File name:

NetTimeSetup-320a3.exe

Full analysis: https://app.any.run/tasks/98e0b668-5a4f-423c-98cc-232a13a33b6e
Verdict: Malicious activity
Analysis date: April 21, 2025, 14:46:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

E4201AE4CA46C6C94C7DA0D396FB8E8E

SHA1:

84C9456F7FDA8D540CE3CF233E2AA3A6F7C22B27

SHA256:

27A27E8B1B84D484544AB7F28A30FBC997C2C9B9409879F1F9C9571FC847AEF3

SSDEEP:

24576:eBgneAJJA3BGnc9DkfLtGiNqn9asktlbmriTkTh8PDAkOvyokAVcDahp:eB3AJJA3BGnc9DkfLtGiNi9asktlbmWu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • NetTime.exe (PID: 7728)
      • NetTime.exe (PID: 8180)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NetTimeSetup-320a3.exe (PID: 3884)
      • NetTimeSetup-320a3.exe (PID: 2136)
      • NetTimeSetup-320a3.tmp (PID: 6488)
    • Reads security settings of Internet Explorer

      • NetTimeSetup-320a3.tmp (PID: 7148)
      • NetTime.exe (PID: 7800)
    • Reads the Windows owner or organization settings

      • NetTimeSetup-320a3.tmp (PID: 6488)
    • Process drops legitimate windows executable

      • NetTimeSetup-320a3.tmp (PID: 6488)
    • There is functionality for taking screenshot (YARA)

      • NetTimeSetup-320a3.tmp (PID: 7148)
    • Application launched itself

      • NetTime.exe (PID: 7800)
    • Creates or modifies Windows services

      • NetTimeService.exe (PID: 7652)
      • NetTime.exe (PID: 7632)
    • Executes as Windows Service

      • NetTimeService.exe (PID: 7672)
  • INFO

    • Checks supported languages

      • NetTimeSetup-320a3.tmp (PID: 7148)
      • NetTimeSetup-320a3.exe (PID: 3884)
      • NetTimeSetup-320a3.exe (PID: 2136)
      • NetTimeSetup-320a3.tmp (PID: 6488)
      • NetTime.exe (PID: 7632)
      • NetTimeService.exe (PID: 7672)
      • NetTime.exe (PID: 7728)
      • NetTime.exe (PID: 7800)
      • NetTime.exe (PID: 8180)
      • NetTimeService.exe (PID: 7652)
    • Create files in a temporary directory

      • NetTimeSetup-320a3.exe (PID: 3884)
      • NetTimeSetup-320a3.exe (PID: 2136)
      • NetTimeSetup-320a3.tmp (PID: 6488)
    • Process checks computer location settings

      • NetTimeSetup-320a3.tmp (PID: 7148)
      • NetTime.exe (PID: 7800)
    • Creates a software uninstall entry

      • NetTimeSetup-320a3.tmp (PID: 6488)
    • Reads the computer name

      • NetTime.exe (PID: 7632)
      • NetTimeSetup-320a3.tmp (PID: 7148)
      • NetTimeSetup-320a3.tmp (PID: 6488)
      • NetTime.exe (PID: 7728)
      • NetTimeService.exe (PID: 7672)
      • NetTime.exe (PID: 7800)
      • NetTime.exe (PID: 8180)
      • NetTimeService.exe (PID: 7652)
    • Detects InnoSetup installer (YARA)

      • NetTimeSetup-320a3.exe (PID: 3884)
      • NetTimeSetup-320a3.tmp (PID: 7148)
    • Compiled with Borland Delphi (YARA)

      • NetTimeSetup-320a3.tmp (PID: 7148)
    • Creates files in the program directory

      • NetTimeSetup-320a3.tmp (PID: 6488)
      • NetTimeService.exe (PID: 7672)
    • The sample compiled with english language support

      • NetTimeSetup-320a3.tmp (PID: 6488)
    • Process checks whether UAC notifications are on

      • NetTime.exe (PID: 7800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mark Griffiths
FileDescription: NetTime Setup
FileVersion:
LegalCopyright: Copyright © 1997, 2000 by Graham Mainwaring, Copyright © 2011-2017 Mark Griffiths, Copyright © 2015
ProductName: NetTime
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
13
Malicious processes
1
Suspicious processes
6

