File name:

passfab-for-rar.exe

Full analysis: https://app.any.run/tasks/21f91e14-30ab-4556-a0bc-015cd4862161
Verdict: Malicious activity
Analysis date: January 21, 2024, 03:19:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C0416973FED56F23B90302B195935242

SHA1:

2C2B93991817B313496C6F52ED025DA713041A20

SHA256:

F950886A1F17186E97BCA59FDCC329D5090313B333403A4978E2BA83CEFD2F68

SSDEEP:

98304:wgxJVexTvlX7JJzhiSAycFq4OCFBIWV/vQJnnKm57Uuce+bbu8ZJp0jkBmCPF18g:lhFg38LQ5Qjcc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • passfab-for-rar.exe (PID: 2268)
      • passfab-for-rar.tmp (PID: 2024)
      • passfab-for-zip.exe (PID: 3188)
      • passfab-for-zip.exe (PID: 3304)
      • passfab-for-zip.tmp (PID: 3360)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • passfab-for-rar.exe (PID: 2268)
      • passfab-for-rar.tmp (PID: 2024)
      • passfab-for-zip.exe (PID: 3188)
      • passfab-for-zip.exe (PID: 3304)
      • passfab-for-zip.tmp (PID: 3360)
    • Reads the Windows owner or organization settings

      • passfab-for-rar.tmp (PID: 2024)
      • passfab-for-zip.tmp (PID: 3360)
      • passfab-for-zip.tmp (PID: 604)
    • Drops 7-zip archiver for unpacking

      • passfab-for-rar.tmp (PID: 2024)
    • Searches for installed software

      • PassFab for RAR.exe (PID: 1604)
    • Reads the Internet Settings

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Reads security settings of Internet Explorer

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Checks for external IP

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Checks Windows Trust Settings

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Reads settings of System Certificates

      • PassFab for RAR.exe (PID: 3832)
      • PassFab for RAR.exe (PID: 1604)
  • INFO

    • Checks supported languages

      • passfab-for-rar.exe (PID: 2268)
      • passfab-for-rar.tmp (PID: 2024)
      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
      • passfab-for-zip.tmp (PID: 604)
      • passfab-for-zip.exe (PID: 3188)
      • passfab-for-zip.tmp (PID: 3360)
      • passfab-for-zip.exe (PID: 3304)
    • Reads the computer name

      • passfab-for-rar.tmp (PID: 2024)
      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
      • passfab-for-zip.tmp (PID: 3360)
    • Create files in a temporary directory

      • passfab-for-rar.exe (PID: 2268)
      • passfab-for-zip.exe (PID: 3188)
      • passfab-for-zip.exe (PID: 3304)
      • passfab-for-zip.tmp (PID: 3360)
      • passfab-for-zip.tmp (PID: 604)
    • Creates files in the program directory

      • passfab-for-rar.tmp (PID: 2024)
      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Reads the machine GUID from the registry

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Application launched itself

      • msedge.exe (PID: 1112)
      • msedge.exe (PID: 2332)
    • Checks proxy server information

      • PassFab for RAR.exe (PID: 1604)
      • PassFab for RAR.exe (PID: 3832)
    • Manual execution by a user

      • msedge.exe (PID: 2332)
      • PassFab for RAR.exe (PID: 3632)
      • WinRAR.exe (PID: 1976)
      • PassFab for RAR.exe (PID: 3832)
      • WinRAR.exe (PID: 1432)
      • passfab-for-zip.exe (PID: 2648)
      • passfab-for-zip.exe (PID: 3188)
      • passfab-for-zip.exe (PID: 3200)
      • passfab-for-zip.exe (PID: 3304)
    • Creates files or folders in the user directory

