File name:

ambibox_setup_2.1.7.zip

Full analysis: https://app.any.run/tasks/d5013b0a-ec06-49bd-81d9-8dfc9d227e9c
Verdict: Malicious activity
Analysis date: January 17, 2024, 15:47:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F178E3D40AD50650DD82D5C9BE277E33

SHA1:

AE529E437E79F1B26BF2C46B8A695FDB93F82792

SHA256:

2961F7B91E1C422633EAD7E531435052DB289A4A3FD6E9010065562631750635

SSDEEP:

98304:KVFTHt7I9TrKaBIyXXOImsSfh0bEGGl6t6jNNDXsghP7xBrj6QPCX1U6OJJjOi4u:ia7AsYjegKxVVFsLWrO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1776)
      • AmbiBox_setup_2.1.7.exe (PID: 296)
      • AmbiBox_setup_2.1.7.exe (PID: 2448)
      • AmbiBox_setup_2.1.7.exe (PID: 2668)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.exe (PID: 1344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AmbiBox_setup_2.1.7.exe (PID: 1344)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.exe (PID: 2448)
      • AmbiBox_setup_2.1.7.exe (PID: 2668)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
      • AmbiBox_setup_2.1.7.exe (PID: 296)
    • Reads the Windows owner or organization settings

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Reads the Internet Settings

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Reads settings of System Certificates

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Checks Windows Trust Settings

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Reads security settings of Internet Explorer

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Adds/modifies Windows certificates

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
    • Process requests binary or script from the Internet

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Process drops legitimate windows executable

      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1776)
    • Checks supported languages

      • AmbiBox_setup_2.1.7.exe (PID: 296)
      • AmbiBox_setup_2.1.7.exe (PID: 1344)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.exe (PID: 2448)
      • AmbiBox_setup_2.1.7.tmp (PID: 2296)
      • AmbiBox_setup_2.1.7.exe (PID: 2668)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
      • AmbiBox_setup_2.1.7.tmp (PID: 2032)
    • Create files in a temporary directory

      • AmbiBox_setup_2.1.7.exe (PID: 296)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.exe (PID: 2448)
      • AmbiBox_setup_2.1.7.exe (PID: 2668)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
      • AmbiBox_setup_2.1.7.exe (PID: 1344)
    • Reads the computer name

      • AmbiBox_setup_2.1.7.tmp (PID: 2032)
      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 2296)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Checks proxy server information

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Reads the machine GUID from the registry

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
      • AmbiBox_setup_2.1.7.tmp (PID: 1880)
    • Creates files or folders in the user directory

      • AmbiBox_setup_2.1.7.tmp (PID: 1652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2015:02:19 10:09:26
ZipCRC: 0xf61409e9
ZipCompressedSize: 9927446
ZipUncompressedSize: 10256517
ZipFileName: AmbiBox_setup_2.1.7.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe ambibox_setup_2.1.7.exe ambibox_setup_2.1.7.tmp no specs ambibox_setup_2.1.7.exe ambibox_setup_2.1.7.tmp ambibox_setup_2.1.7.exe ambibox_setup_2.1.7.tmp no specs ambibox_setup_2.1.7.exe ambibox_setup_2.1.7.tmp

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe
WinRAR.exe
User:
admin
Company:
AmbiBox
Integrity Level:
MEDIUM
Description:
AmbiBox Setup
Exit code:
2
Version:
2.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1776.44671\ambibox_setup_2.1.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1344"C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe" /SPAWNWND=$30170 /NOTIFYWND=$5018E C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe
AmbiBox_setup_2.1.7.tmp
User:
admin
Company:
AmbiBox
Integrity Level:
HIGH
Description:
AmbiBox Setup
Exit code:
2
Version:
2.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1776.44671\ambibox_setup_2.1.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1652"C:\Users\admin\AppData\Local\Temp\is-OTQJM.tmp\AmbiBox_setup_2.1.7.tmp" /SL5="$40172,9675943,467456,C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe" /SPAWNWND=$30170 /NOTIFYWND=$5018E C:\Users\admin\AppData\Local\Temp\is-OTQJM.tmp\AmbiBox_setup_2.1.7.tmp
AmbiBox_setup_2.1.7.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-otqjm.tmp\ambibox_setup_2.1.7.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1776"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ambibox_setup_2.1.7.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1880"C:\Users\admin\AppData\Local\Temp\is-C4622.tmp\AmbiBox_setup_2.1.7.tmp" /SL5="$70182,9675943,467456,C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe" /SPAWNWND=$60184 /NOTIFYWND=$7018E C:\Users\admin\AppData\Local\Temp\is-C4622.tmp\AmbiBox_setup_2.1.7.tmp
AmbiBox_setup_2.1.7.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-c4622.tmp\ambibox_setup_2.1.7.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2032"C:\Users\admin\AppData\Local\Temp\is-3SGKU.tmp\AmbiBox_setup_2.1.7.tmp" /SL5="$5018E,9675943,467456,C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exe" C:\Users\admin\AppData\Local\Temp\is-3SGKU.tmp\AmbiBox_setup_2.1.7.tmpAmbiBox_setup_2.1.7.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3sgku.tmp\ambibox_setup_2.1.7.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2296"C:\Users\admin\AppData\Local\Temp\is-KDHCO.tmp\AmbiBox_setup_2.1.7.tmp" /SL5="$7018E,9675943,467456,C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe" C:\Users\admin\AppData\Local\Temp\is-KDHCO.tmp\AmbiBox_setup_2.1.7.tmpAmbiBox_setup_2.1.7.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kdhco.tmp\ambibox_setup_2.1.7.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2448"C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe
WinRAR.exe
User:
admin
Company:
AmbiBox
Integrity Level:
MEDIUM
Description:
AmbiBox Setup
Exit code:
2
Version:
2.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1776.748\ambibox_setup_2.1.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2668"C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe" /SPAWNWND=$60184 /NOTIFYWND=$7018E C:\Users\admin\AppData\Local\Temp\Rar$EXa1776.748\AmbiBox_setup_2.1.7.exe
AmbiBox_setup_2.1.7.tmp
User:
admin
Company:
AmbiBox
Integrity Level:
HIGH
Description:
AmbiBox Setup
Exit code:
2
Version:
2.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1776.748\ambibox_setup_2.1.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 512
Read events
11 403
Write events
97
Delete events
12

