File name:

idm.6.42.32_with_patch.rar

Full analysis: https://app.any.run/tasks/05d6a913-f8a6-4a2a-b43e-ae2ee5fcfa58
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 18, 2025, 14:48:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
idm
tool
arch-scr
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C94317F91C856D432E7789AA82BF6414

SHA1:

538434CAB3DBCFCFDA0F7E2DCD4923D0E6A31F6D

SHA256:

4016514CD74A3580F33DE0012ABD8AE1ABDF6446A488AFC2B7A64AD2F1513448

SSDEEP:

98304:Gv9o/VhIaDiLe+CtFKHXAV/Z8Vc1Az2mYyY8jYRqLOh8jD3RXt4N/J6TKak7pxiS:EinESnAHqZJdpM1mudnho9mR3a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • Uninstall.exe (PID: 2844)
      • net.exe (PID: 3660)
    • Changes the autorun value in the registry

      • IDMan.exe (PID: 2356)
      • rundll32.exe (PID: 3080)
    • Actions looks like stealing of personal data

      • IDMan.exe (PID: 3216)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • idman642build28.exe (PID: 1416)
    • The process creates files with name similar to system file names

      • IDM1.tmp (PID: 2384)
    • Creates a software uninstall entry

      • IDM1.tmp (PID: 2384)
    • Reads security settings of Internet Explorer

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
      • WinRAR.exe (PID: 2108)
      • IDMan.exe (PID: 3216)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Reads the Internet Settings

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
      • runonce.exe (PID: 2760)
      • IDMan.exe (PID: 3216)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Creates/Modifies COM task schedule object

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
    • Reads settings of System Certificates

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Uses RUNDLL32.EXE to load library

      • Uninstall.exe (PID: 2844)
    • Executable content was dropped or overwritten

      • rundll32.exe (PID: 3080)
      • IDMan.exe (PID: 2356)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Drops a system driver (possible attempt to evade defenses)

      • rundll32.exe (PID: 3080)
    • Creates or modifies Windows services

      • Uninstall.exe (PID: 2844)
    • Application launched itself

      • WinRAR.exe (PID: 2108)
    • There is functionality for taking screenshot (YARA)

      • IEMonitor.exe (PID: 3200)
    • Starts CMD.EXE for commands execution

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Executing commands from a ".bat" file

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Drops 7-zip archiver for unpacking

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 1072)
    • The executable file from the user directory is run by the CMD process

      • t15447.exe (PID: 4068)
      • t15447.exe (PID: 2892)
      • t15447.exe (PID: 3608)
      • t15447.exe (PID: 348)
  • INFO

    • Local mutex for internet shortcut management

      • WinRAR.exe (PID: 2108)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2108)
      • IDMan.exe (PID: 2356)
      • rundll32.exe (PID: 3080)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Checks supported languages

      • idman642build28.exe (PID: 1416)
      • IDM1.tmp (PID: 2384)
      • idmBroker.exe (PID: 704)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
      • MediumILStart.exe (PID: 3696)
      • IDMan.exe (PID: 3216)
      • IEMonitor.exe (PID: 3200)
      • IDM 6.42.32 Patch.exe (PID: 1124)
      • mode.com (PID: 3084)
      • t15447.exe (PID: 4068)
      • t15447.exe (PID: 2892)
      • t15447.exe (PID: 348)
      • t15447.exe (PID: 3608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2108)
      • WinRAR.exe (PID: 3712)
    • Create files in a temporary directory

      • idman642build28.exe (PID: 1416)
      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Manual execution by a user

      • idman642build28.exe (PID: 1416)
      • idman642build28.exe (PID: 2276)
      • firefox.exe (PID: 3280)
      • IDM 6.42.32 Patch.exe (PID: 1396)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Creates files in the program directory

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
    • INTERNETDOWNLOADMANAGER mutex has been found

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IEMonitor.exe (PID: 3200)
      • IDMan.exe (PID: 3216)
    • Reads the machine GUID from the registry

