File name:

Ninite ImgBurn Installer.exe

Full analysis: https://app.any.run/tasks/41ee092c-4ee9-4572-b580-19bda67896da
Verdict: Malicious activity
Analysis date: August 20, 2024, 05:26:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
antivm
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0B1821562C5F2C4D2D6863CD915E6CCD

SHA1:

21E95E2BC95AA4C5652CBBBC4D86F44C310A0635

SHA256:

20D5D5C3F9374CEDA90904352C0A225156C1B88DFBB1113921DBC61C04863EA9

SSDEEP:

12288:1LVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEA:pVP60BM2pMUN9keo+c+zEA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • target.exe (PID: 6884)
      • Ninite.exe (PID: 7044)
    • Reads security settings of Internet Explorer

      • Ninite.exe (PID: 6868)
      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
    • Reads the date of Windows installation

      • Ninite.exe (PID: 6868)
    • Application launched itself

      • Ninite.exe (PID: 6868)
    • Checks Windows Trust Settings

      • Ninite.exe (PID: 7044)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Executable content was dropped or overwritten

      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Searches for installed software

      • Ninite.exe (PID: 7044)
    • The process creates files with name similar to system file names

      • target.exe (PID: 6884)
    • Creates a software uninstall entry

      • target.exe (PID: 6884)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • target.exe (PID: 6884)
    • There is functionality for taking screenshot (YARA)

      • ImgBurn.exe (PID: 7040)
    • There is functionality for VM detection (antiVM strings)

      • ImgBurn.exe (PID: 7040)
  • INFO

    • Reads the computer name

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 6868)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
      • ImgBurn.exe (PID: 7040)
    • Checks supported languages

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 6868)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
      • unzip.exe (PID: 6916)
      • ImgBurn.exe (PID: 7040)
    • Create files in a temporary directory

      • Ninite ImgBurn Installer.exe (PID: 6768)
      • Ninite.exe (PID: 7044)
      • target.exe (PID: 6884)
    • Process checks computer location settings

      • Ninite.exe (PID: 6868)
    • Reads the machine GUID from the registry

      • Ninite.exe (PID: 7044)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Checks proxy server information

      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Creates files or folders in the user directory

      • Ninite.exe (PID: 7044)
      • ImgBurn.exe (PID: 7040)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Reads the software policy settings

      • Ninite.exe (PID: 7044)
      • Ninite ImgBurn Installer.exe (PID: 6768)
    • Creates files in the program directory

      • target.exe (PID: 6884)
      • Ninite.exe (PID: 7044)
    • Manual execution by a user

      • ImgBurn.exe (PID: 7040)
    • UPX packer has been detected

      • ImgBurn.exe (PID: 7040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
7
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ninite imgburn installer.exe ninite.exe no specs ninite.exe target.exe unzip.exe no specs conhost.exe no specs THREAT imgburn.exe

Process information

PID
CMD
Path
Indicators
Parent process
6768"C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe" C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe
explorer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Exit code:
0
Version:
0,1,1,1183
Modules
Images
c:\users\admin\appdata\local\temp\ninite imgburn installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6868Ninite.exe "e9ecd70c87f3c20101cc61fef429932d1180d6a4" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe"C:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exeNinite ImgBurn Installer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6884target.exe /S /NOCANDYC:\Users\admin\AppData\Local\Temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
LIGHTNING UK!
Integrity Level:
HIGH
Description:
ImgBurn Installer
Exit code:
0
Version:
2.5.8.0
Modules
Images
c:\users\admin\appdata\local\temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6892\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeunzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6916"C:\Users\admin\AppData\Local\Temp\BE19E2~1\unzip.exe" -o translation.zipC:\Users\admin\AppData\Local\Temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\unzip.exeNinite.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\be19e201-5eb4-11ef-b4e3-18f7786f96ee\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7040"C:\Program Files (x86)\ImgBurn\ImgBurn.exe" C:\Program Files (x86)\ImgBurn\ImgBurn.exe
explorer.exe
User:
admin
Company:
LIGHTNING UK!
Integrity Level:
MEDIUM
Description:
ImgBurn - The Ultimate Image Burner!
Exit code:
0
Version:
2.5.8.0
Modules
Images
c:\program files (x86)\imgburn\imgburn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7044"C:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exe" "e9ecd70c87f3c20101cc61fef429932d1180d6a4" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite ImgBurn Installer.exe" /relaunchC:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exe
Ninite.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
HIGH
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
16 344
Read events
15 684
Write events
658
Delete events
2

