immediately after the start

      • rcsetup153.exe (PID: 1152)
    • Registers / Runs the DLL via REGSVR32.EXE

      • rcsetup153.exe (PID: 1152)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • rcsetup153.exe (PID: 1152)
    • Reads Internet Explorer settings

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Executes as Windows Service

      • taskhost.exe (PID: 3740)
      • VSSVC.exe (PID: 904)
    • Reads browser cookies

      • rcsetup153.exe (PID: 1152)
    • Reads the Internet Settings

      • rcsetup153.exe (PID: 1152)
      • taskhost.exe (PID: 3740)
      • recuva.exe (PID: 3956)
    • The process creates files with name similar to system file names

      • rcsetup153.exe (PID: 1152)
    • Reads settings of System Certificates

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Checks Windows Trust Settings

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Process requests binary or script from the Internet

      • rcsetup153.exe (PID: 1152)
    • Reads security settings of Internet Explorer

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Searches for installed software

      • rcsetup153.exe (PID: 1152)
    • Connects to the server without a host name

      • rcsetup153.exe (PID: 1152)
  • INFO

    • Reads the computer name

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3484)
      • recuva.exe (PID: 3956)
      • wmpnscfg.exe (PID: 3948)
    • Checks supported languages

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
      • recuva.exe (PID: 3484)
      • wmpnscfg.exe (PID: 3948)
    • Reads Environment values

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Dropped object may contain TOR URL's

      • rcsetup153.exe (PID: 1152)
    • Create files in a temporary directory

      • rcsetup153.exe (PID: 1152)
    • Checks proxy server information

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Creates files or folders in the user directory

      • rcsetup153.exe (PID: 1152)
      • taskhost.exe (PID: 3740)
    • Reads the machine GUID from the registry

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Creates files in the program directory

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Application launched itself

      • msedge.exe (PID: 3888)
      • msedge.exe (PID: 2096)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3948)
      • msedge.exe (PID: 2096)
    • Reads product name

      • recuva.exe (PID: 3956)
    • Reads CPU info

      • recuva.exe (PID: 3956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:26 00:04:50+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 428544
UninitializedDataSize: 16384
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.53.0.2095
ProductVersionNumber: 1.53.0.2095
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Piriform Software Ltd
FileDescription: Recuva Installer
FileVersion: 1.53.0.2095
LegalCopyright: Copyright © 2006-2023 Piriform Software Ltd
ProductName: Recuva
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
21
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rcsetup153.exe taskhost.exe regsvr32.exe no specs recuva.exe no specs msedge.exe no specs recuva.exe msedge.exe no specs wmpnscfg.exe no specs vssvc.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rcsetup153.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1216 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1544 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
644"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2344 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
904C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1032regsvr32.exe /I "C:\Program Files\Recuva\RecuvaShell.dll" /sC:\Windows\System32\regsvr32.exercsetup153.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1152"C:\Users\admin\Desktop\rcsetup153.exe" C:\Users\admin\Desktop\rcsetup153.exe
explorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
Recuva Installer
Exit code:
0
Version:
1.53.0.2095
Modules
Images
c:\users\admin\desktop\rcsetup153.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1576"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1864"C:\Users\admin\Desktop\rcsetup153.exe" C:\Users\admin\Desktop\rcsetup153.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
Recuva Installer
Exit code:
3221226540
Version:
1.53.0.2095
Modules
Images
c:\users\admin\desktop\rcsetup153.exe
c:\windows\system32\ntdll.dll
2080"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1420 --field-trial-handle=1380,i,2988972612266788009,4472433726871695013,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2084"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6913f598,0x6913f5a8,0x6913f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 305
Read events
10 169
Write events
129
Delete events
7

