File name:

Ninite ImgBurn Installer.exe

Full analysis: https://app.any.run/tasks/41ee092c-4ee9-4572-b580-19bda67896da
Verdict: Malicious activity
Analysis date: August 20, 2024, 05:26:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
antivm
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0B1821562C5F2C4D2D6863CD915E6CCD

SHA1:

21E95E2BC95AA4C5652CBBBC4D86F44C310A0635

SHA256:

20D5D5C3F9374CEDA90904352C0A225156C1B88DFBB1113921DBC61C04863EA9

SSDEEP:

12288:1LVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEA:pVP60BM2pMUN9keo+c+zEA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 6868)
      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
    • Drops the executable file immediately after the start

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
    • Checks Windows Trust Settings

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
    • Executable content was dropped or overwritten

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
    • Reads the date of Windows installation

      • Ninite.exe (PID: 6868)
    • Application launched itself

      • Ninite.exe (PID: 6868)
    • Searches for installed software

      • Ninite.exe (PID: 7044)
    • The process creates files with name similar to system file names

      • target.exe (PID: 6884)
    • Creates a software uninstall entry

      • target.exe (PID: 6884)
    • There is functionality for taking screenshot (YARA)

      • ImgBurn.exe (PID: 7040)
    • There is functionality for VM detection (antiVM strings)

      • ImgBurn.exe (PID: 7040)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • target.exe (PID: 6884)
  • INFO

    • Checks proxy server information

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
    • Checks supported languages

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 6868)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
      • unzip.exe (PID: 6916)
      • ImgBurn.exe (PID: 7040)
    • Reads the computer name

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 6868)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
      • ImgBurn.exe (PID: 7040)
    • Creates files or folders in the user directory

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
    • Reads the machine GUID from the registry

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
    • Reads the software policy settings

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
    • Create files in a temporary directory

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
    • Process checks computer location settings

      • Ninite.exe (PID: 6868)
    • Creates files in the program directory

      • target.exe (PID: 6884)
      • Ninite.exe (PID: 7044)
    • Manual execution by a user

      • ImgBurn.exe (PID: 7040)
    • UPX packer has been detected

      • ImgBurn.exe (PID: 7040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
7
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ninite imgburn installer.exe ninite.exe no specs ninite.exe target.exe unzip.exe no specs conhost.exe no specs THREAT imgburn.exe

Process information

PID
CMD
Path
Indicators
Parent process
6768"C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe" C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe
explorer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Exit code:
0
Version:
0,1,1,1183
Modules
Images
c:\users\admin\appdata\local\temp\ninite imgburn installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6868Ninite.exe "e9ecd70c87f3c20101cc61fef429932d1180d6a4" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe"C:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exeNinite ImgBurn Installer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6884target.exe /S /NOCANDYC:\Users\admin\AppData\Local\Temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
LIGHTNING UK!
Integrity Level:
HIGH
Description:
ImgBurn Installer
Exit code:
0
Version:
2.5.8.0
Modules
Images
c:\users\admin\appdata\local\temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6892\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeunzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6916"C:\Users\admin\AppData\Local\Temp\BE19E2~1\unzip.exe" -o translation.zipC:\Users\admin\AppData\Local\Temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\unzip.exeNinite.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7040"C:\Program Files (x86)\ImgBurn\ImgBurn.exe" C:\Program Files (x86)\ImgBurn\ImgBurn.exe
explorer.exe
User:
admin
Company:
LIGHTNING UK!
Integrity Level:
MEDIUM
Description:
ImgBurn - The Ultimate Image Burner!
Exit code:
0
Version:
2.5.8.0
Modules
Images
c:\program files (x86)\imgburn\imgburn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7044"C:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exe" "e9ecd70c87f3c20101cc61fef429932d1180d6a4" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe" /relaunchC:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exe
Ninite.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
HIGH
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
16 344
Read events
15 684
Write events
658
Delete events
2

Modification events

(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7044) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7044) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
10
Suspicious files
24
Text files
2
Unknown types
3

