File name:

Natro_Macro_v0.9.6.zip

Full analysis: https://app.any.run/tasks/8dae59bb-d4d0-456d-89f4-6f0b3f613d56
Verdict: Malicious activity
Analysis date: February 03, 2024, 03:09:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

EC32ADBE4B134BFCEE504849AFE0C339

SHA1:

4345C4CC0F8F2C08DE1A5DF0898209ABC9DBC4B6

SHA256:

39E7951689C112474A0EB14C62C2A36844AE8B607DFF508ABAE11A7E7B8F70C5

SSDEEP:

98304:tf5Uf+YrR27T7z6CurH2sixGCsZgWyXuiPHlJXJ98OlHntzZ9eQJFub6o9MVZfFa:HLFuWtS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
  • SUSPICIOUS

    • Application launched itself

      • NATRO_MACRO.exe (PID: 3264)
      • NATRO_MACRO.exe (PID: 2028)
      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 2736)
      • NATRO_MACRO.exe (PID: 2628)
      • NATRO_MACRO.exe (PID: 2032)
      • NATRO_MACRO.exe (PID: 2868)
      • NATRO_MACRO.exe (PID: 2528)
      • NATRO_MACRO.exe (PID: 3156)
      • NATRO_MACRO.exe (PID: 2496)
      • NATRO_MACRO.exe (PID: 908)
      • NATRO_MACRO.exe (PID: 3048)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 3600)
      • NATRO_MACRO.exe (PID: 3748)
      • NATRO_MACRO.exe (PID: 3576)
      • NATRO_MACRO.exe (PID: 3756)
      • NATRO_MACRO.exe (PID: 3788)
      • NATRO_MACRO.exe (PID: 3612)
      • NATRO_MACRO.exe (PID: 3968)
      • NATRO_MACRO.exe (PID: 1812)
      • NATRO_MACRO.exe (PID: 3860)
      • NATRO_MACRO.exe (PID: 3836)
      • NATRO_MACRO.exe (PID: 4056)
    • Reads the Internet Settings

      • NATRO_MACRO.exe (PID: 3432)
    • Reads settings of System Certificates

      • NATRO_MACRO.exe (PID: 3432)
  • INFO

    • Checks supported languages

      • NATRO_MACRO.exe (PID: 1604)
      • NATRO_MACRO.exe (PID: 548)
      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 2736)
      • NATRO_MACRO.exe (PID: 3332)
      • NATRO_MACRO.exe (PID: 1428)
      • NATRO_MACRO.exe (PID: 3484)
      • NATRO_MACRO.exe (PID: 2028)
      • NATRO_MACRO.exe (PID: 1344)
      • NATRO_MACRO.exe (PID: 2628)
      • NATRO_MACRO.exe (PID: 392)
      • NATRO_MACRO.exe (PID: 2032)
      • NATRO_MACRO.exe (PID: 3768)
      • NATRO_MACRO.exe (PID: 2868)
      • NATRO_MACRO.exe (PID: 3264)
      • NATRO_MACRO.exe (PID: 3052)
      • NATRO_MACRO.exe (PID: 2776)
      • NATRO_MACRO.exe (PID: 3156)
      • NATRO_MACRO.exe (PID: 3040)
      • NATRO_MACRO.exe (PID: 2496)
      • NATRO_MACRO.exe (PID: 3580)
      • NATRO_MACRO.exe (PID: 908)
      • NATRO_MACRO.exe (PID: 3524)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 3600)
      • NATRO_MACRO.exe (PID: 2528)
      • NATRO_MACRO.exe (PID: 3048)
      • NATRO_MACRO.exe (PID: 3000)
      • NATRO_MACRO.exe (PID: 3588)
      • NATRO_MACRO.exe (PID: 3576)
      • NATRO_MACRO.exe (PID: 3548)
      • NATRO_MACRO.exe (PID: 3748)
      • NATRO_MACRO.exe (PID: 3612)
      • NATRO_MACRO.exe (PID: 2612)
      • NATRO_MACRO.exe (PID: 3788)
      • NATRO_MACRO.exe (PID: 3632)
      • NATRO_MACRO.exe (PID: 3756)
      • NATRO_MACRO.exe (PID: 3728)
      • NATRO_MACRO.exe (PID: 3596)
      • NATRO_MACRO.exe (PID: 3840)
      • NATRO_MACRO.exe (PID: 3688)
      • NATRO_MACRO.exe (PID: 3968)
      • NATRO_MACRO.exe (PID: 4056)
      • NATRO_MACRO.exe (PID: 2948)
      • NATRO_MACRO.exe (PID: 3924)
      • NATRO_MACRO.exe (PID: 3860)
      • NATRO_MACRO.exe (PID: 1812)
      • NATRO_MACRO.exe (PID: 4040)
      • NATRO_MACRO.exe (PID: 3928)
      • NATRO_MACRO.exe (PID: 3836)
      • NATRO_MACRO.exe (PID: 2912)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Create files in a temporary directory

