File name:

tranScreen.exe

Full analysis: https://app.any.run/tasks/9dce3162-9f05-4cf3-820d-7f60bde80d11
Verdict: Malicious activity
Analysis date: November 13, 2024, 10:33:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

36F55D9BCC9488C1483696A652FE657C

SHA1:

A3D5647FE78FE08814A0125B081866C9D3B2724B

SHA256:

FF01F3F985E454BA0CF880C118BFED6D39278E5F12F8EF7322730099C46A8058

SSDEEP:

98304:COZfPUHcKw4kYkK+wV+mwkYkK+wV+mvf10ZCnL6ePmzMXNE/hsXxVylfBC4kXNwF:wmjhw31sOlcoXmFvJeIgAdIyB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • tranScreen.exe (PID: 4236)
    • Executable content was dropped or overwritten

      • tranScreen.exe (PID: 4236)
      • TranscreenSoftware.exe (PID: 6164)
      • devcon.exe (PID: 1500)
      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 4568)
      • devcon.exe (PID: 864)
      • devcon.exe (PID: 5616)
      • drvinst.exe (PID: 920)
      • drvinst.exe (PID: 4292)
      • drvinst.exe (PID: 6716)
      • drvinst.exe (PID: 4448)
    • Process drops legitimate windows executable

      • tranScreen.exe (PID: 4236)
      • TranscreenSoftware.exe (PID: 6164)
    • Reads security settings of Internet Explorer

      • tranScreen.exe (PID: 4236)
      • InstallDeviceDriver.exe (PID: 6740)
      • TranscreenSoftware.exe (PID: 6164)
      • devcon.exe (PID: 1500)
    • Drops a system driver (possible attempt to evade defenses)

      • TranscreenSoftware.exe (PID: 6164)
      • devcon.exe (PID: 1500)
      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 4568)
      • devcon.exe (PID: 864)
      • drvinst.exe (PID: 6716)
      • drvinst.exe (PID: 4292)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 4568)
    • Checks Windows Trust Settings

      • devcon.exe (PID: 1500)
    • Executes as Windows Service

      • WUDFHost.exe (PID: 7204)
    • There is functionality for taking screenshot (YARA)

      • TranscreenSoftware.exe (PID: 6164)
    • Connects to unusual port

      • TranscreenSoftware.exe (PID: 6164)
  • INFO

    • Creates files or folders in the user directory

      • tranScreen.exe (PID: 4236)
      • TranscreenSoftware.exe (PID: 6164)
      • InstallDeviceDriver.exe (PID: 6740)
    • Reads the computer name

      • tranScreen.exe (PID: 4236)
      • TranscreenSoftware.exe (PID: 6164)
      • InstallDeviceDriver.exe (PID: 6740)
      • devcon.exe (PID: 1500)
    • Checks supported languages

      • tranScreen.exe (PID: 4236)
      • TranscreenSoftware.exe (PID: 6164)
      • InstallDeviceDriver.exe (PID: 6740)
      • devcon.exe (PID: 6272)
      • devcon.exe (PID: 1500)
      • drvinst.exe (PID: 5952)
    • Creates files in the program directory

      • tranScreen.exe (PID: 4236)
    • The process uses the downloaded file

      • tranScreen.exe (PID: 4236)
      • InstallDeviceDriver.exe (PID: 6740)
      • TranscreenSoftware.exe (PID: 6164)
    • Process checks computer location settings

      • tranScreen.exe (PID: 4236)
      • InstallDeviceDriver.exe (PID: 6740)
      • TranscreenSoftware.exe (PID: 6164)
    • Sends debugging messages

      • InstallDeviceDriver.exe (PID: 6740)
      • TranscreenSoftware.exe (PID: 6164)
      • InstallDeviceDriver.exe (PID: 3732)
      • InstallDeviceDriver.exe (PID: 6232)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 5952)
      • devcon.exe (PID: 1500)
    • Reads the software policy settings

      • drvinst.exe (PID: 5952)
      • devcon.exe (PID: 1500)
    • Create files in a temporary directory

