File name:

Avira Phantom VPN Pro 2.44.1.19908.zip

Full analysis: https://app.any.run/tasks/5e1bdbe1-6ae9-4e47-b198-26cb1398497d
Verdict: Malicious activity
Analysis date: June 04, 2025, 09:41:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
delphi
inno
installer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

B14472C00492BA142C9BB7037DA50A5A

SHA1:

1A29F03C45CC2E766A811AAB30532433B0F6FF8B

SHA256:

FE83D8AC0890EDD958BDAEE69AD54437267206A8EDF1048677DFC7985E0A9986

SSDEEP:

98304:XY2wTX3H1Vhm7G5nCCwT3KSlUfAtZYqat2OCAAihAz2SdFq5X7+hwbrDV5c2vK8O:bj0LqD1L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • tapinstall.exe (PID: 7712)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7448)
      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • tapinstall.exe (PID: 7712)
      • Avira.VpnService.exe (PID: 8136)
      • Avira.WebAppHost.exe (PID: 7196)
      • Avira.WebAppHost.exe (PID: 4648)
    • Executable content was dropped or overwritten

      • Avira Phantom VPN Pro 2.44.1.19908.exe (PID: 3884)
      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • drvinst.exe (PID: 8144)
      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 7744)
    • Reads the Windows owner or organization settings

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • Avira.VpnService.exe (PID: 8136)
    • Uses TASKKILL.EXE to kill process

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Stops a currently running service

      • sc.exe (PID: 6920)
    • Process drops legitimate windows executable

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Drops a system driver (possible attempt to evade defenses)

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 8144)
      • drvinst.exe (PID: 7744)
    • The process verifies whether the antivirus software is installed

      • tapinstall.exe (PID: 7712)
      • Avira.VpnService.exe (PID: 8136)
      • Avira.WebAppHost.exe (PID: 4648)
      • Avira.NetworkBlocker.exe (PID: 6620)
      • Avira.WebAppHost.exe (PID: 7196)
      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Creates files in the driver directory

      • drvinst.exe (PID: 8144)
      • drvinst.exe (PID: 7744)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 7744)
    • Windows service management via SC.EXE

      • sc.exe (PID: 8132)
      • sc.exe (PID: 7752)
    • Executes as Windows Service

      • Avira.VpnService.exe (PID: 8136)
    • Restarts service on failure

      • sc.exe (PID: 5864)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Creates a new Windows service

      • sc.exe (PID: 7280)
    • Starts CMD.EXE for commands execution

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • WinRAR.exe (PID: 7448)
    • Searches for installed software

      • Avira.VpnService.exe (PID: 8136)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 736)
    • Reads Microsoft Outlook installation path

      • Avira.WebAppHost.exe (PID: 7196)
    • Reads Internet Explorer settings

      • Avira.WebAppHost.exe (PID: 7196)
    • Executing commands from ".cmd" file

      • WinRAR.exe (PID: 7448)
  • INFO

    • Reads the computer name

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 8144)
      • drvinst.exe (PID: 7744)
      • Avira.VpnService.exe (PID: 8136)
      • Avira.NetworkBlocker.exe (PID: 6620)
      • Avira.WebAppHost.exe (PID: 4648)
      • Avira.WebAppHost.exe (PID: 7196)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7448)
    • Checks supported languages

      • Avira Phantom VPN Pro 2.44.1.19908.exe (PID: 3884)
      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 7744)
      • drvinst.exe (PID: 8144)
      • Avira.VpnService.exe (PID: 8136)
      • Avira.NetworkBlocker.exe (PID: 6620)
      • Avira.WebAppHost.exe (PID: 4648)
      • Avira.WebAppHost.exe (PID: 7196)
    • Create files in a temporary directory

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • Avira Phantom VPN Pro 2.44.1.19908.exe (PID: 3884)
      • tapinstall.exe (PID: 7712)
    • Process checks computer location settings