Modification events

(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6768) Ninite ImgBurn Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6868) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7044) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7044) Ninite.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
10
Suspicious files
24
Text files
2
Unknown types
3

Dropped files

PID
Process
Filename
Type
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_6C354C532D063DF5607A63BA827F5164der
MD5:063D8D790DA4C828DBF9FBC7ABDFB21C
SHA256:F0358EB9D4525A151C0B774A0F522A166D34417B9A2ED23928EDB456AE563260
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\Local\Temp\bc5734e1-5eb4-11ef-b4e3-18f7786f96ee\Ninite.exeexecutable
MD5:F1DB4FE1D4559183CD1B35A257C970CC
SHA256:A5F912CCBDE324B7C5F5D81076CCDA813B2D80D311F4C854D358B85B02094D56
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517der
MD5:E50123C5FF73350C64D05AA96B5F9DC7
SHA256:826193FD8B17E0E1100C2642E9E3E0A1A8C614B818EF9A706D6055595C3E76EF
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fder
MD5:3E910A164A1056F0821B4FD5C45E5226
SHA256:3133E46785F67837F5BF6D462DB45EA40DB1502883B7DEA85172013190B31F94
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:83E9A2CE0C886CE492844965D97A96E3
SHA256:A9A4DA6A60D301BBA972E892D6D69C68D42779A8355540EA63F71FA8A436032D
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:44824BE66ABA73F05DF293112EF54865
SHA256:1865CA419F06CD93C21586E87B84DF8927BA039AC32FC42A89050A2EC17875F0
6768Ninite ImgBurn Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cder
MD5:9A434BD11534ABBC2C217873A73E8E05
SHA256:009116B4D95A5D5F43BDB6F901E37D394F457C8AEEFB3B232451661E4A10B736
7044Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:3DFCA46E00FFA4795C72A41375F159D3
SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E
7044Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7E575680F4EFF24B25C9373B4F390332binary
MD5:B6E5B067E0D6B49707B17F2A5A291E22
SHA256:83C11077BA42E39E9AA2C6C643CBE95FACEADA886BF61D4A06F85AB2E1C80354
7044Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D03E46CD585BBE111C712E6577BC5F07_56B2A1FF8D0F5C5B4060FCF88A1654FEbinary
MD5:FD8D863585274E568CFEA5DF49061BBC
SHA256:E9975EDDA24BCE7385A16CC623DA9B37E5F6D2C2C375DF79431AB0C9E988C60B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
42
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
Ninite ImgBurn Installer.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
6768
Ninite ImgBurn Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
6768
Ninite ImgBurn Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
6768
Ninite ImgBurn Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgOhtwj4VKsGchDZBEc%3D
unknown
whitelisted
7044
Ninite.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
unknown
7044
Ninite.exe
GET
200
18.173.208.27:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAO9ExOMvLBqk2jkjdZnyjA%3D
unknown
whitelisted
7044
Ninite.exe
GET
200
23.53.40.154:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgSKzUNgjhNLQ14AiZMv1WtnkQ%3D%3D
unknown
whitelisted
6728
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7040
ImgBurn.exe
GET
200
51.222.108.129:80
http://download.imgburn.com/_imgburn_version.txt
unknown
unknown
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4248
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3236
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
6768
Ninite ImgBurn Installer.exe
13.32.27.85:443
ninite.com
AMAZON-02
US
unknown
6768
Ninite ImgBurn Installer.exe
18.245.39.64:80
ocsp.rootca1.amazontrust.com
US
unknown
6768
Ninite ImgBurn Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
7044
Ninite.exe
13.32.27.85:443
ninite.com
AMAZON-02
US
unknown
7044
Ninite.exe
54.231.129.81:443
ninite-tools.s3.amazonaws.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 172.217.18.110
whitelisted
ninite.com
  • 13.32.27.85
  • 13.32.27.127
  • 13.32.27.121
  • 13.32.27.117
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ninite-tools.s3.amazonaws.com
  • 54.231.129.81
  • 54.231.194.9
  • 52.216.220.17
  • 54.231.199.113
  • 52.217.169.241
  • 52.216.62.249
  • 16.182.104.25
  • 16.182.71.177
shared
ocsp.r2m01.amazontrust.com
  • 18.173.208.27
whitelisted
download.imgburn.com
  • 51.222.108.129
unknown
r11.o.lencr.org
  • 23.53.40.154
  • 23.53.40.161
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted

Threats

No threats detected
No debug info