File name:

2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe

Full analysis: https://app.any.run/tasks/7e4af371-b98f-4e5a-9f1e-b37dc1d9d639
Verdict: Malicious activity
Analysis date: December 13, 2023, 14:21:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A5D3E711767FC6EB92E33B6A01C2E376

SHA1:

F2DB52B3DFC1E6F978C369CDC74926930FA94FD7

SHA256:

340EFDE1F8A60F8B7F6F7E146B860CFFFFA5DC791183023387EA921BC9BD7B4F

SSDEEP:

49152:gy7GRR+GPmldU6zBOqlf40XkUJqfKHFAXF7HDC1aBPYU8ahRizeLJj/9goo/pjtp:gyi3GdU6EKNQJHD4bU/hRYOjo/t+a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Reads the Internet Settings

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • rundll32.exe (PID: 284)
    • Reads Internet Explorer settings

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
  • INFO

    • Reads the computer name

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • wmpnscfg.exe (PID: 1840)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Checks proxy server information

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Checks supported languages

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • wmpnscfg.exe (PID: 1840)
    • Reads the machine GUID from the registry

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
    • Creates files or folders in the user directory

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
    • Manual execution by a user

      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3252)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 4000)
      • explorer.exe (PID: 2316)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3604)
      • 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe (PID: 3536)
      • rundll32.exe (PID: 284)
      • wmpnscfg.exe (PID: 1840)
    • Application launched itself

      • msedge.exe (PID: 968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:03 14:15:57+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.3
CodeSize: 203776
InitializedDataSize: 163328
UninitializedDataSize: -
EntryPoint: 0x1f530
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
28
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe explorer.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs 2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\MoistScript_NextGen.luacC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
300"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4100 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
604"C:\Users\admin\AppData\Local\Temp\2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe" C:\Users\admin\AppData\Local\Temp\2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\2take1-moist-script-ng_ez.installer.3.0.3.3.fix.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
684"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3408 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
916"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3552 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=luacC:\Program Files\Microsoft\Edge\Application\msedge.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1820"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1888"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x681ef598,0x681ef5a8,0x681ef5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2068"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1232 --field-trial-handle=1336,i,6760150981171041340,13579212361053040270,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 680
Read events
3 626
Write events
54
Delete events
0

Modification events

(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(604) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4000) 2Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
6
Suspicious files
143
Text files
74
Unknown types
0

Dropped files

PID
Process
Filename
Type
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Join Keks Menu Discord for Updates.urlbinary
MD5:A7A950D77BB624C2B9C10518AFA23B05
SHA256:AED94C24E326AAF58C79249187FE3F6B6AEC699388FA1ED74B578A3F0A27C3E3
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\README.mdtext
MD5:0D57D2BD24479FF72631A9B50B0993E3
SHA256:8541C6ABB86C066598AB8DF1793696D1C8C8FB7981237A75BC5A75AD5CE20D01
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\hud_target.pngimage
MD5:9AE9DD9E4F41329313A183114B675234
SHA256:EC7CE6FE2CDB3F2EC42653F72ADBDC7A392EC973118101B5E7AFBDE7F8A8D8A4
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\MoistScript_ESP_Module.luabinary
MD5:C0B6C59E7DB31D7B85AA162F7230B4A8
SHA256:514AE7D858912DFE3E6966ECDB593E9A3B25C3377EF7F28947293B305370AD49
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\MoistScript_Blacklist_Module.luabinary
MD5:1D1142EC1B4ACB79317ACB8558E8507E
SHA256:39851D19A552AF97216C08DF0E1D2D87C5B3C57D36E8A47C0624DEA90BB1FF7C
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\json.luatext
MD5:DE4359B70C4BEC50ECC71426085C72E7
SHA256:0EACCDA57FABC0330736DE25F45CF589821A42B5E0FE02E4E3125F7DC0BF2B7E
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\MoistScript_MoistBasics_Module.luabinary
MD5:1F98DD0282EF636AF3ED04544B1895BF
SHA256:A2036CC8BFF10014E39CB33D2A8279BF5431ED9E95D8D057D0CC20ABF509E63D
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\Docs\Home · IN2-Moist2Take1-Moist-Script Wiki.mdtext
MD5:329864DEFF8DA1EAD882AE306D313F4D
SHA256:DFE0E39BA076F180148C556E0B8F6E76139879B158C707D50E7E87C444E22F30
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\kick_args.initext
MD5:B489F244E8BC1D11F60C3F445A196757
SHA256:A7161D5F3F3FFEC1130EB1C1040F5BDA723D376A332E128494CEAB7CA8847748
6042Take1-Moist-Script-NG_Ez.Installer.3.0.3.3.fix.exeC:\Users\admin\AppData\Roaming\PopstarDevs\2Take1Menu\scripts\MoistFiles\MoistScript_GTA_Natives.luabinary
MD5:796D7C2F8FF5B2EAC6A9ECFC2F8DA12A
SHA256:DE8102CF085D4F835B28688EF5047AF096F12B0880C54664418122AB6A645113
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
20
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1820
msedge.exe
GET
302
23.213.166.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=luac
unknown
unknown
1820
msedge.exe
GET
301
2.21.20.153:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=luac
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
968
msedge.exe
239.255.255.250:1900
whitelisted
1820
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1820
msedge.exe
23.213.166.81:80
go.microsoft.com
AKAMAI-AS
DE
unknown
1820
msedge.exe
20.31.251.109:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1820
msedge.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
unknown
1820
msedge.exe
104.126.37.131:443
www.bing.com
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.31.251.109
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
shell.windows.com
  • 2.21.20.153
  • 2.21.20.150
whitelisted
www.bing.com
  • 104.126.37.128
  • 104.126.37.123
  • 104.126.37.177
  • 104.126.37.171
  • 104.126.37.161
  • 104.126.37.178
  • 104.126.37.130
  • 104.126.37.137
  • 104.126.37.131
whitelisted
r.bing.com
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.123
  • 104.126.37.128
  • 104.126.37.155
  • 104.126.37.131
  • 104.126.37.177
  • 104.126.37.153
  • 104.126.37.171
whitelisted
th.bing.com
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.131
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.123
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.155
  • 104.126.37.153
whitelisted
www.youtube.com
  • 142.250.185.142
  • 142.250.185.174
  • 142.250.185.206
  • 142.250.185.238
  • 142.250.186.78
  • 142.250.186.110
  • 142.250.181.238
  • 172.217.16.142
  • 142.250.184.206
  • 142.250.184.238
  • 142.250.186.142
  • 142.250.74.206
  • 142.250.186.46
  • 172.217.18.14
  • 172.217.16.206
  • 142.250.186.174
whitelisted

Threats

No threats detected
No debug info