File name:

Natro_Macro_v0.9.6.zip

Full analysis: https://app.any.run/tasks/8dae59bb-d4d0-456d-89f4-6f0b3f613d56
Verdict: Malicious activity
Analysis date: February 03, 2024, 03:09:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

EC32ADBE4B134BFCEE504849AFE0C339

SHA1:

4345C4CC0F8F2C08DE1A5DF0898209ABC9DBC4B6

SHA256:

39E7951689C112474A0EB14C62C2A36844AE8B607DFF508ABAE11A7E7B8F70C5

SSDEEP:

98304:tf5Uf+YrR27T7z6CurH2sixGCsZgWyXuiPHlJXJ98OlHntzZ9eQJFub6o9MVZfFa:HLFuWtS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
  • SUSPICIOUS

    • Application launched itself

      • NATRO_MACRO.exe (PID: 2736)
      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 2028)
      • NATRO_MACRO.exe (PID: 2628)
      • NATRO_MACRO.exe (PID: 2032)
      • NATRO_MACRO.exe (PID: 2868)
      • NATRO_MACRO.exe (PID: 3264)
      • NATRO_MACRO.exe (PID: 2528)
      • NATRO_MACRO.exe (PID: 3156)
      • NATRO_MACRO.exe (PID: 2496)
      • NATRO_MACRO.exe (PID: 3048)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 3600)
      • NATRO_MACRO.exe (PID: 3576)
      • NATRO_MACRO.exe (PID: 3748)
      • NATRO_MACRO.exe (PID: 908)
      • NATRO_MACRO.exe (PID: 3756)
      • NATRO_MACRO.exe (PID: 3788)
      • NATRO_MACRO.exe (PID: 3836)
      • NATRO_MACRO.exe (PID: 3968)
      • NATRO_MACRO.exe (PID: 4056)
      • NATRO_MACRO.exe (PID: 3612)
      • NATRO_MACRO.exe (PID: 1812)
      • NATRO_MACRO.exe (PID: 3860)
    • Reads the Internet Settings

      • NATRO_MACRO.exe (PID: 3432)
    • Reads settings of System Certificates

      • NATRO_MACRO.exe (PID: 3432)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Checks supported languages

      • NATRO_MACRO.exe (PID: 1604)
      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 548)
      • NATRO_MACRO.exe (PID: 2736)
      • NATRO_MACRO.exe (PID: 3484)
      • NATRO_MACRO.exe (PID: 2028)
      • NATRO_MACRO.exe (PID: 1344)
      • NATRO_MACRO.exe (PID: 2628)
      • NATRO_MACRO.exe (PID: 392)
      • NATRO_MACRO.exe (PID: 2032)
      • NATRO_MACRO.exe (PID: 3768)
      • NATRO_MACRO.exe (PID: 2868)
      • NATRO_MACRO.exe (PID: 1428)
      • NATRO_MACRO.exe (PID: 3264)
      • NATRO_MACRO.exe (PID: 2528)
      • NATRO_MACRO.exe (PID: 2776)
      • NATRO_MACRO.exe (PID: 3156)
      • NATRO_MACRO.exe (PID: 3040)
      • NATRO_MACRO.exe (PID: 2496)
      • NATRO_MACRO.exe (PID: 3052)
      • NATRO_MACRO.exe (PID: 3000)
      • NATRO_MACRO.exe (PID: 3048)
      • NATRO_MACRO.exe (PID: 3332)
      • NATRO_MACRO.exe (PID: 3580)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 3588)
      • NATRO_MACRO.exe (PID: 3600)
      • NATRO_MACRO.exe (PID: 3596)
      • NATRO_MACRO.exe (PID: 3576)
      • NATRO_MACRO.exe (PID: 3548)
      • NATRO_MACRO.exe (PID: 3748)
      • NATRO_MACRO.exe (PID: 2612)
      • NATRO_MACRO.exe (PID: 3524)
      • NATRO_MACRO.exe (PID: 908)
      • NATRO_MACRO.exe (PID: 3612)
      • NATRO_MACRO.exe (PID: 3688)
      • NATRO_MACRO.exe (PID: 3756)
      • NATRO_MACRO.exe (PID: 3728)
      • NATRO_MACRO.exe (PID: 3836)
      • NATRO_MACRO.exe (PID: 3788)
      • NATRO_MACRO.exe (PID: 3928)
      • NATRO_MACRO.exe (PID: 3840)
      • NATRO_MACRO.exe (PID: 2948)
      • NATRO_MACRO.exe (PID: 4056)
      • NATRO_MACRO.exe (PID: 3860)
      • NATRO_MACRO.exe (PID: 3632)
      • NATRO_MACRO.exe (PID: 3968)
      • NATRO_MACRO.exe (PID: 3924)
      • NATRO_MACRO.exe (PID: 1812)
      • NATRO_MACRO.exe (PID: 4040)
      • NATRO_MACRO.exe (PID: 2912)
    • Create files in a temporary directory

