File name:

FraudFox UserTools v2.15.exe

Full analysis: https://app.any.run/tasks/bc00bf49-84b1-4647-8b26-a3010ce272c3
Verdict: Malicious activity
Analysis date: August 11, 2023, 05:35:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

47AC6BF1DDB308B69A8CD75484B0DEA5

SHA1:

DB86F4721A62EA51577C94E84D8205D67B03A59E

SHA256:

41EDCB2712FCE377939BDBF9E08217114AFD148B846C7F6640637871E940D418

SSDEEP:

24576:4kCn8mqa+kv8IUCyUvByNiRVBIygHNBV9M+nZdjyF3KRTVdGpRIftRm:4fn8Z/ZIUgBP7BVgH7b//RVdGpRSts

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AdobeSystemsCC.exe (PID: 4004)
      • AdobeSystems.exe (PID: 3388)
      • AdobeSystems.exe (PID: 4064)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeUpdater.exe (PID: 3308)
      • AdobeSync.exe (PID: 2340)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • Changes the login/logoff helper path in the registry

      • AdobeSystemsCC.exe (PID: 4004)
  • SUSPICIOUS

    • Reads the Internet Settings

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • AdobeSystemsCC.exe (PID: 4004)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeSystems.exe (PID: 3388)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • Executable content was dropped or overwritten

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
      • AdobeSystemsCC.exe (PID: 4004)
      • AdobeSystems.exe (PID: 3388)
    • Application launched itself

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
    • Starts itself from another location

      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
  • INFO

    • Reads the computer name

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeSystemsCC.exe (PID: 4004)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • Reads Environment values

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
    • Checks supported languages

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeUpdater.exe (PID: 3308)
      • AdobeSystemsCC.exe (PID: 4004)
      • AdobeSystems.exe (PID: 4064)
      • AdobeSync.exe (PID: 2340)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • The process checks LSA protection

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeSystemsCC.exe (PID: 4004)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • Reads the machine GUID from the registry

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • AdobeSystems.exe (PID: 3388)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
    • Creates files or folders in the user directory

      • FraudFox UserTools v2.15.exe (PID: 1872)
      • FraudFox UserTools v2.15.exe (PID: 2736)
      • WQ6qTyxsI3L0lLuZ.exe (PID: 2536)
      • AdobeSystems.exe (PID: 3388)
      • x3P3eXTMR4EVF2rl.exe (PID: 1456)
      • AdobeSystemsCC.exe (PID: 4004)
    • Create files in a temporary directory

      • FraudFox UserTools v2.15.exe (PID: 2736)
      • AdobeSystemsCC.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

ProductVersion: 6.0.160.1
ProductName: Java(TM) Platform SE 6 U16
OriginalFileName: axbridge.dll
LegalCopyright: Copyright © 2004
InternalName: ActiveX Bridge for JavaBeans(TM)
FullVersion: 1.6.0_16-b01
FileVersion: 6.0.160.1
FileDescription: ActiveX Bridge for JavaBeans(TM)
CompanyName: Sun Microsystems, Inc.
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Dynamic link library
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 6.0.160.1
FileVersionNumber: 6.0.160.1
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1629de
UninitializedDataSize: -
InitializedDataSize: 170496
CodeSize: 1444352
LinkerVersion: 8
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2017:02:18 12:11:10+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 18-Feb-2017 12:11:10
Detected languages:
  • English - United States
CompanyName: Sun Microsystems, Inc.
FileDescription: ActiveX Bridge for JavaBeans(TM)
FileVersion: 6.0.160.1
Full Version: 1.6.0_16-b01
InternalName: ActiveX Bridge for JavaBeans(TM)
LegalCopyright: Copyright © 2004
OriginalFilename: axbridge.dll
ProductName: Java(TM) Platform SE 6 U16
ProductVersion: 6.0.160.1

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 18-Feb-2017 12:11:10
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x001609E4
0x00160A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
7.99463
.rsrc
0x00164000
0x00029692
0x00029800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.7579
.reloc
0x0018E000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.10191

