File name:

rcsetup153.exe

Full analysis: https://app.any.run/tasks/e2de6591-4f9b-4cad-aba1-49bcbaff3068
Verdict: Malicious activity
Analysis date: December 14, 2023, 22:40:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A8B8AB47CB3124FB373D526E0992EDBC

SHA1:

6309FF089057DF60264689DC8B201A0E2DCE967C

SHA256:

F5463E767123F678C2B8DC71738696A24C6F8E5286D8BB98B9A0D81E4375EEA7

SSDEEP:

393216:gbTkXmQB3tw5Xctkv7Kog1taovYKbjNiyPUgluL:gbwGquXg1AaNmglu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rcsetup153.exe (PID: 1152)
    • Steals credentials from Web Browsers

      • taskhost.exe (PID: 3740)
      • rcsetup153.exe (PID: 1152)
    • Actions looks like stealing of personal data

      • rcsetup153.exe (PID: 1152)
    • Registers / Runs the DLL via REGSVR32.EXE

      • rcsetup153.exe (PID: 1152)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • rcsetup153.exe (PID: 1152)
    • Reads Internet Explorer settings

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Executes as Windows Service

      • taskhost.exe (PID: 3740)
      • VSSVC.exe (PID: 904)
    • The process creates files with name similar to system file names

      • rcsetup153.exe (PID: 1152)
    • Reads browser cookies

      • rcsetup153.exe (PID: 1152)
    • Reads the Internet Settings

      • rcsetup153.exe (PID: 1152)
      • taskhost.exe (PID: 3740)
      • recuva.exe (PID: 3956)
    • Searches for installed software

      • rcsetup153.exe (PID: 1152)
    • Reads settings of System Certificates

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Reads security settings of Internet Explorer

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Connects to the server without a host name

      • rcsetup153.exe (PID: 1152)
    • Process requests binary or script from the Internet

      • rcsetup153.exe (PID: 1152)
    • Checks Windows Trust Settings

      • recuva.exe (PID: 3956)
      • rcsetup153.exe (PID: 1152)
  • INFO

    • Checks supported languages

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3484)
      • recuva.exe (PID: 3956)
      • wmpnscfg.exe (PID: 3948)
    • Reads the computer name

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3484)
      • recuva.exe (PID: 3956)
      • wmpnscfg.exe (PID: 3948)
    • Reads Environment values

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Dropped object may contain TOR URL's

      • rcsetup153.exe (PID: 1152)
    • Create files in a temporary directory

      • rcsetup153.exe (PID: 1152)
    • Creates files or folders in the user directory

      • rcsetup153.exe (PID: 1152)
      • taskhost.exe (PID: 3740)
    • Checks proxy server information

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Reads the machine GUID from the registry

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Creates files in the program directory

      • rcsetup153.exe (PID: 1152)
      • recuva.exe (PID: 3956)
    • Application launched itself

      • msedge.exe (PID: 3888)
      • msedge.exe (PID: 2096)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3948)
      • msedge.exe (PID: 2096)
    • Reads product name

      • recuva.exe (PID: 3956)
    • Reads CPU info

      • recuva.exe (PID: 3956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:26 00:04:50+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 428544
UninitializedDataSize: 16384
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.53.0.2095
ProductVersionNumber: 1.53.0.2095
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Piriform Software Ltd
FileDescription: Recuva Installer
FileVersion: 1.53.0.2095
LegalCopyright: Copyright © 2006-2023 Piriform Software Ltd
ProductName: Recuva
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
21
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rcsetup153.exe taskhost.exe regsvr32.exe no specs recuva.exe no specs msedge.exe no specs recuva.exe msedge.exe no specs wmpnscfg.exe no specs vssvc.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rcsetup153.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1216 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1544 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
644"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2344 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
904C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1032regsvr32.exe /I "C:\Program Files\Recuva\RecuvaShell.dll" /sC:\Windows\System32\regsvr32.exercsetup153.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1152"C:\Users\admin\Desktop\rcsetup153.exe" C:\Users\admin\Desktop\rcsetup153.exe
explorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
Recuva Installer
Exit code:
0
Version:
1.53.0.2095
Modules
Images
c:\users\admin\desktop\rcsetup153.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1576"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1864"C:\Users\admin\Desktop\rcsetup153.exe" C:\Users\admin\Desktop\rcsetup153.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
Recuva Installer
Exit code:
3221226540
Version:
1.53.0.2095
Modules
Images
c:\users\admin\desktop\rcsetup153.exe
c:\windows\system32\ntdll.dll
2080"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1420 --field-trial-handle=1380,i,2988972612266788009,4472433726871695013,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2084"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6913f598,0x6913f5a8,0x6913f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 305
Read events
10 169
Write events
129
Delete events
7

