URL:

https://l.gourl.es/l/9e66655d11c5a408051a0bc6ed2caa67ba87e4c8?u=13106332

Full analysis: https://app.any.run/tasks/d3297502-7f65-4175-b16d-b6eb73a8c868
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: November 10, 2025, 11:36:50
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
rat
anti-evasion
Indicators:
MD5:

012FA8207CAD383B9E5512583ADF6D9D

SHA1:

AA94ECF1F3D99A89176A401C1ED3915FB74E0F92

SHA256:

F8442EB2B1301B52A265486BA40FFF591F795D25D2CAB97C68CD8B1E8AC5D5E6

SSDEEP:

3:N8LJC6bWTT7NkTQdtAYr/db5WMdXn:2tkTXNkTQAYr/eMdX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Acrobat_Reader_V112.exe (PID: 5352)
      • agent.tmp (PID: 7452)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • agent.tmp (PID: 7748)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.tmp (PID: 2436)
      • agent.tmp (PID: 2772)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • Acrobat_Reader_V112.exe (PID: 1548)
    • Executable content was dropped or overwritten

      • Acrobat_Reader_V112.exe (PID: 5352)
      • agent.exe (PID: 5724)
      • agent.exe (PID: 6004)
      • agent.tmp (PID: 2816)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • agent.exe (PID: 1312)
      • agent.exe (PID: 6904)
      • agent.tmp (PID: 4764)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.exe (PID: 6492)
      • agent.exe (PID: 7492)
      • agent.tmp (PID: 7448)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • agent.exe (PID: 7676)
      • agent.exe (PID: 2948)
      • agent.tmp (PID: 2360)
      • Acrobat_Reader_V112.exe (PID: 1548)
      • agent.exe (PID: 7504)
      • agent.tmp (PID: 7520)
    • Process drops legitimate windows executable

      • agent.tmp (PID: 2816)
      • agent.tmp (PID: 4764)
      • agent.tmp (PID: 7448)
      • agent.tmp (PID: 2360)
      • agent.tmp (PID: 7520)
    • Creates/Modifies COM task schedule object

      • winagent.exe (PID: 2784)
      • winagent.exe (PID: 5608)
      • winagent.exe (PID: 6524)
      • winagent.exe (PID: 1504)
      • winagent.exe (PID: 3988)
    • Reads the Windows owner or organization settings

      • agent.tmp (PID: 2816)
      • agent.tmp (PID: 4764)
      • agent.tmp (PID: 7448)
      • agent.tmp (PID: 2360)
      • agent.tmp (PID: 7520)
    • Searches for installed software

      • winagent.exe (PID: 2784)
      • agent.tmp (PID: 4764)
      • winagent.exe (PID: 5608)
      • agent.tmp (PID: 7448)
      • winagent.exe (PID: 6524)
      • agent.tmp (PID: 2360)
      • winagent.exe (PID: 3988)
      • agent.tmp (PID: 7520)
      • winagent.exe (PID: 1504)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 2276)
    • The process checks if it is being run in the virtual environment

      • winagent.exe (PID: 2784)
      • winagent.exe (PID: 5608)
      • winagent.exe (PID: 6524)
      • winagent.exe (PID: 3988)
      • winagent.exe (PID: 1504)
    • Executes application which crashes

      • winagent.exe (PID: 2784)
      • winagent.exe (PID: 5608)
      • winagent.exe (PID: 6524)
      • winagent.exe (PID: 3988)
      • winagent.exe (PID: 1504)
  • INFO

    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4504)
      • msedge.exe (PID: 2268)
    • Application launched itself

      • msedge.exe (PID: 4504)
      • Acrobat.exe (PID: 7676)
      • AcroCEF.exe (PID: 2328)
    • Checks supported languages