      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 2912)
    • Reads the machine GUID from the registry

      • NATRO_MACRO.exe (PID: 3432)
    • Reads the computer name

      • NATRO_MACRO.exe (PID: 3432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:09:29 20:08:30
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Natro Macro v0.9.6/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
52
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Natro_Macro_v0.9.6.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
392"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
548"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /f *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
908"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1344"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1428"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1588"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeWinRAR.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1604"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1812"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2028"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
4 666
Read events
4 621
Write events
45
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
31
Suspicious files
5
Text files
421
Unknown types
0

Dropped files

PID
Process
Filename
Type
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\lib\Gdip_All.ahktext
MD5:A800E27D8C3B148E3120DDE65733AD75
SHA256:07E642B22A34F57B8B8414013B794298A0A679B7838A79E50F11960DFCD23182
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\lib\HyperSleep.ahktext
MD5:7F119F281F4D0915ECAE0DD4B92DF746
SHA256:2D6776C4AF23D10C14A8CDE2D02260C2B05B6C366221C5724DB65116A37611E6
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\aromatic pie.pngimage
MD5:387F5BEFF1D2130447A882A07FBCA063
SHA256:BB9562EFF9F7C9C2F17F8D140C85F00550BCE6AE9532A14009B1B4262ED7C4EE
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\abilities.pngimage
MD5:0027C79985BFAE14612C922F63FFCCE0
SHA256:BA536A4E376269C9055F571363C0370C3EAA5D3B2FA0BDAD18FD761A1E93CC65
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\ant_pass.pngimage
MD5:956E6682526321F2FD1463E5DEC9E4DF
SHA256:295B1EF0B3684EAE68333D71719271B14F5E11D48B54A1F9F232BC18D4FFE8B5
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\any pollen.pngimage
MD5:708DF32D7EB8AC41A80C09E7113797A5
SHA256:7D84D787A6BA6EB380446FB161579391A4E41017DE59937B7E0D3B3A2F57E425
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\lib\Walk.ahktext
MD5:D58793FE1CFE0A8FD88BF88108219EA9
SHA256:A20ED69B7F051F17C3B368AF1AF9916B8AEDB950AF4809763336BF08FF45F52C
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\bamboo.pngimage
MD5:D6CFA28B03548D03D858B6F342214C0B
SHA256:2C30D62FC8F1C762E3302574A788BD60DCA0DB4B7B2555A9400FF3024F49DBF0
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\beemenu\beedigit1.pngimage
MD5:5D6B2B098B0C67C6445A653815E2697A
SHA256:9FE28EFAAD59AD7779EC77EE6EF93F71837BE56F36A5D48F1B2FA399D963CF90
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\beemenu\beedigit2.pngimage
MD5:0C1E17BAD65B6ED3ED3D718585EF3274
SHA256:90439AF32B4EFA3EFFFD8C7610D56E72353D36D770AE2CB8B8C7A103AC1F51C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3432
NATRO_MACRO.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
3432
NATRO_MACRO.exe
185.199.108.133:443
raw.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared

Threats

No threats detected
No debug info