Modification events

(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
5AFF46735A9F8FAF53F4367D7555C5B33351AD1E069F5C470C116E5DAF7EC4D8
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
BF45A1178E3AB885805E02C77A5F1D7CD46AB27A653C6D91D7FBDD3C40898B70
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
8A4B6D41AB1B478E9809E87065EE15FBA7A64E58F004BD08EC4890FA7EDBF2A5
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
80040000B06B1D92DE2EDA01
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1152) rcsetup153.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
100
Suspicious files
61
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\RC_Computer.pngimage
MD5:67F13E50FA75087EF8C2074A52CC8BB1
SHA256:044EC2D36E9F573D762FC8A43EB09F7B24EB30094A4E61B5D606FD96F72D391F
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\p\InstallerHelper.dllexecutable
MD5:0DAD2A4D7AA36A106E6599BE16EBA1AF
SHA256:203FC77376100FFA166D4593B27003CB3A82D7516764F1886C66A9A7BBB1D38C
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\Montserrat-Regular.otfbinary
MD5:27E50FFD6A14CBC8221C9DBD3B5208DC
SHA256:40FC1142200A5C1C18F80B6915257083C528C7F7FD2B00A552AEEBC42898D428
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1041.dllexecutable
MD5:10CEC1E9DE4C2E3B3E3C0CAED9B69D0B
SHA256:E33DDE8ED6DBEFC2945A6C0FF82EB148E432F9F8E771E7AF0A040111D9D23E43
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\UserInfo.dllexecutable
MD5:2F69AFA9D17A5245EC9B5BB03D56F63C
SHA256:E54989D2B83E7282D0BEC56B098635146AAB5D5A283F1F89486816851EF885A0
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1053.dllexecutable
MD5:1181929E3ECDADED7B5526C2084CF7EC
SHA256:B1B96DABB98F5C3C0238CCC964F03E9B03885AE551146AA90E547958A2E4F14E
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\g\gcapi_dll.dllexecutable
MD5:2973AF8515EFFD0A3BFC7A43B03B3FCC
SHA256:D0E4581210A22135CE5DEB47D9DF4D636A94B3813E0649AAB84822C9F08AF2A0
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1031.dllexecutable
MD5:265BE91935B61C63CBA03F4B7F05CF7F
SHA256:7C357F11264C03E881CD604B3E8D1D36EFF1CC0BF0F9728E478B178C25A962DE
1152rcsetup153.exeC:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1043.dllexecutable
MD5:AA9AAD1C5C880EA0F48095D50D302FD6
SHA256:08B61F09BA0997A01A82EE650E1D7EFB14380F98D76AE905FDC80659AA5DB70A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
32
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?440741f4bd306e5a
unknown
xml
341 b
unknown
1152
rcsetup153.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9be5154f17c53811
unknown
xml
341 b
unknown
3956
recuva.exe
GET
404
49.13.77.253:80
http://www.ccleaner.com/auto?p=rc&v=1.53.2095&l=1033&a=0&lk=&mk=IH82-8AEJ-BB4F-FSU3-EWAI-2TTB-7NKN-5AZH-HZ8S&o=6.1W3
unknown
xml
341 b
unknown
608
msedge.exe
GET
404
49.13.77.253:80
http://www.ccleaner.com/go/app_releasenotes?p=2&v=1.53.2095&l=1033&b=1&a=0
unknown
xml
341 b
unknown
608
msedge.exe
GET
404
49.13.77.253:80
http://www.ccleaner.com/favicon.ico
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e0032a321da2bdc4
unknown
xml
341 b
unknown
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c06f5c0780293fe1
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d3beddd762d67162
unknown
xml
341 b
unknown
484
lsass.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?153435dafcbdd709
unknown
xml
341 b
unknown
1080
svchost.exe
GET
404
49.13.77.253:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?abdc0569852e700a
unknown
xml
341 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1152
rcsetup153.exe
49.13.77.253:443
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
484
lsass.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
1152
rcsetup153.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
3956
recuva.exe
49.13.77.253:443
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
3956
recuva.exe
49.13.77.253:80
analytics.ff.avast.com
Hetzner Online GmbH
DE
unknown
2096
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
analytics.ff.avast.com
  • 49.13.77.253
whitelisted
ctldl.windowsupdate.com
  • 49.13.77.253
whitelisted
service.piriform.com
  • 49.13.77.253
whitelisted
www.ccleaner.com
  • 49.13.77.253
whitelisted
config.edge.skype.com
  • 49.13.77.253
whitelisted
edge.microsoft.com
  • 49.13.77.253
whitelisted
www.bing.com
  • 49.13.77.253
whitelisted

Threats

PID
Process
Class
Message
3956
recuva.exe
Misc activity
ET POLICY Recuva File Recovery Software - Observed User-Agent
No debug info