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • MediumILStart.exe (PID: 3696)
      • IDMan.exe (PID: 3216)
    • Reads the computer name

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
      • IDMan.exe (PID: 3216)
      • MediumILStart.exe (PID: 3696)
      • IEMonitor.exe (PID: 3200)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Creates files or folders in the user directory

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Reads the software policy settings

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Disables trace logs

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Checks proxy server information

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Application launched itself

      • firefox.exe (PID: 3280)
      • firefox.exe (PID: 3256)
    • Creates files in the driver directory

      • rundll32.exe (PID: 3080)
    • Reads the time zone

      • runonce.exe (PID: 2760)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2760)
    • Starts MODE.COM to configure console settings

      • mode.com (PID: 3084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 3628352
UncompressedSize: 3628343
OperatingSystem: Win32
ArchivedFileName: IDM 6.42.32 Patch.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
85
Monitored processes
40
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe idman642build28.exe no specs idman642build28.exe idm1.tmp no specs idmbroker.exe no specs idman.exe firefox.exe no specs uninstall.exe no specs rundll32.exe firefox.exe no specs firefox.exe runonce.exe no specs grpconv.exe no specs net.exe no specs net1.exe no specs winrar.exe mediumilstart.exe no specs idman.exe iemonitor.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs idm 6.42.32 patch.exe no specs idm 6.42.32 patch.exe cmd.exe no specs cmd.exe no specs attrib.exe no specs mode.com no specs t15447.exe no specs t15447.exe no specs t15447.exe no specs reg.exe no specs find.exe no specs t15447.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
348C:\Users\admin\AppData\Local\Temp\wtmpd\t15447.exe i9dCxZ5SjHC:\Users\admin\AppData\Local\Temp\wtmpd\t15447.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\wtmpd\t15447.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
576"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.6.1335965278\1287632213" -childID 5 -isForBrowser -prefsHandle 1464 -prefMapHandle 3164 -prefsLen 29349 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd334935-08fd-44fc-ba07-e58374fbd64d} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3244 1a0a79b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
704"C:\Program Files\Internet Download Manager\idmBroker.exe" -RegServerC:\Program Files\Internet Download Manager\idmBroker.exeIDM1.tmp
User:
admin
Company:
Internet Download Manager, Tonec Inc.
Integrity Level:
HIGH
Description:
Broker for reading of IDM settings
Exit code:
0
Version:
6, 35, 9, 1
Modules
Images
c:\program files\internet download manager\idmbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1072C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\wtmpd\t15421.bat" "C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" "C:\Windows\System32\cmd.exeIDM 6.42.32 Patch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1124"C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\idm 6.42.32 patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1324"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.5.875245593\781427180" -childID 4 -isForBrowser -prefsHandle 1948 -prefMapHandle 1876 -prefsLen 36100 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e3b455e-5a04-47b2-b2ee-86c111f89069} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3392 192549b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1396"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.internetdownloadmanager.com/support/installffextfrommozillasite.htmlC:\Program Files\Mozilla Firefox\firefox.exeIDMan.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1396"C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" C:\Users\admin\Desktop\IDM 6.42.32 Patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\idm 6.42.32 patch.exe
c:\windows\system32\ntdll.dll
1416"C:\Users\admin\Desktop\idman642build28.exe" C:\Users\admin\Desktop\idman642build28.exe
explorer.exe
User:
admin
Company:
Tonec Inc.
Integrity Level:
HIGH
Description:
Internet Download Manager installer
Exit code:
0
Version:
6, 42, 28, 1
Modules
Images
c:\users\admin\desktop\idman642build28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.3.1310669352\447199199" -childID 2 -isForBrowser -prefsHandle 2620 -prefMapHandle 2616 -prefsLen 34441 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a7c7f101-9203-4c7d-897c-d84002a5371c} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 2632 176ba9b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
32 399
Read events
31 602
Write events
693
Delete events
104

Modification events

(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\idm.6.42.32_with_patch.rar
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
19
Suspicious files
287
Text files
43
Unknown types
0

