File name:

TFM Pgiex Client v6.zip

Full analysis: https://app.any.run/tasks/24080cb3-e1bd-412c-8a38-de3712a8a4c7
Verdict: Malicious activity
Analysis date: February 06, 2022, 19:56:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CDBB36E31429222672198D13FA2ECF09

SHA1:

77310F77ACF474E8A2A2BFD55461EA4C7F6BAF32

SHA256:

23F9B243882F95EB2FB6EEA5DE1E63658F2395823F927568D50AAC8AEA8ACF35

SSDEEP:

196608:K6fZOUWT7cKSUFP94Vntzu2FT6Brx/33R4ikdV/20kRsgLlYRKCnnnphKlb3WZa5:KD7nSUFUnRpFeB9p4ljlktLlYQ6gWZuv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3204)
      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • Adobe AIR Updater.exe (PID: 2068)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
    • Application was dropped or rewritten from another process

      • AdobeAIR.exe (PID: 2984)
      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • Adobe AIR Updater.exe (PID: 2068)
      • Pgiex - Transformice SWF Updater.exe (PID: 3400)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3164)
      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • Adobe AIR Updater.exe (PID: 2068)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
      • AdobeAIR.exe (PID: 2984)
      • Pgiex - Transformice SWF Updater.exe (PID: 3400)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3164)
      • AdobeAIR.exe (PID: 2984)
      • msiexec.exe (PID: 3696)
      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
    • Drops a file that was compiled in debug mode

      • AdobeAIR.exe (PID: 2984)
      • WinRAR.exe (PID: 3164)
      • msiexec.exe (PID: 3696)
      • adobe air installer.exe (PID: 2940)
      • Adobe AIR Installer.exe (PID: 3192)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
    • Reads CPU info

      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • Adobe AIR Updater.exe (PID: 2068)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
    • Checks supported languages

      • WinRAR.exe (PID: 3164)
      • Adobe AIR Installer.exe (PID: 3192)
      • adobe air installer.exe (PID: 2940)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
      • Adobe AIR Updater.exe (PID: 2068)
      • AdobeAIR.exe (PID: 2984)
      • Pgiex - Transformice SWF Updater.exe (PID: 3400)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3164)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3164)
    • Creates files in the user directory

      • Adobe AIR Installer.exe (PID: 3192)
      • Adobe AIR Updater.exe (PID: 2068)
      • TFMClient - Pgiex Tfm.exe (PID: 2824)
    • Application launched itself

      • Adobe AIR Installer.exe (PID: 3192)
    • Executed as Windows Service

      • msiexec.exe (PID: 3696)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3696)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3696)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3696)
    • Creates files in the program directory

      • msiexec.exe (PID: 3696)
      • adobe air installer.exe (PID: 2940)
    • Changes default file association

      • msiexec.exe (PID: 3696)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3696)
    • Reads Environment values

      • TFMClient - Pgiex Tfm.exe (PID: 2136)
      • Pgiex - Transformice SWF Updater.exe (PID: 3400)
  • INFO

    • Manual execution by user

      • AdobeAIR.exe (PID: 2984)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
    • Reads the computer name

      • msiexec.exe (PID: 3696)
    • Checks supported languages

      • msiexec.exe (PID: 3696)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3696)
      • Adobe AIR Updater.exe (PID: 2068)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3696)
      • Adobe AIR Updater.exe (PID: 2068)
      • TFMClient - Pgiex Tfm.exe (PID: 2136)
      • Pgiex - Transformice SWF Updater.exe (PID: 3400)
    • Dropped object may contain Bitcoin addresses

      • TFMClient - Pgiex Tfm.exe (PID: 2824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: AdobeAIR.exe
ZipUncompressedSize: 7689512
ZipCompressedSize: 7351309
ZipCRC: 0xeaed1e2b
ZipModifyDate: 2021:03:25 12:16:14
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
10
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe searchprotocolhost.exe no specs adobeair.exe adobe air installer.exe adobe air installer.exe msiexec.exe adobe air updater.exe tfmclient - pgiex tfm.exe pgiex - transformice swf updater.exe tfmclient - pgiex tfm.exe

