File name:

Download Nimble Tools Nimble Kick WiN Plugin Crack.exe

Full analysis: https://app.any.run/tasks/b947d4b7-a77f-4b35-adc4-51d3903bcd0d
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 17, 2026, 21:45:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
auto
offloader
loader
lumma
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

84E772AC7047ED5298AA5B7442C42CB9

SHA1:

9D90CB5B98C4382EBA62693CA4137D2EF5B4A093

SHA256:

05469322BB6E9DABD14F399E66F35995B386D103DEC271D15DDA0AC043B9865F

SSDEEP:

1536:Uy3T4iSID7Mu2pTUfzM74mVvtfsOBct/pMZq9p1aNESDtXR:pkibD7Mu2pT+M7VVvtESc3M8pS5DtXR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • starter.exe (PID: 8852)
    • OFFLOADER has been found (auto)

      • starter.exe (PID: 8852)
    • Changes the autorun value in the registry

      • VC_redist.x86.exe (PID: 7936)
    • LUMMA has been detected (YARA)

      • set_3.exe (PID: 7256)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
    • Executable content was dropped or overwritten

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • set_2.exe (PID: 4036)
      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 2608)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
      • VC_redist.x86.exe (PID: 1424)
      • VC_redist.x86.exe (PID: 2288)
    • Creates file in the systems drive root

      • starter.exe (PID: 8852)
    • Reads the Windows owner or organization settings

      • set_2.tmp (PID: 8012)
      • msiexec.exe (PID: 4852)
    • Process drops legitimate windows executable

      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 2608)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
      • VC_redist.x86.exe (PID: 2288)
    • Starts a Microsoft application from unusual location

      • vc_redist.x86.exe (PID: 2608)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
    • Access to an unwanted program domain was detected

      • starter.exe (PID: 8852)
    • Searches for installed software

      • vc_redist.x86.exe (PID: 5716)
      • dllhost.exe (PID: 8636)
      • VC_redist.x86.exe (PID: 1424)
      • VC_redist.x86.exe (PID: 2288)
    • Starts itself from another location

      • vc_redist.x86.exe (PID: 5716)
    • Executes as Windows Service

      • VSSVC.exe (PID: 8184)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4852)
    • Application launched itself

      • VC_redist.x86.exe (PID: 1960)
      • VC_redist.x86.exe (PID: 1424)
  • INFO

    • Reads the computer name

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • GameBar.exe (PID: 2376)
      • set_2.exe (PID: 4036)
      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 2608)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
      • VC_redist.x86.exe (PID: 1424)
      • VC_redist.x86.exe (PID: 2288)
      • set_3.exe (PID: 7256)
    • The sample compiled with english language support

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 2608)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
      • VC_redist.x86.exe (PID: 1424)
      • VC_redist.x86.exe (PID: 2288)
    • Reads the machine GUID from the registry

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
    • Checks supported languages

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • GameBar.exe (PID: 2376)
      • set_2.exe (PID: 4036)
      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 5716)
      • vc_redist.x86.exe (PID: 2608)
      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
      • VC_redist.x86.exe (PID: 1960)
      • VC_redist.x86.exe (PID: 1424)
      • VC_redist.x86.exe (PID: 2288)
      • set_3.exe (PID: 7256)
    • Reads security settings of Internet Explorer

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • GameBar.exe (PID: 2376)
      • starter.exe (PID: 8852)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 1424)
    • Create files in a temporary directory

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • set_2.exe (PID: 4036)
      • set_2.tmp (PID: 8012)
      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 7936)
      • VC_redist.x86.exe (PID: 1424)
    • Checks proxy server information

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • slui.exe (PID: 8304)
    • Creates files or folders in the user directory

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • msiexec.exe (PID: 4852)
      • set_2.tmp (PID: 8012)
    • There is functionality for taking screenshot (YARA)

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 8316)
      • starter.exe (PID: 8852)
      • set_3.exe (PID: 7256)
    • Creates files in the program directory

      • set_2.tmp (PID: 8012)
      • VC_redist.x86.exe (PID: 7936)
    • Drops script file

      • set_2.tmp (PID: 8012)
    • Process checks computer location settings

      • vc_redist.x86.exe (PID: 5716)
      • VC_redist.x86.exe (PID: 1424)
    • Manages system restore points

      • SrTasks.exe (PID: 8916)
    • Creates a software uninstall entry

      • VC_redist.x86.exe (PID: 7936)
      • msiexec.exe (PID: 4852)
    • Launching a file from a Registry key