      • devcon.exe (PID: 1500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:16 08:12:31+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 126464
InitializedDataSize: 10105344
UninitializedDataSize: -
EntryPoint: 0xb284
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.6.7.6
ProductVersionNumber: 2.6.7.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: TranscreenSoft
FileDescription: TranscreenSoftClient
FileVersion: 2.6.7.6
InternalName: TranscreenSoft
LegalCopyright: -
OriginalFileName: -
ProductName: TranscreenSoft
ProductVersion: 2.6.7.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
28
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start transcreen.exe THREAT transcreensoftware.exe installdevicedriver.exe conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe conhost.exe no specs drvinst.exe drvinst.exe installdevicedriver.exe conhost.exe no specs installdevicedriver.exe conhost.exe no specs devcon.exe no specs devcon.exe no specs conhost.exe no specs conhost.exe no specs devcon.exe devcon.exe conhost.exe no specs conhost.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe wudfhost.exe no specs transcreen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\tools\amd64\devcon.exe" -install "C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\vcamera\amd64\TranScreenCamera.inf" root\SHARECAMERAC:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\tools\amd64\devcon.exe
InstallDeviceDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.14393.0 (rs1_release.160715-1616)
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\drivers\tools\amd64\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
920DrvInst.exe "2" "211" "ROOT\USB\0000" "C:\WINDOWS\INF\oem7.inf" "oem7.inf:c14ce8840c48fa1f:MyDevice_Install:19.13.50.927:hid\vid_1b36&pid_0d11," "423aa307f" "000000000000021C"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1500"C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\tools\amd64\devcon.exe" -install "C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\tffaudio\x64\tff_virtaudio.inf" *tff_virtaudioC:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\tools\amd64\devcon.exe
InstallDeviceDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.14393.0 (rs1_release.160715-1616)
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\drivers\tools\amd64\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1788"C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\vmonitor\x64\devcon.exe" -remove hid\vid_1b36&pid_0d11C:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers\vmonitor\x64\devcon.exeInstallDeviceDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.14393.0 (rs1_release.160715-1616)
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\drivers\vmonitor\x64\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2620"C:\Users\admin\AppData\Local\Temp\tranScreen.exe" C:\Users\admin\AppData\Local\Temp\tranScreen.exeexplorer.exe
User:
admin
Company:
TranscreenSoft
Integrity Level:
MEDIUM
Description:
TranscreenSoftClient
Exit code:
3221226540
Version:
2.6.7.6
Modules
Images
c:\users\admin\appdata\local\temp\transcreen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3732"C:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exe" INSTALL_VIRTUAL_CAMERAC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exe
TranscreenSoftware.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\transcreen\software\installdevicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3944\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4004\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstallDeviceDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4236"C:\Users\admin\AppData\Local\Temp\tranScreen.exe" C:\Users\admin\AppData\Local\Temp\tranScreen.exe
explorer.exe
User:
admin
Company:
TranscreenSoft
Integrity Level:
HIGH
Description:
TranscreenSoftClient
Exit code:
0
Version:
2.6.7.6
Modules
Images
c:\users\admin\appdata\local\temp\transcreen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4292DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{30ef2235-1397-6c46-a044-00d3444929e2}\transcreencamera.inf" "9" "4e1788aaf" "0000000000000214" "WinSta0\Default" "00000000000001C4" "208" "c:\users\admin\appdata\roaming\transcreen\software\drivers\vcamera\amd64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
27 394
Read events
26 023
Write events
1 356
Delete events
15

Modification events

(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FriendlyName
Value:
Microphone (2- Realtek AC'97 Audio)
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointId
Value:
{0.0.1.00000000}.{05b02c95-c55a-499c-a533-120810b973df}
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:EndpointGuid
Value:
{05B02C95-C55A-499C-A533-120810B973DF}
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:WaveInId
Value:
0
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{05B02C95-C55A-499C-A533-120810B973DF}
Operation:writeName:ClassManagerFlags
Value:
2
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FriendlyName
Value:
Line In (2- Realtek AC'97 Audio)
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:CLSID
Value:
{E30629D2-27E5-11CE-875D-00608CB78066}
(PID) Process:(6164) TranscreenSoftware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\wave:{A14F8BF5-56E3-412D-AF34-D2240261ED67}
Operation:writeName:FilterData
Value:
02000000000020000000000000000000
Executable files
76
Suspicious files
33
Text files
402
Unknown types
8