      • identity_helper.exe (PID: 8044)
      • Acrobat_Reader_V112.exe (PID: 5352)
      • agent.exe (PID: 5724)
      • agent.tmp (PID: 7452)
      • agent.exe (PID: 6004)
      • agent.tmp (PID: 2816)
      • unzip.exe (PID: 1116)
      • unzip.exe (PID: 6892)
      • winagent.exe (PID: 2784)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • agent.exe (PID: 1312)
      • agent.tmp (PID: 7748)
      • agent.exe (PID: 6904)
      • agent.tmp (PID: 4764)
      • unzip.exe (PID: 7932)
      • unzip.exe (PID: 6536)
      • winagent.exe (PID: 5608)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.exe (PID: 6492)
      • agent.tmp (PID: 2436)
      • agent.tmp (PID: 7448)
      • unzip.exe (PID: 8080)
      • agent.exe (PID: 7492)
      • unzip.exe (PID: 7636)
      • winagent.exe (PID: 6524)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • agent.exe (PID: 7676)
      • agent.tmp (PID: 2772)
      • agent.tmp (PID: 2360)
      • agent.exe (PID: 2948)
      • unzip.exe (PID: 2164)
      • unzip.exe (PID: 2964)
      • winagent.exe (PID: 3988)
      • Acrobat_Reader_V112.exe (PID: 1548)
      • agent.exe (PID: 7504)
      • agent.tmp (PID: 7520)
      • unzip.exe (PID: 6640)
      • unzip.exe (PID: 7492)
      • winagent.exe (PID: 1504)
    • Reads Environment values

      • identity_helper.exe (PID: 8044)
      • winagent.exe (PID: 2784)
      • winagent.exe (PID: 5608)
      • winagent.exe (PID: 6524)
      • winagent.exe (PID: 3988)
      • winagent.exe (PID: 1504)
    • Reads the computer name

      • Acrobat_Reader_V112.exe (PID: 5352)
      • identity_helper.exe (PID: 8044)
      • agent.tmp (PID: 7452)
      • agent.tmp (PID: 2816)
      • winagent.exe (PID: 2784)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • agent.tmp (PID: 7748)
      • agent.tmp (PID: 4764)
      • winagent.exe (PID: 5608)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.tmp (PID: 7448)
      • agent.tmp (PID: 2436)
      • winagent.exe (PID: 6524)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • agent.tmp (PID: 2772)
      • agent.tmp (PID: 2360)
      • winagent.exe (PID: 3988)
      • Acrobat_Reader_V112.exe (PID: 1548)
      • agent.tmp (PID: 7520)
      • winagent.exe (PID: 1504)
    • Create files in a temporary directory

      • Acrobat_Reader_V112.exe (PID: 5352)
      • agent.exe (PID: 5724)
      • agent.exe (PID: 6004)
      • agent.tmp (PID: 2816)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • agent.exe (PID: 1312)
      • agent.exe (PID: 6904)
      • agent.tmp (PID: 4764)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.exe (PID: 6492)
      • agent.tmp (PID: 7448)
      • agent.exe (PID: 7492)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • agent.exe (PID: 7676)
      • agent.exe (PID: 2948)
      • agent.tmp (PID: 2360)
      • Acrobat_Reader_V112.exe (PID: 1548)
      • agent.exe (PID: 7504)
      • agent.tmp (PID: 7520)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 4504)
    • Process checks computer location settings

      • Acrobat_Reader_V112.exe (PID: 5352)
      • agent.tmp (PID: 7452)
      • Acrobat_Reader_V112.exe (PID: 7772)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • agent.tmp (PID: 7748)
      • agent.tmp (PID: 2436)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • agent.tmp (PID: 2772)
      • Acrobat_Reader_V112.exe (PID: 1548)
    • The sample compiled with english language support

      • agent.tmp (PID: 2816)
      • agent.tmp (PID: 4764)
      • agent.tmp (PID: 7448)
      • agent.tmp (PID: 2360)
      • agent.tmp (PID: 7520)
    • Creates a software uninstall entry

      • agent.tmp (PID: 2816)
      • agent.tmp (PID: 4764)
      • agent.tmp (PID: 7448)
      • agent.tmp (PID: 2360)
      • agent.tmp (PID: 7520)
    • Creates files in the program directory

      • winagent.exe (PID: 2784)
      • unzip.exe (PID: 1116)
      • agent.tmp (PID: 2816)
      • agent.tmp (PID: 4764)
      • unzip.exe (PID: 7932)
      • agent.tmp (PID: 7448)
      • unzip.exe (PID: 8080)
      • agent.tmp (PID: 2360)
      • unzip.exe (PID: 2164)
      • agent.tmp (PID: 7520)
      • unzip.exe (PID: 6640)
    • Reads the software policy settings

      • winagent.exe (PID: 2784)
      • WerFault.exe (PID: 2816)
      • winagent.exe (PID: 5608)
      • WerFault.exe (PID: 7596)
      • winagent.exe (PID: 6524)
      • WerFault.exe (PID: 6080)
      • winagent.exe (PID: 3988)
      • WerFault.exe (PID: 6444)
      • slui.exe (PID: 144)
      • winagent.exe (PID: 1504)
      • WerFault.exe (PID: 3148)
    • Reads product name