Dropped files

PID
Process
Filename
Type
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exeexecutable
MD5:F1DB4FE1D4559183CD1B35A257C970CC
SHA256:A5F912CCBDE324B7C5F5D81076CCDA813B2D80D311F4C854D358B85B02094D56
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_6C354C532D063DF5607A63BA827F5164der
MD5:063D8D790DA4C828DBF9FBC7ABDFB21C
SHA256:F0358EB9D4525A151C0B774A0F522A166D34417B9A2ED23928EDB456AE563260
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fder
MD5:3E910A164A1056F0821B4FD5C45E5226
SHA256:3133E46785F67837F5BF6D462DB45EA40DB1502883B7DEA85172013190B31F94
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_6C354C532D063DF5607A63BA827F5164binary
MD5:0B93DED84861232163E226A31FC44BD1
SHA256:2BA085711B4D474C8A99841706E04FCDA88C902FB2CE5E6917905C4F113ECA36
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517der
MD5:E50123C5FF73350C64D05AA96B5F9DC7
SHA256:826193FD8B17E0E1100C2642E9E3E0A1A8C614B818EF9A706D6055595C3E76EF
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cder
MD5:9A434BD11534ABBC2C217873A73E8E05
SHA256:009116B4D95A5D5F43BDB6F901E37D394F457C8AEEFB3B232451661E4A10B736
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:44824BE66ABA73F05DF293112EF54865
SHA256:1865CA419F06CD93C21586E87B84DF8927BA039AC32FC42A89050A2EC17875F0
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:E76E6DF2C4F09616E147648B732B060E
SHA256:35CA52C023D2E86E3C39038618FD35891F2A64CE1600E370739AA9A7CACD06B6
7044Ninite.exeC:\Users\admin\AppData\Local\Temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\translation.zip_be19e202-5eb4-11ef-b4e3-18f7786f96eecompressed
MD5:76CDB2BAD9582D23C1F6F4D868218D6C
SHA256:8739C76E681F900923B900C9DF0EF75CF421D39CABB54650C4B9AD19B6A76D85
7044Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:D2311FD0E2FCEAAE4C95D58F979F1606
SHA256:124FCABB6D30049E24B559C5A79BA111B4D1FCEEB7414F03EE0EDC9E8F14D59A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
42
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
6728
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7044
Ninite.exe
GET
200
23.53.40.154:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgSKzUNgjhNLQ14AiZMv1WtnkQ%3D%3D
unknown
whitelisted
1288
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6768
Ninite ImgBurn Installer.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
6768
Ninite ImgBurn Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
7040
ImgBurn.exe
GET
200
51.222.108.129:80
http://download.imgburn.com/_imgburn_version.txt
unknown
unknown
7040
ImgBurn.exe
GET
301
34.198.182.201:80
http://update1.imgburn.com/_imgburn_version.txt
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4248
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3236
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
6768
Ninite ImgBurn Installer.exe
13.32.27.85:443
ninite.com
AMAZON-02
US
unknown
6768
Ninite ImgBurn Installer.exe
18.245.39.64:80
ocsp.rootca1.amazontrust.com
US
unknown
6768
Ninite ImgBurn Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
7044
Ninite.exe
13.32.27.85:443
ninite.com
AMAZON-02
US
unknown
7044
Ninite.exe
54.231.129.81:443
ninite-tools.s3.amazonaws.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 172.217.18.110
whitelisted
ninite.com
  • 13.32.27.85
  • 13.32.27.127
  • 13.32.27.121
  • 13.32.27.117
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ninite-tools.s3.amazonaws.com
  • 54.231.129.81
  • 54.231.194.9
  • 52.216.220.17
  • 54.231.199.113
  • 52.217.169.241
  • 52.216.62.249
  • 16.182.104.25
  • 16.182.71.177
shared
ocsp.r2m01.amazontrust.com
  • 18.173.208.27
whitelisted
download.imgburn.com
  • 51.222.108.129
unknown
r11.o.lencr.org
  • 23.53.40.154
  • 23.53.40.161
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted

Threats

No threats detected
No debug info