File name:

idm.6.42.32_with_patch.rar

Full analysis: https://app.any.run/tasks/05d6a913-f8a6-4a2a-b43e-ae2ee5fcfa58
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 18, 2025, 14:48:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
idm
tool
arch-scr
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C94317F91C856D432E7789AA82BF6414

SHA1:

538434CAB3DBCFCFDA0F7E2DCD4923D0E6A31F6D

SHA256:

4016514CD74A3580F33DE0012ABD8AE1ABDF6446A488AFC2B7A64AD2F1513448

SSDEEP:

98304:Gv9o/VhIaDiLe+CtFKHXAV/Z8Vc1Az2mYyY8jYRqLOh8jD3RXt4N/J6TKak7pxiS:EinESnAHqZJdpM1mudnho9mR3a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • rundll32.exe (PID: 3080)
      • IDMan.exe (PID: 2356)
    • Starts NET.EXE for service management

      • Uninstall.exe (PID: 2844)
      • net.exe (PID: 3660)
    • Actions looks like stealing of personal data

      • IDMan.exe (PID: 3216)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
      • WinRAR.exe (PID: 2108)
      • IDMan.exe (PID: 3216)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Starts application with an unusual extension

      • idman642build28.exe (PID: 1416)
    • Reads the Internet Settings

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • runonce.exe (PID: 2760)
      • Uninstall.exe (PID: 2844)
      • IDM 6.42.32 Patch.exe (PID: 1124)
      • IDMan.exe (PID: 3216)
    • Creates a software uninstall entry

      • IDM1.tmp (PID: 2384)
    • Creates/Modifies COM task schedule object

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • Uninstall.exe (PID: 2844)
    • Reads settings of System Certificates

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • The process creates files with name similar to system file names

      • IDM1.tmp (PID: 2384)
    • Drops a system driver (possible attempt to evade defenses)

      • rundll32.exe (PID: 3080)
    • Creates or modifies Windows services

      • Uninstall.exe (PID: 2844)
    • Uses RUNDLL32.EXE to load library

      • Uninstall.exe (PID: 2844)
    • Application launched itself

      • WinRAR.exe (PID: 2108)
    • There is functionality for taking screenshot (YARA)

      • IEMonitor.exe (PID: 3200)
    • Executable content was dropped or overwritten

      • IDMan.exe (PID: 2356)
      • IDM 6.42.32 Patch.exe (PID: 1124)
      • rundll32.exe (PID: 3080)
    • Starts CMD.EXE for commands execution

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Drops 7-zip archiver for unpacking

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 1072)
    • Executing commands from a ".bat" file

      • IDM 6.42.32 Patch.exe (PID: 1124)
    • The executable file from the user directory is run by the CMD process

      • t15447.exe (PID: 2892)
      • t15447.exe (PID: 4068)
      • t15447.exe (PID: 348)
      • t15447.exe (PID: 3608)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2108)
      • IDMan.exe (PID: 2356)
      • rundll32.exe (PID: 3080)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Local mutex for internet shortcut management

      • WinRAR.exe (PID: 2108)
    • Manual execution by a user

      • idman642build28.exe (PID: 2276)
      • idman642build28.exe (PID: 1416)
      • firefox.exe (PID: 3280)
      • IDM 6.42.32 Patch.exe (PID: 1124)
      • IDM 6.42.32 Patch.exe (PID: 1396)
    • Checks supported languages

      • idman642build28.exe (PID: 1416)
      • IDM1.tmp (PID: 2384)
      • idmBroker.exe (PID: 704)
      • Uninstall.exe (PID: 2844)
      • MediumILStart.exe (PID: 3696)
      • IDMan.exe (PID: 3216)
      • IDMan.exe (PID: 2356)
      • IEMonitor.exe (PID: 3200)
      • IDM 6.42.32 Patch.exe (PID: 1124)
      • mode.com (PID: 3084)
      • t15447.exe (PID: 2892)
      • t15447.exe (PID: 4068)
      • t15447.exe (PID: 348)
      • t15447.exe (PID: 3608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2108)
      • WinRAR.exe (PID: 3712)
    • INTERNETDOWNLOADMANAGER mutex has been found

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
      • IEMonitor.exe (PID: 3200)
    • Create files in a temporary directory

      • idman642build28.exe (PID: 1416)
      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Reads the machine GUID from the registry

