File name:

2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe

Full analysis: https://app.any.run/tasks/7e4af371-b98f-4e5a-9f1e-b37dc1d9d639
Verdict: Malicious activity
Analysis date: December 13, 2023, 14:21:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A5D3E711767FC6EB92E33B6A01C2E376

SHA1:

F2DB52B3DFC1E6F978C369CDC74926930FA94FD7

SHA256:

340EFDE1F8A60F8B7F6F7E146B860CFFFFA5DC791183023387EA921BC9BD7B4F

SSDEEP:

49152:gy7GRR+GPmldU6zBOqlf40XkUJqfKHFAXF7HDC1aBPYU8ahRizeLJj/9goo/pjtp:gyi3GdU6EKNQJHD4bU/hRYOjo/t+a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • rundll32.exe (PID: 284)
    • Reads Microsoft Outlook installation path

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Reads Internet Explorer settings

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
  • INFO

    • Checks proxy server information

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Checks supported languages

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • wmpnscfg.exe (PID: 1840)
    • Reads the computer name

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • wmpnscfg.exe (PID: 1840)
    • Manual execution by a user

      • explorer.exe (PID: 2316)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3252)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • rundll32.exe (PID: 284)
      • wmpnscfg.exe (PID: 1840)
    • Creates files or folders in the user directory

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
    • Reads the machine GUID from the registry

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Application launched itself

      • msedge.exe (PID: 968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:03 14:15:57+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.3
CodeSize: 203776
InitializedDataSize: 163328
UninitializedDataSize: -
EntryPoint: 0x1f530
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
28
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe explorer.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\MoistScript_NextGen.luacC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
300"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4100 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
604"C:\Users\admin\AppData\Local\Temp\2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe" C:\Users\admin\AppData\Local\Temp\2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
684"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3408 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
916"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3552 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=luacC:\Program Files\Microsoft\Edge\Application\msedge.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1820"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1888"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x681ef598,0x681ef5a8,0x681ef5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2068"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1232 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 680
Read events
3 626
Write events
54
Delete events
0

Modification events

(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
6
Suspicious files
143
Text files
74
Unknown types
0

Dropped files

PID
Process
Filename
Type
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\Home · IN2-Moist2Take1-Moist-Script Wiki.mdtext
MD5:329864DEFF8DA1EAD882AE306D313F4D
SHA256:DFE0E39BA076F180148C556E0B8F6E76139879B158C707D50E7E87C444E22F30
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\Script Features (Online) · IN2-Moist2Take1-Moist-Script Wiki.mdtext
MD5:DC4F7D747E82B183F489425319BC1CEC
SHA256:EC0C7F72368A03D3D131952B54FFBB4C14C0A1A106160EA9D9D9B2131B221E3C
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\README.mdtext
MD5:0D57D2BD24479FF72631A9B50B0993E3
SHA256:8541C6ABB86C066598AB8DF1793696D1C8C8FB7981237A75BC5A75AD5CE20D01
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\FeaturesMarkDown.mdtext
MD5:E1E970B7463F82D04CD06892AC6FDCD4
SHA256:5F0039DE89A08732C1C970ADD536539A4A07BE626E37B9D920AD866720007A2D
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\Installation & Setup · IN2-Moist2Take1-Moist-Script Wiki.mdtext
MD5:2C4FBC18D5B670C59A4FFA022FA39866
SHA256:0B2E5013E25158C1A08DC76386EFEEBBB0BA5A4B91B756E4EC44F09A2CA2ECCC
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Join Keks Menu Discord for Updates.urlbinary
MD5:A7A950D77BB624C2B9C10518AFA23B05
SHA256:AED94C24E326AAF58C79249187FE3F6B6AEC699388FA1ED74B578A3F0A27C3E3
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Join Gee-Skid Server for Moistscript Updates Chat and Support.urlurl
MD5:81B3E794451B70E7C3C1F4CDCCDB17C9
SHA256:82C3ED6391C6620C5F68EF72BD0C1FDF39C5C05D17EEA84EF1D66AA274105AF8
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\Script Features (ScreenShots)· IN2-Moist2Take1-Moist-Script Wiki.mdtext
MD5:7C6A70EA6476515D442B6063427A89A5
SHA256:FCE6A707C60B59960B50194122DE214AA6414516BE2FBE98D617AFC5BBAA33F0
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\ChatSpam.initext
MD5:0A79C024700E715A3E024015FA38090F
SHA256:0C55D864CC70BCFC5A82D85C5C78E7BAC3AB10F6CF745255702F0949D127FF02
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\MoistScript_Blacklist_Module.luabinary
MD5:1D1142EC1B4ACB79317ACB8558E8507E
SHA256:39851D19A552AF97216C08DF0E1D2D87C5B3C57D36E8A47C0624DEA90BB1FF7C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
20
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1820
msedge.exe
GET
302
23.213.166.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=luac
unknown
unknown
1820
msedge.exe
GET
301
2.21.20.153:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=luac
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
968
msedge.exe
239.255.255.250:1900
whitelisted
1820
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1820
msedge.exe
23.213.166.81:80
go.microsoft.com
AKAMAI-AS
DE
unknown
1820
msedge.exe
20.31.251.109:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1820
msedge.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
unknown
1820
msedge.exe
104.126.37.131:443
www.bing.com
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.31.251.109
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
shell.windows.com
  • 2.21.20.153
  • 2.21.20.150
whitelisted
www.bing.com
  • 104.126.37.128
  • 104.126.37.123
  • 104.126.37.177
  • 104.126.37.171
  • 104.126.37.161
  • 104.126.37.178
  • 104.126.37.130
  • 104.126.37.137
  • 104.126.37.131
whitelisted
r.bing.com
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.123
  • 104.126.37.128
  • 104.126.37.155
  • 104.126.37.131
  • 104.126.37.177
  • 104.126.37.153
  • 104.126.37.171
whitelisted
th.bing.com
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.131
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.123
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.155
  • 104.126.37.153
whitelisted
www.youtube.com
  • 142.250.185.142
  • 142.250.185.174
  • 142.250.185.206
  • 142.250.185.238
  • 142.250.186.78
  • 142.250.186.110
  • 142.250.181.238
  • 172.217.16.142
  • 142.250.184.206
  • 142.250.184.238
  • 142.250.186.142
  • 142.250.74.206
  • 142.250.186.46
  • 172.217.18.14
  • 172.217.16.206
  • 142.250.186.174
whitelisted

Threats

No threats detected
No debug info