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • The sample compiled with english language support

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 8144)
      • drvinst.exe (PID: 7744)
    • Creates files in the program directory

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • Avira.VpnService.exe (PID: 8136)
    • Compiled with Borland Delphi (YARA)

      • Avira Phantom VPN Pro 2.44.1.19908.exe (PID: 3884)
      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Creates files or folders in the user directory

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Creates a software uninstall entry

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
    • Reads the software policy settings

      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 8144)
      • Avira.VpnService.exe (PID: 8136)
      • slui.exe (PID: 6044)
    • Reads the machine GUID from the registry

      • tapinstall.exe (PID: 7712)
      • drvinst.exe (PID: 8144)
      • Avira.VpnService.exe (PID: 8136)
      • Avira.WebAppHost.exe (PID: 4648)
      • Avira.WebAppHost.exe (PID: 7196)
    • Detects InnoSetup installer (YARA)

      • Avira Phantom VPN Pro 2.44.1.19908.tmp (PID: 3268)
      • Avira Phantom VPN Pro 2.44.1.19908.exe (PID: 3884)
    • Reads Environment values

      • Avira.VpnService.exe (PID: 8136)
      • Avira.WebAppHost.exe (PID: 7196)
    • Disables trace logs

      • Avira.VpnService.exe (PID: 8136)
      • Avira.WebAppHost.exe (PID: 7196)
    • Reads product name

      • Avira.VpnService.exe (PID: 8136)
    • Reads CPU info

      • Avira.VpnService.exe (PID: 8136)
    • Checks proxy server information

      • Avira.WebAppHost.exe (PID: 7196)
      • Avira.VpnService.exe (PID: 8136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:05:04 07:18:52
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Setup/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
40
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe avira phantom vpn pro 2.44.1.19908.exe no specs avira phantom vpn pro 2.44.1.19908.exe avira phantom vpn pro 2.44.1.19908.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs tapinstall.exe conhost.exe no specs drvinst.exe drvinst.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs avira.vpnservice.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs avira.networkblocker.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs timeout.exe no specs avira.webapphost.exe no specs avira.webapphost.exe no specs cmd.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
716"C:\Windows\System32\taskkill.exe" /f /im Avira.WebAppHost.exeC:\Windows\SysWOW64\taskkill.exeAvira Phantom VPN Pro 2.44.1.19908.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
736"C:\WINDOWS\system32\cmd.exe" /C TIMEOUT 10C:\Windows\SysWOW64\cmd.exeAvira Phantom VPN Pro 2.44.1.19908.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1072"C:\Windows\System32\taskkill.exe" /f /im Avira.NetworkBlocker.exeC:\Windows\SysWOW64\taskkill.exeAvira Phantom VPN Pro 2.44.1.19908.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1472\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAvira.NetworkBlocker.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2148\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exeWinRAR.exe
User:
admin
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
MEDIUM
Description:
Avira Phantom VPN Pro 2.44.1.19908 Setup
Exit code:
3221226540
Version:
2.44.1.19908
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7448.40264\setup\avira phantom vpn pro 2.44.1.19908.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3268"C:\Users\admin\AppData\Local\Temp\is-JDR4P.tmp\Avira Phantom VPN Pro 2.44.1.19908.tmp" /SL5="$403F6,4884611,248832,C:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exe" C:\Users\admin\AppData\Local\Temp\is-JDR4P.tmp\Avira Phantom VPN Pro 2.44.1.19908.tmp
Avira Phantom VPN Pro 2.44.1.19908.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jdr4p.tmp\avira phantom vpn pro 2.44.1.19908.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
3884"C:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exe
WinRAR.exe
User:
admin
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
HIGH
Description:
Avira Phantom VPN Pro 2.44.1.19908 Setup
Exit code:
0
Version:
2.44.1.19908
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7448.40264\setup\avira phantom vpn pro 2.44.1.19908.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
17 501
Read events
17 392
Write events
102
Delete events
7