      • VC_redist.x86.exe (PID: 7936)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4852)
    • Creating file in SysWOW64

      • msiexec.exe (PID: 4852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(7256) set_3.exe
C2 (9)basilicros.su/asdasq
broguenko.su/asfase
familyriwo.su/fssdaw
greekcs.cyou
hammernew.su/asdase
heavylussy.su/ccvfd
homuncloud.su/ascasef
izzardtow.su/cascasc
whitepepper.su/asds
ChaCha20
keyPJJ6TtcX+Th65c/qOHtUvIcvFPbsuRNyLGM+UVBDX08=
noncevISPVktQnjQ=
counter0
Strings (41)" Content-Disposition: form-data; name="file"; filename="
%LocalAppData%\Steam\local.vdf
%ProgramFiles%\
<span class="actual_persona_name">
Account
AppData
Applications/Steam/Tokens.txt
Content-Type: multipart/form-data; boundary=
Cookie: __cf_mw_byp=
DiscordCanary
DiscordPTB
Display Resolution:
DisplayName
Execution Path:
History
Install Date:
InstallLocation
LocalAppData
Mails/Windows Mail
Mails/Windows Mail Alternative
Network\Cookies
Operation System:
ROOT\CIMV2
SeImpersonatePrivilege
SerialNumber
SystemDrive
Time Zone: UTC
Wallets/
\Application\
\IndexedDB\chrome-extension_
\KnownDlls\
\LocalState\Indexed\LiveComm\
\Sync Extension Settings\
\storage\default\moz-extension+++
_0.indexeddb.leveldb
eyAidHlwIjogIkpXVCIsICJhbGciOiAiRWREU0EiIH0
https://steamcommunity.com/profiles/76561199880317058
microsoft.windowscommunicationsapps*
name="atok" value="
ntdll.dll
steam.exe
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3532
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
20
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start download nimble tools nimble kick win  plugin crack.exe #OFFLOADER starter.exe gamebar.exe no specs set_2.exe set_2.tmp vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe vc_redist.x86.exe no specs vc_redist.x86.exe vc_redist.x86.exe #LUMMA set_3.exe slui.exe svchost.exe download nimble tools nimble kick win  plugin crack.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1424"C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" -burn.clean.room="C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" -burn.filehandle.attached=740 -burn.filehandle.self=760 -uninstall -quiet -burn.related.upgrade -burn.ancestors={3fdfb881-a139-4811-9788-61520be14e1f} -burn.filehandle.self=1268 -burn.embedded BurnPipe.{BD8E08EE-20D4-4A3E-9B8A-DD6CF318B585} {4F4FEAB0-F46E-49CC-9993-74B0B370D73A} 7936C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe
VC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\programdata\package cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1960"C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={3fdfb881-a139-4811-9788-61520be14e1f} -burn.filehandle.self=1268 -burn.embedded BurnPipe.{BD8E08EE-20D4-4A3E-9B8A-DD6CF318B585} {4F4FEAB0-F46E-49CC-9993-74B0B370D73A} 7936C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exeVC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\programdata\package cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2288"C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{DC0B65CB-3E32-43BF-A268-298AAF5354D1} {F6E1863B-8FC9-40D6-8998-59EBE04D1B94} 1424C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe
VC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\programdata\package cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2292C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2376"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\msvcp140_app.dll
c:\windows\system32\oleaut32.dll
2608"C:\Users\admin\AppData\Local\Temp\is-QN7T8LY4YC.tmp\vc_redist.x86.exe" /install /quiet /norestartC:\Users\admin\AppData\Local\Temp\is-QN7T8LY4YC.tmp\vc_redist.x86.exe
set_2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ v14 Redistributable (x86) - 14.50.35710
Exit code:
0
Version:
14.50.35710.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qn7t8ly4yc.tmp\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4036"C:\Users\admin\AppData\Local\Temp\nshABEF.tmp\set_2.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\nshABEF.tmp\set_2.exe
starter.exe
User:
admin
Company:
Doc services Co.
Integrity Level:
HIGH
Description:
Docs Helper Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nshabef.tmp\set_2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4852C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5204"C:\Users\admin\Desktop\Download Nimble Tools Nimble Kick WiN Plugin Crack.exe" C:\Users\admin\Desktop\Download Nimble Tools Nimble Kick WiN Plugin Crack.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\download nimble tools nimble kick win plugin crack.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5528\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
17 314
Read events
16 435
Write events
616
Delete events
263