Process information

PID
CMD
Path
Indicators
Parent process
2068"c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -installupdatecheckc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
Adobe AIR Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
33.1.1.385
Modules
Images
c:\program files\common files\adobe air\versions\1.0\resources\adobe air updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
2136"C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe" C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
TFMClient - Pgiex Tfm
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\users\admin\desktop\tfm pgiex client v6\tfmclient - pgiex tfm.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2824"C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe" C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe
TFMClient - Pgiex Tfm.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\0343508a-1741-4891-84da-05c4846283be\tfmclient - pgiex tfm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2940"C:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe" -stdio \\.\pipe\AIR_3192_0 -eiC:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe
Adobe AIR Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
HIGH
Description:
Adobe AIR Installer
Exit code:
0
Version:
33.1.1.385
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2984"C:\Users\admin\Desktop\AdobeAIR.exe" C:\Users\admin\Desktop\AdobeAIR.exe
Explorer.EXE
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
33.1.1.385
Modules
Images
c:\users\admin\desktop\adobeair.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3164"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3192"C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe
AdobeAIR.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
33.1.1.385
Modules
Images
c:\users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3204"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3400"C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe"C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe
TFMClient - Pgiex Tfm.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Pgiex - Transformice SWF Updater
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\0343508a-1741-4891-84da-05c4846283be\pgiex - transformice swf updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3696C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
23 085
Read events
22 769
Write events
303
Delete events
13

Modification events

(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3164) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
35
Suspicious files
17
Text files
56
Unknown types
86

Dropped files

PID
Process
Filename
Type
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pixman\COPYINGtext
MD5:1168F6DA9F901D48731A7D51940FECAD
SHA256:6E9F39A63E6E8AE87DE8AFDF5E7E9571B964A52717614EDB84675016042F6AFC
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\template.msiexecutable
MD5:32FF6AEB858F568659329935919BA4BB
SHA256:6F71B263DA13DFD79E16CA35C49CA39AD0EC370F902FB87E9C8F9395FA9A41E8
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\sentineltext
MD5:A5C11CA014FE30B8085EA2E95F7196C4
SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\setup.swfswf
MD5:60CB4BC16891B669EDD5D7094CE403F1
SHA256:3DDC574F0DB25A3C18EF30A448057FA48851F7CCA195258347CAB156C5BB7673
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swfswf
MD5:9C9D13B4EBCE6056466C3ECED7A60631
SHA256:54C854CB8DE91C1FCC05BF9ACE5EE71E98E7ECDC80D234EFF54AC1318C43CC9F
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\WebKit\LGPL License.txttext
MD5:8C2A8D5DB686D0E41323611A1DCABB67
SHA256:98B84A0EF7B265DFD8C4796BC03EFF27EBCE5491026798C14508D80049434FEB
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pcre2\COPYINGtext
MD5:1F800C179F381B72E818AAB4BA25C504
SHA256:4F8DEFD8B03D6E0DF53C3A37FD37CAF2BD8A5E8E77F7886FE3557BA4CDA45E8C
3164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5707\AdobeAIR.exeexecutable
MD5:CE0059C94FD5F8099E54F85FF204B511
SHA256:D5C8659A712145CC19B4E23FF0C731C87FEFC5C100D98C963A2689C5FD97A96C
2984AdobeAIR.exeC:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Adobe Root Certificate.cerder
MD5:BF70913FF8D6D60A47FE825330815DB4
SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC
3164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5179\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exeexecutable
MD5:08773F1A4562128900D33D360BCE85E1
SHA256:AD479BF73BD329475B843C4A1786796C3F202D71F5D1C41CA8E5DA3B40CDED7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
81
TCP/UDP connections
35
DNS requests
13
Threats
24