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.00112
490
UNKNOWN
UNKNOWN
RT_MANIFEST
50
7.83966
5673
UNKNOWN
UNKNOWN
RT_ICON
51
1.01767
67624
UNKNOWN
UNKNOWN
RT_ICON
52
1.26755
38056
UNKNOWN
UNKNOWN
RT_ICON
53
1.34624
21640
UNKNOWN
UNKNOWN
RT_ICON
54
1.24301
16936
UNKNOWN
UNKNOWN
RT_ICON
55
1.66658
9640
UNKNOWN
UNKNOWN
RT_ICON
56
2.11336
4264
UNKNOWN
UNKNOWN
RT_ICON
57
2.42373
2440
UNKNOWN
UNKNOWN
RT_ICON
58
3.00456
1128
UNKNOWN
UNKNOWN
RT_ICON

Imports

mscoree.dll
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start fraudfox usertools v2.15.exe adobesystems.exe fraudfox usertools v2.15.exe wq6qtyxsi3l0lluz.exe adobeupdater.exe no specs adobesystemscc.exe adobesystems.exe no specs x3p3extmr4evf2rl.exe adobesync.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1456"C:\Users\admin\AppData\Local\Temp\x3P3eXTMR4EVF2rl.exe" C:\Users\admin\AppData\Local\Temp\x3P3eXTMR4EVF2rl.exe
AdobeSystemsCC.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Collaboration Synchronizer 10.1
Exit code:
0
Version:
10.1.16.13
Modules
Images
c:\users\admin\appdata\local\temp\x3p3extmr4evf2rl.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
1872"C:\Users\admin\AppData\Local\Temp\FraudFox UserTools v2.15.exe" C:\Users\admin\AppData\Local\Temp\FraudFox UserTools v2.15.exe
explorer.exe
User:
admin
Company:
Sun Microsystems, Inc.
Integrity Level:
MEDIUM
Description:
ActiveX Bridge for JavaBeans(TM)
Exit code:
0
Version:
6.0.160.1
Modules
Images
c:\users\admin\appdata\local\temp\fraudfox usertools v2.15.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\gdi32.dll
2340"C:\Users\admin\AppData\Local\Adobe\Acrobat\Updater\AdobeSync.exe" C:\Users\admin\AppData\Local\Temp\x3P3eXTMR4EVF2rl.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\Updater\AdobeSync.exex3P3eXTMR4EVF2rl.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Collaboration Synchronizer 10.1
Exit code:
0
Version:
10.1.16.13
Modules
Images
c:\users\admin\appdata\local\adobe\acrobat\updater\adobesync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2536"C:\Users\admin\AppData\Local\Temp\WQ6qTyxsI3L0lLuZ.exe" C:\Users\admin\AppData\Local\Temp\WQ6qTyxsI3L0lLuZ.exe
FraudFox UserTools v2.15.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe Updater
Exit code:
0
Version:
15.9.2205.29857
Modules
Images
c:\users\admin\appdata\local\temp\wq6qtyxsi3l0lluz.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2736"C:\Users\admin\AppData\Local\Temp\FraudFox UserTools v2.15.exe"C:\Users\admin\AppData\Local\Temp\FraudFox UserTools v2.15.exe
FraudFox UserTools v2.15.exe
User:
admin
Company:
Sun Microsystems, Inc.
Integrity Level:
MEDIUM
Description:
ActiveX Bridge for JavaBeans(TM)
Exit code:
0
Version:
6.0.160.1
Modules
Images
c:\users\admin\appdata\local\temp\fraudfox usertools v2.15.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3308"C:\Users\admin\AppData\Local\Adobe\Acrobat\Updater\AdobeUpdater.exe" C:\Users\admin\AppData\Local\Temp\WQ6qTyxsI3L0lLuZ.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\Updater\AdobeUpdater.exeWQ6qTyxsI3L0lLuZ.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe Updater
Exit code:
0
Version:
15.9.2205.29857
Modules
Images
c:\users\admin\appdata\local\adobe\acrobat\updater\adobeupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3388"C:\Users\admin\AppData\Local\AdobeSystems.exe" C:\Users\admin\AppData\Local\AdobeSystems.exe
FraudFox UserTools v2.15.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Collaboration Synchronizer 10.1
Exit code:
0
Version:
10.1.16.13
Modules
Images
c:\users\admin\appdata\local\adobesystems.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
4004"C:\Users\admin\AppData\Local\AdobeSystemsCC.exe" C:\Users\admin\AppData\Local\AdobeSystemsCC.exe
AdobeSystems.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Collaboration Synchronizer 10.1
Exit code:
0
Version:
10.1.16.13
Modules
Images
c:\users\admin\appdata\local\adobesystemscc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
4064"C:\Users\admin\AppData\Local\AdobeSystems.exe"C:\Users\admin\AppData\Local\AdobeSystems.exeAdobeSystems.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Collaboration Synchronizer 10.1
Exit code:
0
Version:
10.1.16.13
Modules
Images
c:\users\admin\appdata\local\adobesystems.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
6 047
Read events
5 998
Write events
49
Delete events
0