Behavior graph

Click at the process to see the details
start nettimesetup-320a3.exe nettimesetup-320a3.tmp no specs nettimesetup-320a3.exe nettimesetup-320a3.tmp sppextcomobj.exe no specs slui.exe no specs nettime.exe no specs nettimeservice.exe no specs nettimeservice.exe nettime.exe nettime.exe nettime.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
2136"C:\Users\admin\Downloads\NetTimeSetup-320a3.exe" /SPAWNWND=$5028C /NOTIFYWND=$50304 C:\Users\admin\Downloads\NetTimeSetup-320a3.exe
NetTimeSetup-320a3.tmp
User:
admin
Company:
Mark Griffiths
Integrity Level:
HIGH
Description:
NetTime Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\nettimesetup-320a3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3884"C:\Users\admin\Downloads\NetTimeSetup-320a3.exe" C:\Users\admin\Downloads\NetTimeSetup-320a3.exe
explorer.exe
User:
admin
Company:
Mark Griffiths
Integrity Level:
MEDIUM
Description:
NetTime Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\nettimesetup-320a3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6488"C:\Users\admin\AppData\Local\Temp\is-7FFVT.tmp\NetTimeSetup-320a3.tmp" /SL5="$60282,542270,56832,C:\Users\admin\Downloads\NetTimeSetup-320a3.exe" /SPAWNWND=$5028C /NOTIFYWND=$50304 C:\Users\admin\AppData\Local\Temp\is-7FFVT.tmp\NetTimeSetup-320a3.tmp
NetTimeSetup-320a3.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7ffvt.tmp\nettimesetup-320a3.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7148"C:\Users\admin\AppData\Local\Temp\is-TU25A.tmp\NetTimeSetup-320a3.tmp" /SL5="$50304,542270,56832,C:\Users\admin\Downloads\NetTimeSetup-320a3.exe" C:\Users\admin\AppData\Local\Temp\is-TU25A.tmp\NetTimeSetup-320a3.tmpNetTimeSetup-320a3.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-tu25a.tmp\nettimesetup-320a3.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7196C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7244"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7632"C:\Program Files (x86)\NetTime\NetTime.exe" /installserviceC:\Program Files (x86)\NetTime\NetTime.exeNetTimeSetup-320a3.tmp
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.2.0.233
Modules
Images
c:\program files (x86)\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7652"C:\Program Files (x86)\NetTime\NetTimeService.exe" /install /silentC:\Program Files (x86)\NetTime\NetTimeService.exeNetTime.exe
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer - NT Service
Exit code:
0
Version:
3.2.0.233
Modules
Images
c:\program files (x86)\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7672"C:\Program Files (x86)\NetTime\NetTimeService.exe"C:\Program Files (x86)\NetTime\NetTimeService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Network Time Synchronizer - NT Service
Version:
3.2.0.233
Modules
Images
c:\program files (x86)\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
2 160
Read events
2 099
Write events
58
Delete events
3

Modification events

(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.5 (a)
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\NetTime
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\NetTime\
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Icon Group
Value:
NetTime
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
installservice
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Language
Value:
default
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:DisplayName
Value:
NetTime
(PID) Process:(6488) NetTimeSetup-320a3.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\NetTime\unins000.exe"
Executable files
10
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3884NetTimeSetup-320a3.exeC:\Users\admin\AppData\Local\Temp\is-TU25A.tmp\NetTimeSetup-320a3.tmpexecutable
MD5:9303156631EE2436DB23827E27337BE4
SHA256:BAE22F27C12BCE1FAEB64B6EB733302AFF5867BAA8EED832397A7CE284A86FF4
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\is-73L8N.tmpexecutable
MD5:2C6FC06E1A194CE00743683FB3FE1215
SHA256:A40AF8797928F466F9661AC20DBDDAB66BB0124716886629AAFB6FEEBEBC7CC1
6488NetTimeSetup-320a3.tmpC:\Users\admin\AppData\Local\Temp\is-KAKJ5.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6488NetTimeSetup-320a3.tmpC:\Users\admin\AppData\Local\Temp\is-KAKJ5.tmp\_isetup\_setup64.tmpexecutable
MD5:526426126AE5D326D0A24706C77D8C5C
SHA256:B20A8D88C550981137ED831F2015F5F11517AEB649C29642D9D61DEA5EBC37D1
2136NetTimeSetup-320a3.exeC:\Users\admin\AppData\Local\Temp\is-7FFVT.tmp\NetTimeSetup-320a3.tmpexecutable
MD5:9303156631EE2436DB23827E27337BE4
SHA256:BAE22F27C12BCE1FAEB64B6EB733302AFF5867BAA8EED832397A7CE284A86FF4
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\NetTime.exeexecutable
MD5:2C6FC06E1A194CE00743683FB3FE1215
SHA256:A40AF8797928F466F9661AC20DBDDAB66BB0124716886629AAFB6FEEBEBC7CC1
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\NetTimeService.exeexecutable
MD5:E552B5EF7B06DBA8B78AF8BB716D349F
SHA256:90E53BFAA4F79FE72016170384E05A40E25B99B08D9B7B762D06B156C70DA1A5
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\is-6KF20.tmpexecutable
MD5:E552B5EF7B06DBA8B78AF8BB716D349F
SHA256:90E53BFAA4F79FE72016170384E05A40E25B99B08D9B7B762D06B156C70DA1A5
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\unins000.exeexecutable
MD5:E622FBE75E85F078D73A8636F2227600
SHA256:AABA625D6B32805F2B8359B074D61E9F1B1493D06BD7B94FCB80F86BCEE45111
6488NetTimeSetup-320a3.tmpC:\Program Files (x86)\NetTime\is-JJ8CN.tmpexecutable
MD5:E622FBE75E85F078D73A8636F2227600
SHA256:AABA625D6B32805F2B8359B074D61E9F1B1493D06BD7B94FCB80F86BCEE45111
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7976
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7976
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7800
NetTime.exe
GET
200
103.230.156.198:80
http://www.timesynctool.com/updatecheck?3.2.0.233
unknown
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7672
NetTimeService.exe
185.13.148.71:123
0.nettime.pool.ntp.org
whitelisted
7800
NetTime.exe
103.230.156.198:80
www.timesynctool.com
Mammoth Media Pty Ltd
AU
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.16.253.202
whitelisted
google.com
  • 172.217.23.110
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.4
  • 20.190.160.64
  • 20.190.160.65
  • 20.190.160.17
  • 20.190.160.128
  • 40.126.32.133
  • 20.190.160.20
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
0.nettime.pool.ntp.org
  • 185.13.148.71
  • 148.251.5.46
  • 78.46.53.2
  • 94.130.184.193
whitelisted
www.timesynctool.com
  • 103.230.156.198
malicious
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

PID
Process
Class
Message
7800
NetTime.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Mozilla/3.0 (compatible))
No debug info