File name:

Netflix-CE V5.1_48897101.exe

Full analysis: https://app.any.run/tasks/7dcebeb0-6b0f-4fec-bb96-cebe19be7d08
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 30, 2024, 14:56:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1198DAAA23F0AF650C7CD4555FBEF9E8

SHA1:

783F86460785027A41A84E41B42A05B4D4A1A462

SHA256:

25C846183E10BD2A146325EFFECDDBABF0F390717FD11D597012A033E6DAF600

SSDEEP:

98304:pQR6VdJ09uqigD3RAMF6LgaZze6wXCawiMVQwP3F1PwuQqkZObuyX+QuZUREMsLb:A1+GiB+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
    • Actions looks like stealing of personal data

      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • setup48897101.exe (PID: 1704)
      • OfferInstaller.exe (PID: 1844)
    • Reads settings of System Certificates

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Reads the Internet Settings

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • setup48897101.exe (PID: 1704)
      • OfferInstaller.exe (PID: 1844)
    • Checks Windows Trust Settings

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
    • Executable content was dropped or overwritten

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
    • The process creates files with name similar to system file names

      • setup48897101.exe (PID: 1292)
    • Reads the Windows owner or organization settings

      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • The process drops C-runtime libraries

      • setup48897101.exe (PID: 1292)
    • Process drops legitimate windows executable

      • setup48897101.exe (PID: 1292)
    • Access to an unwanted program domain was detected

      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Searches for installed software

      • setup48897101.exe (PID: 1292)
    • Starts CMD.EXE for commands execution

      • setup48897101.exe (PID: 1292)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1640)
    • Adds/modifies Windows certificates

      • setup48897101.exe (PID: 1292)
    • Executing commands from a ".bat" file

      • setup48897101.exe (PID: 1292)
    • Get information on the list of running processes

      • cmd.exe (PID: 1640)
    • Start notepad (likely ransomware note)

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
  • INFO

    • Checks supported languages

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • wmpnscfg.exe (PID: 764)
      • setup48897101.exe (PID: 1704)
      • OfferInstaller.exe (PID: 1844)
    • Reads the computer name

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • wmpnscfg.exe (PID: 764)
      • OfferInstaller.exe (PID: 1844)
      • setup48897101.exe (PID: 1704)
    • Creates files or folders in the user directory

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Checks proxy server information

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
    • Reads the machine GUID from the registry

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • setup48897101.exe (PID: 1704)
      • OfferInstaller.exe (PID: 1844)
    • Reads the software policy settings

      • Netflix-CE V5.1_48897101.exe (PID: 4088)
      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Reads product name

      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Reads Environment values

      • setup48897101.exe (PID: 1292)
      • OfferInstaller.exe (PID: 1844)
    • Create files in a temporary directory

      • setup48897101.exe (PID: 1292)
      • setup48897101.exe (PID: 1704)
      • OfferInstaller.exe (PID: 1844)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:24 20:04:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.22
CodeSize: 4347392
InitializedDataSize: 5656576
UninitializedDataSize: -
EntryPoint: 0x396dbb
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Download Manager
FileVersion: 1
InternalName: Download Manager
LegalCopyright: Download Manager
OriginalFileName: Download Manager
ProductName: Download Manager
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
11
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start netflix-ce v5.1_48897101.exe setup48897101.exe wmpnscfg.exe no specs setup48897101.exe no specs offerinstaller.exe cmd.exe no specs tasklist.exe no specs find.exe no specs timeout.exe no specs notepad.exe no specs netflix-ce v5.1_48897101.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
860timeout 5C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1292C:\Users\admin\AppData\Local\setup48897101.exe hhwnd=131370 hreturntoinstaller hextras=id:785dcafef1ce402-DE-PiJMZC:\Users\admin\AppData\Local\setup48897101.exe
Netflix-CE V5.1_48897101.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup48897101.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1640C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\H2OCleanup.bat""C:\Windows\System32\cmd.exesetup48897101.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1704C:\Users\admin\AppData\Local\setup48897101.exe hreadyC:\Users\admin\AppData\Local\setup48897101.exeNetflix-CE V5.1_48897101.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup48897101.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1844"C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe" C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe
setup48897101.exe
User:
admin
Company:
Adaware
Integrity Level:
HIGH
Description:
OfferInstaller
Version:
7.14.2.0
Modules
Images
c:\users\admin\appdata\local\temp\ec05d89197b949eb6957b79472e8723d\offerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2236find /I "1292"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2284tasklist /FI "PID eq 1292" /fo csv C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2528"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\link.txtC:\Windows\System32\notepad.exeNetflix-CE V5.1_48897101.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3976"C:\Users\admin\AppData\Local\Temp\Netflix-CE V5.1_48897101.exe" C:\Users\admin\AppData\Local\Temp\Netflix-CE V5.1_48897101.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Download Manager
Exit code:
3221226540
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\netflix-ce v5.1_48897101.exe
c:\windows\system32\ntdll.dll
Total events
29 075
Read events
28 897
Write events
161
Delete events
17

Modification events

(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4088) Netflix-CE V5.1_48897101.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
23
Suspicious files
10
Text files
21
Unknown types
7