      • PassFab for RAR.exe (PID: 1604)
    • Reads Microsoft Office registry keys

      • PassFab for RAR.exe (PID: 3832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 16:39:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 181248
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PassFab, Inc.
FileDescription: PassFab for RAR Setup
FileVersion:
LegalCopyright:
ProductName: PassFab for RAR
ProductVersion: 9.5.2.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
86
Monitored processes
35
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start passfab-for-rar.exe passfab-for-rar.tmp passfab for rar.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs passfab for rar.exe no specs passfab for rar.exe winrar.exe no specs winrar.exe no specs passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.tmp no specs passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.tmp passfab-for-rar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3992 --field-trial-handle=1332,i,5077437808634579151,4613980763243911351,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
604"C:\Users\admin\AppData\Local\Temp\is-ENLJR.tmp\passfab-for-zip.tmp" /SL5="$5029A,56197701,247296,C:\Users\admin\Desktop\passfab-for-zip.exe" C:\Users\admin\AppData\Local\Temp\is-ENLJR.tmp\passfab-for-zip.tmppassfab-for-zip.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-enljr.tmp\passfab-for-zip.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1424 --field-trial-handle=1316,i,10666369626318820297,5635178282745824838,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1588 --field-trial-handle=1332,i,5077437808634579151,4613980763243911351,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://cbs.passfab.com/go?pid=1077&a=i&v=9.5.2C:\Program Files\Microsoft\Edge\Application\msedge.exePassFab for RAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1268"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1648 --field-trial-handle=1332,i,5077437808634579151,4613980763243911351,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1432"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\your_file.zip" C:\Users\admin\Desktop\your_file\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1492 --field-trial-handle=1332,i,5077437808634579151,4613980763243911351,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1268 --field-trial-handle=1332,i,5077437808634579151,4613980763243911351,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files\PassFab for RAR\PassFab for RAR.exe"C:\Program Files\PassFab for RAR\PassFab for RAR.exe
passfab-for-rar.tmp
User:
admin
Company:
PassFab
Integrity Level:
HIGH
Exit code:
0
Version:
9.5.2.2
Modules
Images
c:\program files\passfab for rar\passfab for rar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\passfab for rar\softwarelog.dll
c:\program files\passfab for rar\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
Total events
15 338
Read events
15 127
Write events
201
Delete events
10

Modification events

(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1604) PassFab for RAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2024) passfab-for-rar.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
3F5E3F3A20842A1DA71AC76F7BEA62C3EA976B94D65A2815CD940A6989C181DC
(PID) Process:(2024) passfab-for-rar.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\PassFab for RAR\AgentSupport.dll
Executable files
54
Suspicious files
122
Text files
172
Unknown types
0

Dropped files

PID
Process
Filename
Type
2268passfab-for-rar.exeC:\Users\admin\AppData\Local\Temp\is-C7NNS.tmp\passfab-for-rar.tmpexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-U6A41.tmpexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\unins000.exeexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-8PEKO.tmpexecutable
MD5:3F2096AF472FE36F347C7B35124029FE
SHA256:D80EA48DC277E3E1E58DB6E46728D1D7FF6E0C3D52076754ADA1C3CE4A49825B
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\BugSplat.dllexecutable
MD5:C3B26FD51AA57E786B715E1C9D9AADA8
SHA256:AB2A8F4D09066767941730A2AA222B436F7642161B506DEC4F00A98E4FF4B0E4
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-LT5VC.tmpexecutable
MD5:9BCA1913378AB31A0923F8B5F680E74F
SHA256:7298FD2733F929AA1EBFD47C30B6289EC9C699C76143E9297355CF510411A842
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-JBL37.tmp
MD5:
SHA256:
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\password.ini
MD5:
SHA256:
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-5O7EJ.tmptext
MD5:9E30D0AD0D0B80763F907E80FF3FD407
SHA256:BFA5DDC88B835AA5D54F12AC3E485BAD37B26D223B2C43F310EBE8CB1CB21FCC
2024passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-BCLLG.tmpexecutable
MD5:C3B26FD51AA57E786B715E1C9D9AADA8
SHA256:AB2A8F4D09066767941730A2AA222B436F7642161B506DEC4F00A98E4FF4B0E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
62
DNS requests
68
Threats
23

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1604
PassFab for RAR.exe
GET
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
unknown
1604
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1604
PassFab for RAR.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
1604
PassFab for RAR.exe
GET
200
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a1f8e0ad7815bf7a
unknown
compressed
4.66 Kb
unknown
1604
PassFab for RAR.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
155 b
unknown
1604
PassFab for RAR.exe
GET
521
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=AE9CD964-FF22-4C57-8A2B-25199434708C&IP=192.168.100.53&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
unknown
html
6.72 Kb
unknown
1604
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1604
PassFab for RAR.exe
GET
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=60D36B72-7140-4106-A200-860888C13560&IP=192.168.100.53&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
unknown
unknown
1604
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1604
PassFab for RAR.exe
POST
200
172.217.16.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1604
PassFab for RAR.exe
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
2332
msedge.exe
239.255.255.250:1900
whitelisted
1556
msedge.exe
104.18.25.142:443
cbs.passfab.com
CLOUDFLARENET
unknown
1556
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1556
msedge.exe
20.71.70.115:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1556
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1556
msedge.exe
92.123.104.32:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
whitelisted
cbs.passfab.com
  • 104.18.25.142
  • 104.18.24.142
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.71.70.115
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.71.70.115
whitelisted
www.bing.com
  • 92.123.104.32
  • 92.123.104.38
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.80
  • 23.216.77.69
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared

Threats

PID
Process
Class
Message
1604
PassFab for RAR.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1604
PassFab for RAR.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1604
PassFab for RAR.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1604
PassFab for RAR.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
3832
PassFab for RAR.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
3832
PassFab for RAR.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
17 ETPRO signatures available at the full report
No debug info