Modification events

(PID) Process:(1872) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1872) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1872) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1872) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2736) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2736) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2736) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2736) FraudFox UserTools v2.15.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2536) WQ6qTyxsI3L0lLuZ.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2536) WQ6qTyxsI3L0lLuZ.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
10
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1872FraudFox UserTools v2.15.exeC:\Users\admin\AppData\Local\AdobeSystems.exeexecutable
MD5:E445B683497855FA273BC7A15C4BB2BE
SHA256:AAF87EF55D7EAE69A6C49E065F20126EBD2A27C5207E4EAF4792EE32887254BC
3388AdobeSystems.exeC:\Users\admin\AppData\Local\AdobeSystemsCC.exeexecutable
MD5:6DE72D8673D88864E013BD30631871A3
SHA256:BEF526CEDD2B2543BF1250EA5B4E3F98FCDFA68F111494DCA1418C6DB4F02BA1
3388AdobeSystems.exeC:\Users\admin\AppData\Local\AdobeSystemsCC.txttext
MD5:CAF00D5D6F21C3624FB150442F9E1C00
SHA256:18CB55AA12B498AA19AFBBA43731562985E6826B655D01514C009E200AC80C6E
2536WQ6qTyxsI3L0lLuZ.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\Updater\AdobeUpdater.exeexecutable
MD5:5324F596227A0869E6CA03C9BC728FC1
SHA256:22E6F18EE2C807C2585A4D53B94A96BD2A202D59E78D0BA2EE91132529C1EF59
2536WQ6qTyxsI3L0lLuZ.exeC:\Users\admin\AppData\Roaming\Adobe\Updater\AdobeHelper.exeexecutable
MD5:5324F596227A0869E6CA03C9BC728FC1
SHA256:22E6F18EE2C807C2585A4D53B94A96BD2A202D59E78D0BA2EE91132529C1EF59
4004AdobeSystemsCC.exeC:\Users\admin\AppData\Local\Temp\x3P3eXTMR4EVF2rl.exeexecutable
MD5:C502D2F8071D0B91ED1537E0EA76B46A
SHA256:7D57F90C1174E4568F298F0179C26BA90F43E53BFF9E39A546759AB5666BABB8
1456x3P3eXTMR4EVF2rl.exeC:\Users\admin\AppData\Roaming\Adobe\Updater\AdobeSystems.exeexecutable
MD5:C502D2F8071D0B91ED1537E0EA76B46A
SHA256:7D57F90C1174E4568F298F0179C26BA90F43E53BFF9E39A546759AB5666BABB8
4004AdobeSystemsCC.exeC:\Users\admin\AppData\Roaming\Adobe\Cloud\Local\bNEeQYJKTBR1.exeexecutable
MD5:6DE72D8673D88864E013BD30631871A3
SHA256:BEF526CEDD2B2543BF1250EA5B4E3F98FCDFA68F111494DCA1418C6DB4F02BA1
1872FraudFox UserTools v2.15.exeC:\Users\admin\Documents\Delay.txttext
MD5:99E7188B344C1AF8D5DCC14755DE4324
SHA256:66DFF79A68A72FD6F082BDF9B9D7C0C339D53D674FD49C168BD806D7EEF12E57
1872FraudFox UserTools v2.15.exeC:\Users\admin\AppData\Local\AdobeSystems.txttext
MD5:523F758DE60C329F9373598800BB9445
SHA256:35A9FA6CE719CA4B67B6DBA19662636E0964B61643668BC61EA09F73799B5683
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info