Dropped files

PID
Process
Filename
Type
1292setup48897101.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\GenericSetup.dllexecutable
MD5:08112F27DCD8F1D779231A7A3E944CB1
SHA256:11C6A8470A3F2B2BE9B8CAFE5F9A0AFCE7303BFD02AB783A0F0EE09A184649FA
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:E3FCB68529038CEA76609881C9FA1E9E
SHA256:ED6274AB494212C3ACE4CD30FB8D521F8E9EFCC79F37EBBECCCF59B933CF2DFC
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\700B9980BA1F8C3D19B9578F56B7386F_345749F8109B3F0DBE7840DC04B120E5binary
MD5:80ABB38A51B3786B4FD66362F4DCC689
SHA256:7924611A16095DF18484E55717AD5FAA729B1F9CCA61888D7D91758DA596D7AC
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:43543E0A190EA104C457FACCFB497C52
SHA256:DE94BB9E19A0CFA84CBEA93040079C2FA1326318E5960B111009D4DD4A87E727
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\service[1].htmtext
MD5:0674241EB88930660BC13CD57CE70420
SHA256:63B1A1D9446E64E460233631249AFDF9B1CA10A606A22D101E1EF618F0631282
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\geo[1].htmtext
MD5:4437140084A30D4C644AB6F184079AA3
SHA256:B4083751F9B9078429250593D100A9233EE3CA83D21D26A49641E112B02F472A
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:2F369D9EBE62434F6E7FA122D3F4FDA2
SHA256:46C84D44F7F1BBBF863723EC79F02074B8C5BCCE63B9AFFBE4E87EFD9D8CB8CA
4088Netflix-CE V5.1_48897101.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\700B9980BA1F8C3D19B9578F56B7386F_345749F8109B3F0DBE7840DC04B120E5binary
MD5:A3B9CCBED212EA849C978F831032A7E8
SHA256:739ACB622DDB0724F17BC06164426CCE05CBBD6A205B09B1521FB3E821599AAD
1292setup48897101.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\msvcp140.dllexecutable
MD5:8FF1898897F3F4391803C7253366A87B
SHA256:51398691FEEF7AE0A876B523AEC47C4A06D9A1EE62F1A0AEE27DE6D6191C68AD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
25
DNS requests
14
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4088
Netflix-CE V5.1_48897101.exe
GET
304
23.216.77.72:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cfe0a7f8e7962138
unknown
unknown
4088
Netflix-CE V5.1_48897101.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
unknown
1292
setup48897101.exe
GET
200
23.216.77.72:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6332dae1732afbf8
unknown
unknown
4088
Netflix-CE V5.1_48897101.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
unknown
4088
Netflix-CE V5.1_48897101.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/s/gts1d4/w2JVwme7rvU/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEELAll3IHWDiEuOptsbe6aY%3D
unknown
unknown
GET
200
142.250.186.35:80
http://ocsp.pki.goog/s/gts1d4/c60NpY15aYI/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDIkRwUzpFoGQr1j0t77Yt6
unknown
unknown
4088
Netflix-CE V5.1_48897101.exe
GET
200
2.19.217.103:80
http://x1.c.lencr.org/
unknown
unknown
4088
Netflix-CE V5.1_48897101.exe
GET
200
2.19.217.103:80
http://x2.c.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
4088
Netflix-CE V5.1_48897101.exe
35.190.60.70:443
www.dlsft.com
GOOGLE
US
whitelisted
4088
Netflix-CE V5.1_48897101.exe
23.216.77.72:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4088
Netflix-CE V5.1_48897101.exe
142.250.186.35:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1292
setup48897101.exe
104.16.149.130:443
flow.lavasoft.com
CLOUDFLARENET
unknown
1292
setup48897101.exe
104.16.212.94:443
sos.adaware.com
CLOUDFLARENET
unknown
1292
setup48897101.exe
23.216.77.72:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4088
Netflix-CE V5.1_48897101.exe
188.114.97.3:443
filedm.com
CLOUDFLARENET
NL
unknown

DNS requests

Domain
IP
Reputation
www.dlsft.com
  • 35.190.60.70
unknown
ctldl.windowsupdate.com
  • 23.216.77.72
  • 23.216.77.44
whitelisted
ocsp.pki.goog
  • 142.250.186.35
whitelisted
www.google.com
  • 216.58.206.68
whitelisted
flow.lavasoft.com
  • 104.16.149.130
  • 104.16.148.130
whitelisted
sos.adaware.com
  • 104.16.212.94
  • 104.16.213.94
whitelisted
dlsft.com
  • 35.190.60.70
unknown
filedm.com
  • 188.114.97.3
  • 188.114.96.3
malicious
x1.c.lencr.org
  • 2.19.217.103
whitelisted
x2.c.lencr.org
  • 2.19.217.103
whitelisted

Threats

Found threats are available for the paid subscriptions
5 ETPRO signatures available at the full report
Process
Message
Netflix-CE V5.1_48897101.exe
at initializeDynamicVariables (this://app/main.html(329))
Netflix-CE V5.1_48897101.exe
at getFileInfo.@285@39 (this://app/main.html(307))
Netflix-CE V5.1_48897101.exe
Netflix-CE V5.1_48897101.exe
Error: (undefined) has no property - value
Netflix-CE V5.1_48897101.exe
setup48897101.exe
setup48897101.exe
Error: File not found - sciterwrapper:console.tis
setup48897101.exe
setup48897101.exe
at sciter:init-script.tis
setup48897101.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'