      • NATRO_MACRO.exe (PID: 1588)
      • NATRO_MACRO.exe (PID: 3432)
      • NATRO_MACRO.exe (PID: 2912)
    • Reads the computer name

      • NATRO_MACRO.exe (PID: 3432)
    • Reads the machine GUID from the registry

      • NATRO_MACRO.exe (PID: 3432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:09:29 20:08:30
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Natro Macro v0.9.6/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
52
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs natro_macro.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Natro_Macro_v0.9.6.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
392"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
548"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /f *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
908"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1344"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1428"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1588"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeWinRAR.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1604"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1812"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2028"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exe" /script /ErrorStdOut *C:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\NATRO_MACRO.exeNATRO_MACRO.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.29243\natro macro v0.9.6\natro_macro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
4 666
Read events
4 621
Write events
45
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
31
Suspicious files
5
Text files
421
Unknown types
0

Dropped files

PID
Process
Filename
Type
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\bamboo.pngimage
MD5:D6CFA28B03548D03D858B6F342214C0B
SHA256:2C30D62FC8F1C762E3302574A788BD60DCA0DB4B7B2555A9400FF3024F49DBF0
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\a bit of both.pngimage
MD5:6839A3D9FB3A3B664A778DD6639DCC5E
SHA256:76F39CB1023EC4F6D52A898EEB277C288F892A03BFB6B67284F5548FFA57CC95
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\lib\HyperSleep.ahktext
MD5:7F119F281F4D0915ECAE0DD4B92DF746
SHA256:2D6776C4AF23D10C14A8CDE2D02260C2B05B6C366221C5724DB65116A37611E6
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\3Planters.PNGimage
MD5:EF32FE4CC267AC9247834A8020A2174D
SHA256:0BE56F50839FD430A175C0F9CE91ED336DEF38021E6F21B6A1EFDAF4871FD501
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\natro_macro.ahktext
MD5:A57CBFA6F4CCA96C72289E4F41A4CC45
SHA256:EC275C7D66B1B661769CD81FD18CB3BB3EC2589A751740522F122D68269CA06B
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\any pollen.pngimage
MD5:708DF32D7EB8AC41A80C09E7113797A5
SHA256:7D84D787A6BA6EB380446FB161579391A4E41017DE59937B7E0D3B3A2F57E425
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\abilities.pngimage
MD5:0027C79985BFAE14612C922F63FFCCE0
SHA256:BA536A4E376269C9055F571363C0370C3EAA5D3B2FA0BDAD18FD761A1E93CC65
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\beemenu\beedigit4.pngimage
MD5:949243C56BF871FD1A30BB446E03F423
SHA256:46D145C99867D7DB7E6525D8D34A99BF300C3A8DD23BF3E68F80A3243E66BAC9
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\aromatic pie.pngimage
MD5:387F5BEFF1D2130447A882A07FBCA063
SHA256:BB9562EFF9F7C9C2F17F8D140C85F00550BCE6AE9532A14009B1B4262ED7C4EE
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.29243\Natro Macro v0.9.6\nm_image_assets\beemenu\beedigit1.pngimage
MD5:5D6B2B098B0C67C6445A653815E2697A
SHA256:9FE28EFAAD59AD7779EC77EE6EF93F71837BE56F36A5D48F1B2FA399D963CF90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3432
NATRO_MACRO.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
3432
NATRO_MACRO.exe
185.199.108.133:443
raw.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared

Threats

No threats detected
No debug info