Modification events

(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Avira Phantom VPN Pro 2.44.1.19908.zip
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7448) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3268) Avira Phantom VPN Pro 2.44.1.19908.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C7F7E4E0-2E15-485F-B37B-9E96A55D35BD}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.1.ee2 (u)
(PID) Process:(3268) Avira Phantom VPN Pro 2.44.1.19908.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C7F7E4E0-2E15-485F-B37B-9E96A55D35BD}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Avira\VPN
Executable files
116
Suspicious files
19
Text files
731
Unknown types
58

Dropped files

PID
Process
Filename
Type
7448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Setup\Avira Phantom VPN Pro 2.44.1.19908.exeexecutable
MD5:0FE5732C15E8150C8F107A0E73DB4E45
SHA256:940EC4012984218F6E314D793C995B3CB3C3366AABBA0308FECE77FE2ED7ABB7
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Program Files (x86)\Avira\VPN\is-15O1N.tmptext
MD5:B2A6F839D31488C3B8A979A7828CFE05
SHA256:7A372C76536D1FF0FBFE82A2AEF9AC823D18EF3ED580CFE2474EDC631E57CC05
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\ProgramData\Avira\VPN\is-H2I2L.tmpxml
MD5:D0A82D1F6812D69AAB47854A72DB915C
SHA256:8CD642C39EC85D454FF8A598279FFF07E10C7B59FA5802118146EF6BB261850B
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Program Files (x86)\Avira\VPN\unins000.exeexecutable
MD5:F019D7BE022910406834AE32E6F3417E
SHA256:7597B3DBF0FCE4D5CE61285D7702F067E04C00025F6AE6E9378227B060AB4CEF
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Users\admin\AppData\Local\Temp\is-UUEH2.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Users\admin\AppData\Local\Temp\is-UUEH2.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
7448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7448.40264\Read Me.txttext
MD5:44DB932DDAE8EC88D800266A4789BB7D
SHA256:40073A7B8F546B688A1F816D5F17EF7817F9FAFB6B5221BC902C868779D63609
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Program Files (x86)\Avira\VPN\is-7BRCL.tmpimage
MD5:00EF5795980D6286FDB6B228341169B5
SHA256:127BF7B231CA20E9805B28F3521E88A311D03BC5B4FD1EDFF52AC6CBD1B091D3
3884Avira Phantom VPN Pro 2.44.1.19908.exeC:\Users\admin\AppData\Local\Temp\is-JDR4P.tmp\Avira Phantom VPN Pro 2.44.1.19908.tmpexecutable
MD5:0C1C8EB89026AF3BC48B56D10759C400
SHA256:02FEBFFFCAC96296E9CBAD84CCCF0153A11C051E0F2421E86360ECCFC21F7F4D
3268Avira Phantom VPN Pro 2.44.1.19908.tmpC:\Users\admin\AppData\Local\Temp\is-UUEH2.tmp\English.rtftext
MD5:B0533AFC5844AF4513E46CC4E451DBBA
SHA256:A5ECF679013A334DAC5E2D264F8F45D38CCBF4752C4B4F8DA3DD41DE0EAE17DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
33
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5408
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6540
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6540
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8136
Avira.VpnService.exe
GET
200
184.24.77.30:80
http://www.msftncsi.com/ncsi.txt
unknown
whitelisted
8136
Avira.VpnService.exe
GET
200
184.24.77.30:80
http://www.msftncsi.com/ncsi.txt
unknown
whitelisted
8136
Avira.VpnService.exe
GET
200
184.24.77.30:80
http://www.msftncsi.com/ncsi.txt
unknown
whitelisted
8136
Avira.VpnService.exe
GET
200
184.24.77.30:80
http://www.msftncsi.com/ncsi.txt
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5408
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2516
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5408
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.160.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.160.128
  • 20.190.160.4
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.74
  • 20.190.160.5
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
No debug info