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • MediumILStart.exe (PID: 3696)
      • IDMan.exe (PID: 3216)
    • Reads the computer name

      • IDM1.tmp (PID: 2384)
      • Uninstall.exe (PID: 2844)
      • MediumILStart.exe (PID: 3696)
      • IDMan.exe (PID: 3216)
      • IDMan.exe (PID: 2356)
      • IEMonitor.exe (PID: 3200)
      • IDM 6.42.32 Patch.exe (PID: 1124)
    • Creates files in the program directory

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
    • Checks proxy server information

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Creates files or folders in the user directory

      • IDM1.tmp (PID: 2384)
      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Reads the software policy settings

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Disables trace logs

      • IDMan.exe (PID: 2356)
      • IDMan.exe (PID: 3216)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2760)
    • Application launched itself

      • firefox.exe (PID: 3280)
      • firefox.exe (PID: 3256)
    • Creates files in the driver directory

      • rundll32.exe (PID: 3080)
    • Reads the time zone

      • runonce.exe (PID: 2760)
    • Starts MODE.COM to configure console settings

      • mode.com (PID: 3084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 3628352
UncompressedSize: 3628343
OperatingSystem: Win32
ArchivedFileName: IDM 6.42.32 Patch.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
85
Monitored processes
40
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe idman642build28.exe no specs idman642build28.exe idm1.tmp no specs idmbroker.exe no specs idman.exe firefox.exe no specs uninstall.exe no specs rundll32.exe firefox.exe no specs firefox.exe runonce.exe no specs grpconv.exe no specs net.exe no specs net1.exe no specs winrar.exe mediumilstart.exe no specs idman.exe iemonitor.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs idm 6.42.32 patch.exe no specs idm 6.42.32 patch.exe cmd.exe no specs cmd.exe no specs attrib.exe no specs mode.com no specs t15447.exe no specs t15447.exe no specs t15447.exe no specs reg.exe no specs find.exe no specs t15447.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
348C:\Users\admin\AppData\Local\Temp\wtmpd\t15447.exe i9dCxZ5SjHC:\Users\admin\AppData\Local\Temp\wtmpd\t15447.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\wtmpd\t15447.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
576"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.6.1335965278\1287632213" -childID 5 -isForBrowser -prefsHandle 1464 -prefMapHandle 3164 -prefsLen 29349 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd334935-08fd-44fc-ba07-e58374fbd64d} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3244 1a0a79b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
704"C:\Program Files\Internet Download Manager\idmBroker.exe" -RegServerC:\Program Files\Internet Download Manager\idmBroker.exeIDM1.tmp
User:
admin
Company:
Internet Download Manager, Tonec Inc.
Integrity Level:
HIGH
Description:
Broker for reading of IDM settings
Exit code:
0
Version:
6, 35, 9, 1
Modules
Images
c:\program files\internet download manager\idmbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1072C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\wtmpd\t15421.bat" "C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" "C:\Windows\System32\cmd.exeIDM 6.42.32 Patch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1124"C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\idm 6.42.32 patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1324"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.5.875245593\781427180" -childID 4 -isForBrowser -prefsHandle 1948 -prefMapHandle 1876 -prefsLen 36100 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e3b455e-5a04-47b2-b2ee-86c111f89069} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3392 192549b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1396"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.internetdownloadmanager.com/support/installffextfrommozillasite.htmlC:\Program Files\Mozilla Firefox\firefox.exeIDMan.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1396"C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" C:\Users\admin\Desktop\IDM 6.42.32 Patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\idm 6.42.32 patch.exe
c:\windows\system32\ntdll.dll
1416"C:\Users\admin\Desktop\idman642build28.exe" C:\Users\admin\Desktop\idman642build28.exe
explorer.exe
User:
admin
Company:
Tonec Inc.
Integrity Level:
HIGH
Description:
Internet Download Manager installer
Exit code:
0
Version:
6, 42, 28, 1
Modules
Images
c:\users\admin\desktop\idman642build28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.3.1310669352\447199199" -childID 2 -isForBrowser -prefsHandle 2620 -prefMapHandle 2616 -prefsLen 34441 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a7c7f101-9203-4c7d-897c-d84002a5371c} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 2632 176ba9b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
32 399
Read events
31 602
Write events
693
Delete events
104