      • winagent.exe (PID: 2784)
      • winagent.exe (PID: 5608)
      • winagent.exe (PID: 6524)
      • winagent.exe (PID: 3988)
      • winagent.exe (PID: 1504)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2816)
      • WerFault.exe (PID: 7596)
      • WerFault.exe (PID: 6080)
      • WerFault.exe (PID: 6444)
      • WerFault.exe (PID: 3148)
    • Manual execution by a user

      • Acrobat_Reader_V112.exe (PID: 7772)
      • Acrobat_Reader_V112.exe (PID: 7956)
      • Acrobat_Reader_V112.exe (PID: 7420)
      • Acrobat.exe (PID: 7676)
      • Acrobat_Reader_V112.exe (PID: 1548)
    • Checks proxy server information

      • WerFault.exe (PID: 2816)
      • WerFault.exe (PID: 7596)
      • WerFault.exe (PID: 6080)
      • WerFault.exe (PID: 6444)
      • slui.exe (PID: 144)
      • WerFault.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
270
Monitored processes
101
Malicious processes
0
Suspicious processes
15

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs acrobat_reader_v112.exe agent.exe agent.tmp no specs agent.exe agent.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs unzip.exe no specs conhost.exe no specs unzip.exe no specs conhost.exe no specs winagent.exe svchost.exe werfault.exe acrobat_reader_v112.exe agent.exe agent.tmp no specs agent.exe agent.tmp unzip.exe no specs conhost.exe no specs unzip.exe no specs conhost.exe no specs winagent.exe werfault.exe slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs acrobat_reader_v112.exe agent.exe agent.tmp no specs agent.exe agent.tmp unzip.exe no specs conhost.exe no specs unzip.exe no specs conhost.exe no specs winagent.exe werfault.exe msedge.exe no specs acrobat_reader_v112.exe agent.exe agent.tmp no specs agent.exe agent.tmp msedge.exe no specs unzip.exe no specs conhost.exe no specs unzip.exe no specs conhost.exe no specs winagent.exe werfault.exe msedge.exe no specs acrobat.exe no specs acrobat.exe no specs msedge.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrobat_reader_v112.exe agent.exe agent.tmp unzip.exe no specs conhost.exe no specs unzip.exe no specs conhost.exe no specs winagent.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
144C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1116"C:\Program Files (x86)\Advanced Monitoring Agent\unzip.exe" package.zipC:\Program Files (x86)\Advanced Monitoring Agent\unzip.exeagent.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\advanced monitoring agent\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1144"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1540 --field-trial-handle=1608,i,13747373454439815972,5828743546883964782,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1312"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /VERYSILENT /norestartC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe
Acrobat_Reader_V112.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Advanced Monitoring Agent Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1504"C:\Program Files (x86)\Advanced Monitoring Agent\winagent.exe" /autoinstallC:\Program Files (x86)\Advanced Monitoring Agent\winagent.exe
agent.tmp
User:
admin
Company:
Remote Monitoring
Integrity Level:
HIGH
Description:
winagent
Exit code:
3221225477
Version:
10.14.4
Modules
Images
c:\program files (x86)\advanced monitoring agent\winagent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
1548"C:\Users\admin\Downloads\Acrobat_Reader_V112.exe" C:\Users\admin\Downloads\Acrobat_Reader_V112.exe
explorer.exe
User:
admin
Company:
N-able Technologies
Integrity Level:
HIGH
Description:
Advanced Monitoring Agent Setup
Exit code:
0
Modules
Images
c:\users\admin\downloads\acrobat_reader_v112.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1832"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2200,i,8992828630852179562,4622970529513532102,262144 --variations-seed-version --mojo-platform-channel-handle=2184 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1844\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeunzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1852"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5604,i,8992828630852179562,4622970529513532102,262144 --variations-seed-version --mojo-platform-channel-handle=5680 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2124\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeunzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
46 532
Read events
46 236
Write events
265
Delete events
31

Modification events

(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:DisplayName
Value:
Advanced Monitoring Agent
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Advanced Monitoring Agent\unins000.exe"
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files (x86)\Advanced Monitoring Agent\unins000.exe" /SILENT
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:NoModify
Value:
1
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:NoRepair
Value:
1
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:InstallDate
Value:
20251110
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:EstimatedSize
Value:
31745
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.3 (a)
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Advanced Monitoring Agent
(PID) Process:(2816) agent.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Monitoring Agent_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Advanced Monitoring Agent\
Executable files
222
Suspicious files
474
Text files
146
Unknown types
8