Modification events

(PID) Process:(1776) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1776) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
10
Suspicious files
8
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1344AmbiBox_setup_2.1.7.exeC:\Users\admin\AppData\Local\Temp\is-OTQJM.tmp\AmbiBox_setup_2.1.7.tmpexecutable
MD5:671676D83AF57B61E0342979C3B03A6A
SHA256:ACE062C97B30A9EE62C7A40994DCDEE0998252526AA21C367250255E20EE808F
1776WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1776.44671\AmbiBox_setup_2.1.7.exeexecutable
MD5:A36A9B905D32E458EE57CF7B03EF8071
SHA256:C521FFC7AD434FE3582E0AF3930BD0265AB7BCFB951246135AA6809298A35A03
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\Local\Temp\is-TMQ64.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:D2298227380C79853A47F0C8406C1076
SHA256:A8CE3852C49AA7515AA8D3999790851AF5A6C8759A878AC139087E553A32DEDC
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\Local\Temp\is-TMQ64.tmp\idp.dllexecutable
MD5:6CDE0DAE7FB1B6CFF8D936CAFBCD2C56
SHA256:D4F638C3DB5BFD138CD71B829D379851F37C15B88757C6BF99B2C1662C507731
2448AmbiBox_setup_2.1.7.exeC:\Users\admin\AppData\Local\Temp\is-KDHCO.tmp\AmbiBox_setup_2.1.7.tmpexecutable
MD5:671676D83AF57B61E0342979C3B03A6A
SHA256:ACE062C97B30A9EE62C7A40994DCDEE0998252526AA21C367250255E20EE808F
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\Local\Temp\Cab773F.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1652AmbiBox_setup_2.1.7.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
11
DNS requests
3
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1652
AmbiBox_setup_2.1.7.tmp
HEAD
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
unknown
1652
AmbiBox_setup_2.1.7.tmp
GET
200
184.24.77.187:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?15609a8d39a25569
unknown
compressed
4.66 Kb
unknown
GET
200
184.24.77.187:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e62fdf5a3d383eaa
unknown
compressed
65.2 Kb
unknown
1652
AmbiBox_setup_2.1.7.tmp
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1652
AmbiBox_setup_2.1.7.tmp
GET
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
html
162 b
unknown
1652
AmbiBox_setup_2.1.7.tmp
HEAD
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
html
162 b
unknown
1652
AmbiBox_setup_2.1.7.tmp
GET
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
html
162 b
unknown
1880
AmbiBox_setup_2.1.7.tmp
HEAD
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
unknown
1880
AmbiBox_setup_2.1.7.tmp
GET
301
5.187.4.139:80
http://www.playclaw.com/bin/playclaw5.3105.exe
unknown
html
162 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1652
AmbiBox_setup_2.1.7.tmp
5.187.4.139:80
www.playclaw.com
diva-e Datacenters GmbH
DE
unknown
1652
AmbiBox_setup_2.1.7.tmp
5.187.4.139:443
www.playclaw.com
diva-e Datacenters GmbH
DE
unknown
1652
AmbiBox_setup_2.1.7.tmp
184.24.77.187:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1652
AmbiBox_setup_2.1.7.tmp
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
1880
AmbiBox_setup_2.1.7.tmp
5.187.4.139:80
www.playclaw.com
diva-e Datacenters GmbH
DE
unknown
1880
AmbiBox_setup_2.1.7.tmp
5.187.4.139:443
www.playclaw.com
diva-e Datacenters GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
www.playclaw.com
  • 5.187.4.139
unknown
ctldl.windowsupdate.com
  • 184.24.77.187
  • 184.24.77.202
  • 184.24.77.201
  • 184.24.77.194
  • 184.24.77.209
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted

Threats

Found threats are available for the paid subscriptions
6 ETPRO signatures available at the full report
No debug info