Modification events

(PID) Process:(8316) Download Nimble Tools Nimble Kick WiN Plugin Crack.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8316) Download Nimble Tools Nimble Kick WiN Plugin Crack.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8316) Download Nimble Tools Nimble Kick WiN Plugin Crack.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:InstalledVersionMajor
Value:
02003ED162CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:InstalledVersionMinor
Value:
22003ED162CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:InstalledVersionBuild
Value:
616D3ED162CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:InstalledVersionRevision
Value:
00003ED162CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:PreviousAppTerminationFromSuspended
Value:
003ED162CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:CurrentDisplayMonitor
Value:
670061006D0065000000643365CE56A0DC01
(PID) Process:(2376) GameBar.exeKey:\REGISTRY\A\{d11eb97d-b203-3874-316d-79e2d3380376}\LocalState
Operation:writeName:StartupTipIndex
Value:
0100000000000000AF9567CE56A0DC01
Executable files
81
Suspicious files
71
Text files
185
Unknown types
1

Dropped files

PID
Process
Filename
Type
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nsb516A.tmp\System.dllexecutable
MD5:4ADD245D4BA34B04F213409BFE504C07
SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nsb516A.tmp\INetC.dllexecutable
MD5:40D7ECA32B2F4D29DB98715DD45BFAC5
SHA256:85E03805F90F72257DD41BFDAA186237218BBB0EC410AD3B6576A88EA11DCCB9
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\setup_3560689[1].exeexecutable
MD5:8F9AE852D1A2966417AB3D114DAF91E3
SHA256:24328D8F838B12307C121E0B953E564F27059302A3BBF12D54E94D855F561CA4
8852starter.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\bqWhxxuyKRoKg[1].txttext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
8852starter.exeC:\Users\admin\AppData\Local\Temp\nshABEF.tmp\stext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
8852starter.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:5777E1037DD7C399BAD0205FE35EFD47
SHA256:1ABC584B839913A028B9E6EE02FEA6C8859930FC30B463A2C778092CBFA6E0CE
8852starter.exeC:\Users\admin\AppData\Local\Temp\nshABEF.tmp\status.logtext
MD5:444BCB3A3FCF8389296C49467F27E1D6
SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nsb516A.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nsb516A.tmp\nsDialogs.dllexecutable
MD5:1D8F01A83DDD259BC339902C1D33C8F1
SHA256:4B7D17DA290F41EBE244827CC295CE7E580DA2F7E9F7CC3EFC1ABC6898E3C9ED
8316Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nsb516A.tmp\NSISdl.dllexecutable
MD5:05F72D6A944E701217EF2EB2CC13E0EE
SHA256:AAB28914794A1CDDA4561E9F2AF3E006DBED220D9D6BFE049B56D0CB9B783648
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
139
TCP/UDP connections
68
DNS requests
33
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
356
svchost.exe
POST
400
40.126.32.76:443
https://login.live.com/RST2.srf
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
200
172.67.205.73:80
http://housesice.space/U2kYpvKV
US
text
160 b
unknown
8736
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
356
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
302
188.114.97.0:443
https://rabbitsbird.info/pe/build.php?pe=n&sub=&source=3942&s1=57194526&title=RG93bmxvYWQgTmltYmxlIFRvb2xzIE5pbWJsZSBLaWNrIFdpTiAgUGx1Z2luIENyYWNr&ti=1771364749
US
html
175 b
unknown
356
svchost.exe
POST
400
40.126.32.76:443
https://login.live.com/RST2.srf
US
whitelisted
8736
svchost.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
binary
5.70 Kb
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
200
142.250.180.3:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
200
142.250.180.3:80
http://c.pki.goog/r/r4.crl
US
binary
528 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8736
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7244
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
172.67.205.73:80
housesice.space
CLOUDFLARENET
US
whitelisted
356
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
188.114.97.0:443
rabbitsbird.info
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 13.69.116.105
whitelisted
google.com
  • 142.250.180.14
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
housesice.space
  • 172.67.205.73
unknown
login.live.com
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
rabbitsbird.info
  • 188.114.97.0
malicious
c.pki.goog
  • 142.250.180.3
whitelisted
crl.microsoft.com
  • 84.53.175.17
whitelisted

Threats

PID
Process
Class
Message
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] NSIS INetC plugin User-Agent observed in HTTP request
8852
starter.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] NSIS INetC plugin User-Agent observed in HTTP request
8852
starter.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
8852
starter.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
8852
starter.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
A Network Trojan was detected
ET MALWARE Suspicious Download Setup_ exe
8316
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
8852
starter.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
8852
starter.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
8852
starter.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
No debug info