Dropped files

PID
Process
Filename
Type
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF16208d.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF16208d.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF16206d.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF16209c.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF16209c.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF16208d.TMP
MD5:
SHA256:
4504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
160
DNS requests
148
Threats
29

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4556
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
2268
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:QjcLNZtY4opjo9FOGilfqaND-XivsDQfmqFPeQkBgIA&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
95 b
whitelisted
4504
msedge.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
DE
binary
727 b
whitelisted
1284
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
RU
binary
825 b
whitelisted
8048
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
NL
binary
814 b
whitelisted
8048
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
NL
binary
813 b
whitelisted
4504
msedge.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
DE
binary
471 b
whitelisted
4504
msedge.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAa7Qj4Jnq0A09Vb8dNyx3M%3D
DE
binary
727 b
whitelisted
3332
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ddbf4492-d475-4fe4-bcde-6cbac56f6034?P1=1762967629&P2=404&P3=2&P4=CsT1q032OD7gcHNf2wiSb%2bpB4c0%2f9QXaUDP%2brs9MlImQxw0vAGC%2bZ5NTToPTJ%2bF4RBqsG%2fMrYBHw%2bj8V6DX9RA%3d%3d
US
binary
1.09 Kb
whitelisted
3332
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4c4fdee0-d69c-42b7-bf5c-3ec046e9dfc9?P1=1762967630&P2=404&P3=2&P4=DIOsDxN8XC3Vs46pM6%2bRfvFtDaNEPmRsX5LjHkiJ48RiM92xcZe%2fSv%2bzoX2fn2lS3w4hpnw8CLpPjaiguhMR3Q%3d%3d
US
binary
2.98 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1284
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7068
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2268
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2268
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2268
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2268
msedge.exe
52.51.118.159:443
l.gourl.es
AMAZON-02
IE
whitelisted
2268
msedge.exe
2.16.241.220:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.238
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
  • 150.171.29.11
  • 150.171.30.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
l.gourl.es
  • 52.51.118.159
  • 52.51.241.129
  • 52.214.44.207
unknown
copilot.microsoft.com
  • 2.16.241.220
  • 2.16.241.224
whitelisted
adobe-online.bencahil.com
  • 216.198.79.65
  • 64.29.17.65
unknown
www.bing.com
  • 2.16.241.219
  • 2.16.241.203
  • 2.16.241.212
  • 2.16.241.200
  • 2.16.241.222
  • 2.16.241.221
  • 2.16.241.218
  • 2.16.241.204
  • 2.16.241.197
  • 2.16.204.155
  • 2.16.204.150
  • 2.16.204.160
  • 2.16.204.148
  • 2.16.204.147
  • 2.16.204.161
  • 2.16.204.149
  • 2.16.204.153
  • 2.16.204.151
  • 2.16.241.205
  • 2.16.241.208
  • 2.16.241.207
  • 2.16.241.206
  • 2.16.241.211
  • 2.16.241.202
  • 2.16.241.227
whitelisted
xpaywalletcdn.azureedge.net
  • 13.107.213.45
  • 13.107.246.45
whitelisted
update.googleapis.com
  • 142.251.140.163
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Inline HTTP
2276
svchost.exe
Potential Corporate Privacy Violation
ET INFO Observed DNS Query for Suspicious TLD (.management)
2784
winagent.exe
Misc activity
ET INFO Observed RMM Domain in TLS SNI (remote .management)
2276
svchost.exe
Misc activity
ET INFO Observed RMM Domain in DNS Lookup (remote .management)
2276
svchost.exe
Potential Corporate Privacy Violation
ET INFO Observed DNS Query for Suspicious TLD (.management)
2276
svchost.exe
Misc activity
ET INFO Observed RMM Domain in DNS Lookup (remote .management)
2784
winagent.exe
Misc activity
ET INFO Observed RMM Domain in TLS SNI (remote .management)
2276
svchost.exe
Potential Corporate Privacy Violation
ET INFO Observed DNS Query for Suspicious TLD (.management)
2276
svchost.exe
Misc activity
ET INFO Observed RMM Domain in DNS Lookup (remote .management)
No debug info