Dropped files

PID
Process
Filename
Type
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnkbinary
MD5:FDE6B0DED58B610091D78D8FBDB14981
SHA256:744C9A6BD0006A0A98D019909FD675F514CF4047C7B9E6788E47915E4A96A67C
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnkbinary
MD5:A2AF162C1D3A1ED01CAA5994DEB5EC59
SHA256:1F1FF073BEBA8FFDEAEE162B0A60A2CEEBBC405448EB2D5BE3062052B9686BCD
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\TUTORIALS.lnkbinary
MD5:46E1A3E98D2C8E05CCB9B09CE776AE06
SHA256:BE6654766739EE67DEEAF13DE1546BB0C5236855D8B0EEF82CC3761FF7846A5E
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnkbinary
MD5:97C1922E73F4E8909CEA59E99A364CB6
SHA256:9B367CDFAE9A79550DA84092A11919EEC4A4719CB858576CB4DD2BE44361C146
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnkbinary
MD5:D571A1862875B82DB535417A832C940E
SHA256:3D9F01E4ABE4F68C012980215512FA82D5AE430AAAA9CD46D08B542ADC7EFC47
2108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2108.5606\idman642build28.exeexecutable
MD5:BD146DC9B93E39A11ED1BA7AB5429898
SHA256:F34CDED028D1F729FD872EF8BC813FAC24CC1A955A9C06D98F7A43A5A0D75D06
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnkbinary
MD5:CE399777E9023283C9B710B232E27EA6
SHA256:FFC393E5F7D7DA55335C2F72DE1C0A231CAE647FDEE6B0B7BE870726767BB74D
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnkbinary
MD5:2EE1D54606680A76A8EC838F83D68678
SHA256:02ED86605DE87E19E7095C6C7D07827B6DA6034F96A1959303910E6A2CC26DD5
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Internet Download Manager.lnkbinary
MD5:12F251F3C3EEDA593CF25CE62A3A5841
SHA256:8A84B5661AF219489205B2F327E16C8EBF3A71F2A095132384EC8452819A286E
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Internet Download Manager.lnkbinary
MD5:51911FC1E67AFE2AE93FE5F456D3EE9B
SHA256:DE124A56429691A4D5248A76813B107236B8E05AC7BA2C5F2648393040711818
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
66
DNS requests
152
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2356
IDMan.exe
GET
200
88.221.110.91:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19454423c030c89d
unknown
whitelisted
3256
firefox.exe
POST
200
2.22.242.225:80
http://r11.o.lencr.org/
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/we2
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/we2
unknown
whitelisted
3256
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
3256
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
3256
firefox.exe
POST
200
18.173.205.76:80
http://ocsps.ssl.com/
unknown
whitelisted
3256
firefox.exe
POST
200
18.173.205.76:80
http://ocsps.ssl.com/
unknown
whitelisted
3256
firefox.exe
POST
200
2.22.242.121:80
http://r10.o.lencr.org/
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/we2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
2356
IDMan.exe
88.221.110.91:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
3256
firefox.exe
169.61.27.133:443
secure.internetdownloadmanager.com
SOFTLAYER
US
whitelisted
3256
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3256
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
3256
firefox.exe
18.173.205.76:80
ocsps.ssl.com
US
whitelisted
3256
firefox.exe
2.22.242.225:80
r11.o.lencr.org
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.110
whitelisted
ctldl.windowsupdate.com
  • 88.221.110.91
  • 2.16.100.168
whitelisted
test.internetdownloadmanager.com
  • 185.80.221.18
whitelisted
secure.internetdownloadmanager.com
  • 169.61.27.133
whitelisted
www.internetdownloadmanager.com
  • 169.61.27.133
whitelisted
mirror3.internetdownloadmanager.com
  • 174.127.113.77
whitelisted
mirror5.internetdownloadmanager.com
  • 185.80.221.19
whitelisted
registeridm.com
  • 169.61.27.133
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

No threats detected
No debug info