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2136
TFMClient - Pgiex Tfm.exe
GET
204
142.250.186.78:80
http://google.com/generate_204
US
malicious
2068
Adobe AIR Updater.exe
GET
200
52.222.206.67:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
2068
Adobe AIR Updater.exe
GET
200
18.66.92.28:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
2824
TFMClient - Pgiex Tfm.exe
GET
200
51.75.128.119:80
http://www.transformice.com/langues/tfm-pl.gz?d=695
GB
pz
52.8 Kb
suspicious
2824
TFMClient - Pgiex Tfm.exe
GET
200
51.75.128.119:80
http://www.transformice.com/images/x_bibliotheques/x_meli_costumes.swf?d=685.695?d=685
GB
swf
599 Kb
suspicious
2824
TFMClient - Pgiex Tfm.exe
GET
200
51.75.128.119:80
http://www.transformice.com/images/x_bibliotheques/costume1.swf?d=685.695?d=685
GB
swf
28.8 Kb
suspicious
2068
Adobe AIR Updater.exe
GET
200
13.32.118.159:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEArnLp9awM69gd%2BIe6rguv0%3D
US
der
471 b
whitelisted
2824
TFMClient - Pgiex Tfm.exe
GET
200
51.75.128.119:80
http://www.transformice.com/images/x_bibliotheques/fourrures/f222.swf?d=685.695?d=685
GB
swf
8.47 Kb
suspicious
2824
TFMClient - Pgiex Tfm.exe
GET
200
212.47.246.230:80
http://audio.atelier801.com/transformice/musique/intro.mp3
FR
mp3
931 Kb
suspicious
2824
TFMClient - Pgiex Tfm.exe
GET
200
51.75.128.119:80
http://www.transformice.com/images/x_bibliotheques/fourrures/f223.swf?d=685.695?d=685
GB
swf
9.12 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2136
TFMClient - Pgiex Tfm.exe
142.250.186.78:80
google.com
Google Inc.
US
whitelisted
2068
Adobe AIR Updater.exe
54.144.96.229:443
airsdk.harman.com
Amazon.com, Inc.
US
unknown
2068
Adobe AIR Updater.exe
67.27.233.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
2136
TFMClient - Pgiex Tfm.exe
140.82.36.185:443
bolcorp.icu
US
suspicious
2068
Adobe AIR Updater.exe
13.32.118.159:80
ocsp.sca1b.amazontrust.com
Amazon.com, Inc.
US
whitelisted
2824
TFMClient - Pgiex Tfm.exe
140.82.36.185:80
bolcorp.icu
US
suspicious
2136
TFMClient - Pgiex Tfm.exe
162.159.134.233:443
discordapp.com
Cloudflare Inc
shared
2824
TFMClient - Pgiex Tfm.exe
37.187.29.8:11801
OVH SAS
FR
malicious
2824
TFMClient - Pgiex Tfm.exe
51.75.128.119:80
www.transformice.com
GB
suspicious
2824
TFMClient - Pgiex Tfm.exe
51.158.113.197:80
GB
suspicious

DNS requests

Domain
IP
Reputation
airsdk.harman.com
  • 54.144.96.229
  • 23.23.10.80
suspicious
ctldl.windowsupdate.com
  • 67.27.233.254
  • 8.253.204.120
  • 67.27.157.126
  • 67.27.159.254
  • 67.27.233.126
whitelisted
google.com
  • 142.250.186.78
malicious
bolcorp.icu
  • 140.82.36.185
malicious
o.ss2.us
  • 18.66.92.28
  • 18.66.92.73
  • 18.66.92.207
  • 18.66.92.70
whitelisted
ocsp.rootg2.amazontrust.com
  • 52.222.206.67
  • 52.222.206.202
  • 52.222.206.73
  • 52.222.206.35
whitelisted
ocsp.rootca1.amazontrust.com
  • 52.222.206.73
  • 52.222.206.35
  • 52.222.206.67
  • 52.222.206.202
shared
ocsp.sca1b.amazontrust.com
  • 13.32.118.159
  • 13.32.118.108
  • 13.32.118.23
  • 13.32.118.71
whitelisted
transformice.bolcorp.icu
  • 140.82.36.185
suspicious
discordapp.com
  • 162.159.134.233
  • 162.159.133.233
  • 162.159.129.233
  • 162.159.130.233
  • 162.159.135.233
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
2136
TFMClient - Pgiex Tfm.exe
Potentially Bad Traffic
ET INFO Suspicious Domain (*.icu) in TLS SNI
2136
TFMClient - Pgiex Tfm.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
2136
TFMClient - Pgiex Tfm.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
2136
TFMClient - Pgiex Tfm.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
3400
Pgiex - Transformice SWF Updater.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
3400
Pgiex - Transformice SWF Updater.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
2824
TFMClient - Pgiex Tfm.exe
Potential Corporate Privacy Violation
ET POLICY Outdated Flash Version M1
2824
TFMClient - Pgiex Tfm.exe
Potential Corporate Privacy Violation
ET INFO Observed Interesting Content-Type Inbound (application/x-sh)
2824
TFMClient - Pgiex Tfm.exe
Potential Corporate Privacy Violation
ET INFO Observed Interesting Content-Type Inbound (application/x-sh)
No debug info