Dropped files

PID
Process
Filename
Type
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\Drivers.zipcompressed
MD5:1273B0C68E1129096838414C15647BF1
SHA256:0627B303956462624628416D283EA71B1B426C41AF5171E3C82B7E74417D109C
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\TranscreenSoftware.exeexecutable
MD5:5FE3DA058C9A6FE8AB75F76EB840B8F0
SHA256:EA9D50AB11F3E5CC43CA1BEEED00D03D7E775E0E6A7B8631A966E7B53B8CE1BF
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\InstallDeviceDriver.exeexecutable
MD5:D8F0C1FB5338369BE6C35FB1402DCBDA
SHA256:A0CDECFE0EDBA591979F6CB1F532D9452BDE289E646644EF5A5C1ACA906E8574
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libx264-146.dllexecutable
MD5:BB927B4A2DAF63516AFB2D73805949E7
SHA256:907534D4B1007FB660C21F17AF0F110AB768F42ABCED223825C4DD31A5653FFA
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\ScreenCast.dllexecutable
MD5:F1977F5D7327ADF67AB2CEACE43484F5
SHA256:97F7C5A44D9EE25FF775EE22C82114FE670C3F26FEA6A44BCA0720C98BC7CC82
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libgcc_s_dw2-1.dllexecutable
MD5:97E7F6F9D7F92F54B6FC06B8B1397117
SHA256:F240698B514FA954E2A75D239FC784FFB8B931CD05E43F585017469F12A45084
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\SoftTranscreen.zipcompressed
MD5:C0E34263E6A3D5FE86CB1FF7D3C76EB5
SHA256:E55950AEBBFBA040BA4B0AD25BC02EEB535C2E65AF729B1D3CFC7E0B4AB745CA
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\wz264.dllexecutable
MD5:7FCD1553756FD96779A417FE4FFBC769
SHA256:988CD8B51E3EC088FBC6B6A1613688C7D9F053C401BDF5055311E1B26929743C
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\DuiLib.dllexecutable
MD5:FEF2483D0B3F41E59767893681249F87
SHA256:DD8FA304426DAC773B6B42D103F6AD8EAD673402EE506C7BB7E566EEF041A5EE
4236tranScreen.exeC:\Users\admin\AppData\Roaming\Transcreen\Software\libVMonitor-New.dllexecutable
MD5:7AF20E3C8A63222A56A74B2929CB518C
SHA256:A94890DCCBD78C94598DABA1C39147377885906B0E1C801CA50EFB004E5CF62A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
59
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.36.77.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3788
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1884
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7364
SIHClient.exe
GET
200
96.6.17.223:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.36.77.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
96.6.17.223:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
96.6.17.223:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.36.77.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
96.6.17.223:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4360
SearchApp.exe
23.36.79.155:443
www.bing.com
Akamai International B.V.
NO
whitelisted
23.36.79.155:443
www.bing.com
Akamai International B.V.
NO
whitelisted
6944
svchost.exe
23.36.77.81:80
crl.microsoft.com
Akamai International B.V.
NO
whitelisted
5488
MoUsoCoreWorker.exe
23.36.77.81:80
crl.microsoft.com
Akamai International B.V.
NO
whitelisted
23.36.77.81:80
crl.microsoft.com
Akamai International B.V.
NO
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5488
MoUsoCoreWorker.exe
96.6.17.223:80
www.microsoft.com
AKAMAI-AS
NO
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.36.77.81
whitelisted
www.bing.com
  • 23.36.79.155
whitelisted
google.com
  • 142.250.74.46
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 96.6.17.223
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.177.84
whitelisted
th.bing.com
  • 23.36.77.242
whitelisted
go.microsoft.com
  • 96.6.17.155
whitelisted
arc.msn.com
  • 20.24.121.134
whitelisted

Threats

No threats detected
Process
Message
TranscreenSoftware.exe
Tff_Zx_Soft_UI::PageSwitching 2
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.200: InitTFFControler() call InitHidManager()!
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: InitTFFControler() Call HeartBeat
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: InitTFFControler() Call Video
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: InitTFFControler() where strServerId=,strServerId=
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: lOSMainVersion=6.200000
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: InitTFFControler() where strServerId=,value=
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.216: InitTFFControler() Call Broadcast
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.450: DXGIInit() ,nOutput = 0,iScreenNum=1
TranscreenSoftware.exe
[INFO]2024-11-13 10:33:38.466: InitTFFControler() Call Audio