Modification events

(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\idm.6.42.32_with_patch.rar
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
19
Suspicious files
287
Text files
43
Unknown types
0

Dropped files

PID
Process
Filename
Type
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\TUTORIALS.lnkbinary
MD5:35031A8F760A108D209A6131A0D4B884
SHA256:4AB2A51E047C8B5B56A5B0EE906C28AF95772BECF1343F40EFCD5AFAB9F16C6F
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnkbinary
MD5:A2AF162C1D3A1ED01CAA5994DEB5EC59
SHA256:1F1FF073BEBA8FFDEAEE162B0A60A2CEEBBC405448EB2D5BE3062052B9686BCD
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnkbinary
MD5:97C1922E73F4E8909CEA59E99A364CB6
SHA256:9B367CDFAE9A79550DA84092A11919EEC4A4719CB858576CB4DD2BE44361C146
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnkbinary
MD5:CE399777E9023283C9B710B232E27EA6
SHA256:FFC393E5F7D7DA55335C2F72DE1C0A231CAE647FDEE6B0B7BE870726767BB74D
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Grabber Help.lnkbinary
MD5:4CE12433A96EA9B072699E1664825BDA
SHA256:6B6763FB60475E7A26D86D6B600E85B928A2602ECAF2F60B63A5B8B8C71560EF
2384IDM1.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnkbinary
MD5:FDE6B0DED58B610091D78D8FBDB14981
SHA256:744C9A6BD0006A0A98D019909FD675F514CF4047C7B9E6788E47915E4A96A67C
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnkbinary
MD5:2EE1D54606680A76A8EC838F83D68678
SHA256:02ED86605DE87E19E7095C6C7D07827B6DA6034F96A1959303910E6A2CC26DD5
2384IDM1.tmpC:\Users\admin\AppData\Local\Temp\~DF0150341D472963F1.TMPbinary
MD5:EE8BD0BBA48B18D0BAD3C5E99783012F
SHA256:9358C73885A14C7DE17FDB75D2D0012ADDC7C61D90F5B1F38A129762BFFD7DEA
2384IDM1.tmpC:\Users\admin\Desktop\Internet Download Manager.lnkbinary
MD5:DBD2B9BCBE20270156B0CCA8BA2E9825
SHA256:D53A498B62B49AF9A8972649667FE4A11C779050D29F8EAA843791CF05686FD7
2384IDM1.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Grabber Help.lnkbinary
MD5:AADB862F012DFA01346DF26395BBD79A
SHA256:EAC7E2A054E31698A9C6DFC764EBD0EB1F90C11DF539FB7ECEA15A4633E82489
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
66
DNS requests
152
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3256
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
2356
IDMan.exe
GET
200
88.221.110.91:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19454423c030c89d
unknown
whitelisted
3256
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
3256
firefox.exe
POST
200
18.173.205.76:80
http://ocsps.ssl.com/
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/s/wr3/cgo
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/we2
unknown
whitelisted
3256
firefox.exe
POST
200
2.22.242.225:80
http://r11.o.lencr.org/
unknown
whitelisted
3256
firefox.exe
POST
200
2.22.242.121:80
http://r10.o.lencr.org/
unknown
whitelisted
3256
firefox.exe
POST
200
172.217.18.99:80
http://o.pki.goog/we2
unknown
whitelisted
3256
firefox.exe
POST
200
2.22.242.121:80
http://r10.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
2356
IDMan.exe
88.221.110.91:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
3256
firefox.exe
169.61.27.133:443
secure.internetdownloadmanager.com
SOFTLAYER
US
whitelisted
3256
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3256
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
3256
firefox.exe
18.173.205.76:80
ocsps.ssl.com
US
whitelisted
3256
firefox.exe
2.22.242.225:80
r11.o.lencr.org
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.110
whitelisted
ctldl.windowsupdate.com
  • 88.221.110.91
  • 2.16.100.168
whitelisted
test.internetdownloadmanager.com
  • 185.80.221.18
whitelisted
secure.internetdownloadmanager.com
  • 169.61.27.133
whitelisted
www.internetdownloadmanager.com
  • 169.61.27.133
whitelisted
mirror3.internetdownloadmanager.com
  • 174.127.113.77
whitelisted
mirror5.internetdownloadmanager.com
  • 185.80.221.19
whitelisted
registeridm.com
  • 169.61.27.133
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

No threats detected
No debug info