Modification events

(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
5AFF46735A9F8FAF53F4367D7555C5B33351AD1E069F5C470C116E5DAF7EC4D8
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
BF45A1178E3AB885805E02C77A5F1D7CD46AB27A653C6D91D7FBDD3C40898B70
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
8A4B6D41AB1B478E9809E87065EE15FBA7A64E58F004BD08EC4890FA7EDBF2A5
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
80040000B06B1D92DE2EDA01
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
100
Suspicious files
61
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\UserInfo.dllexecutable
MD5:2F69AFA9D17A5245EC9B5BB03D56F63C
SHA256:E54989D2B83E7282D0BEC56B098635146AAB5D5A283F1F89486816851EF885A0
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\pfUI.dllexecutable
MD5:F7222368C66E02EE333E6FCA4FDCCB66
SHA256:B09F1359C68947C7D13123DDA3AB56360B982BEFB43C134BE815934ED4879215
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\PF_logo.pngimage
MD5:079CCA30760CCA3C01863B6B96E87848
SHA256:8DD37D3721E25C32C5BF878B6DBA9E61D04B7CE8AEC45BDF703A41BC41802DFA
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1053.dllexecutable
MD5:1181929E3ECDADED7B5526C2084CF7EC
SHA256:B1B96DABB98F5C3C0238CCC964F03E9B03885AE551146AA90E547958A2E4F14E
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\Recuva_Logo_72px.pngimage
MD5:6A2E01749E591A1CE8216DAED41B8721
SHA256:F72782600989EFF0AA13FF7C63875538C9042C32B77862475C899514F61C9290
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\Montserrat-Regular.otfbinary
MD5:27E50FFD6A14CBC8221C9DBD3B5208DC
SHA256:40FC1142200A5C1C18F80B6915257083C528C7F7FD2B00A552AEEBC42898D428
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1040.dllexecutable
MD5:1B76D1E1721505BB78E244CA9F4B4592
SHA256:7000A53F92557E349FD06A7D8C243D15EB934F07E85FB384B331EEBB429296C2
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\g\gcapi_dll.dllexecutable
MD5:2973AF8515EFFD0A3BFC7A43B03B3FCC
SHA256:D0E4581210A22135CE5DEB47D9DF4D636A94B3813E0649AAB84822C9F08AF2A0
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\RC_Computer.pngimage
MD5:67F13E50FA75087EF8C2074A52CC8BB1
SHA256:044EC2D36E9F573D762FC8A43EB09F7B24EB30094A4E61B5D606FD96F72D391F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
32
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
608
msedge.exe
GET
404
49.13.77.253:80
http://www.ccleaner.com/go/app_releasenotes?p=2&v=1.53.2095&l=1033&b=1&a=0
unknown
xml
341 b
unknown
608
msedge.exe
GET
404
49.13.77.253:80
http://www.ccleaner.com/favicon.ico
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e0032a321da2bdc4
unknown
xml
341 b
unknown
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?153435dafcbdd709
unknown
xml
341 b
unknown
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c06f5c0780293fe1
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?86cdc092d7002690
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d3beddd762d67162
unknown
xml
341 b
unknown
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?440741f4bd306e5a
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?abdc0569852e700a
unknown
xml
341 b
unknown
608
msedge.exe
GET
404
49.13.77.253:443
https://49.13.77.253/extensionwebstorebase/v1/logextensionreliability?success=false&cv=&errorString=MANIFEST_FETCH_FAILED&crxId=jmjflgjpcpepeafmmgdpfkogkghcpiha&os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-US&acceptformat=crx3
unknown
xml
341 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1152
rcsetup153.exe
49.13.77.253:443
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
484
lsass.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
1152
rcsetup153.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
3956
recuva.exe
49.13.77.253:443
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
3956
recuva.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
2096
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
analytics.ff.avast.com
  • 49.13.77.253
whitelisted
ctldl.windowsupdate.com
  • 49.13.77.253
whitelisted
service.piriform.com
  • 49.13.77.253
whitelisted
www.ccleaner.com
  • 49.13.77.253
whitelisted
config.edge.skype.com
  • 49.13.77.253
whitelisted
edge.microsoft.com
  • 49.13.77.253
whitelisted
www.bing.com
  • 49.13.77.253
whitelisted

Threats

PID
Process
Class
Message
3956
recuva.exe
Misc activity
ET POLICY Recuva File Recovery Software - Observed User-Agent
No debug info