File name:

TreeSizeFree.exe

Full analysis: https://app.any.run/tasks/fc1ac7ac-e942-4d19-abe6-6290f5518e78
Verdict: Malicious activity
Analysis date: October 02, 2021, 00:16:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

E31DF4A1DCB48483429E4348B9CB7083

SHA1:

5569FA42FFFEB7A0013070025608B1F059A5ED46

SHA256:

51707A86F2154DBB186050D11D519A7D8201FAED771D8C55A5C9FDD73327C03A

SSDEEP:

196608:biWnM39ATrilLChJ9l/OE85VnoZpsnqNHk:ryI1l/3X+D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TreeSizeFreeSetup.exe (PID: 1876)
      • TreeSizeFreeSetup.exe (PID: 2844)
    • Drops executable file immediately after starts

      • TreeSizeFreeSetup.exe (PID: 1876)
      • TreeSizeFreeSetup.exe (PID: 2844)
  • SUSPICIOUS

    • Checks supported languages

      • TreeSizeFree.exe (PID: 1448)
      • TreeSizeFreeSetup.exe (PID: 1876)
      • TreeSizeFreeSetup.tmp (PID: 2776)
      • TreeSizeFreeSetup.exe (PID: 2844)
      • TreeSizeFreeSetup.tmp (PID: 3544)
    • Reads the computer name

      • TreeSizeFree.exe (PID: 1448)
      • TreeSizeFreeSetup.tmp (PID: 2776)
      • TreeSizeFreeSetup.tmp (PID: 3544)
    • Starts Internet Explorer

      • TreeSizeFree.exe (PID: 1448)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3580)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3580)
      • iexplore.exe (PID: 2196)
      • TreeSizeFreeSetup.exe (PID: 1876)
      • TreeSizeFreeSetup.exe (PID: 2844)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 2196)
      • iexplore.exe (PID: 3580)
    • Reads the computer name

      • iexplore.exe (PID: 3580)
      • iexplore.exe (PID: 2196)
    • Changes internet zones settings

      • iexplore.exe (PID: 2196)
    • Application launched itself

      • iexplore.exe (PID: 2196)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3580)
      • iexplore.exe (PID: 2196)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2196)
      • iexplore.exe (PID: 3580)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3580)
    • Creates files in the user directory

      • iexplore.exe (PID: 3580)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2196)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2196)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2196)
    • Application was dropped or rewritten from another process

      • TreeSizeFreeSetup.tmp (PID: 2776)
      • TreeSizeFreeSetup.tmp (PID: 3544)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (37.6)
.exe | UPX compressed Win32 Executable (24.5)
.exe | Win32 EXE Yoda's Crypter (24)
.dll | Win32 Dynamic Link Library (generic) (5.9)
.exe | Win32 Executable (generic) (4)

EXIF

EXE

ProgramID: JAMSoftware.TreeSizeFree
Comments: https://www.jam-software.com/treesize_free/
ProductVersion: 4.5.2
ProductName: TreeSize Free
OriginalFileName: TreeSizeFree.exe
LegalCopyright: © 1996-2021 by Joachim Marder e.K.
InternalName: 80
FileVersion: 4.5.2.600
FileDescription: TreeSize Free hard disk space manager
CompanyName: JAM Software
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 4.5.2.0
FileVersionNumber: 4.5.2.600
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x1cb6eb0
UninitializedDataSize: 22634496
InitializedDataSize: 57344
CodeSize: 7475200
LinkerVersion: 2.25
PEType: PE32
TimeStamp: 2021:08:23 14:50:56+02:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 23-Aug-2021 12:50:56

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0050
Pages in file: 0x0002
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x000F
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x001A
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 23-Aug-2021 12:50:56
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_NET_RUN_FROM_SWAP
  • IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x01596000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x01597000
0x00721000
0x00720800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.92156
.rsrc
0x01CB8000
0x0000E000
0x0000D600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.76947

Imports

IMAGEHLP.DLL
KERNEL32.DLL
SHFolder.dll
URLMON.DLL
advapi32.dll
comctl32.dll
comdlg32.dll
crypt32.dll
gdi32.dll
mpr.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start treesizefree.exe no specs iexplore.exe iexplore.exe treesizefreesetup.exe treesizefreesetup.tmp no specs treesizefreesetup.exe treesizefreesetup.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Users\admin\AppData\Local\Temp\TreeSizeFree.exe" C:\Users\admin\AppData\Local\Temp\TreeSizeFree.exeExplorer.EXE
User:
admin
Company:
JAM Software
Integrity Level:
MEDIUM
Description:
TreeSize Free hard disk space manager
Exit code:
1
Version:
4.5.2.600
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\treesizefree.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1876"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe
iexplore.exe
User:
admin
Company:
JAM Software
Integrity Level:
MEDIUM
Description:
TreeSize Free Setup
Exit code:
1
Version:
4.5.2.600
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
2196"C:\Program Files\Internet Explorer\iexplore.exe" https://www.jam-software.com/treesize_free/C:\Program Files\Internet Explorer\iexplore.exe
TreeSizeFree.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2776"C:\Users\admin\AppData\Local\Temp\is-J5LOT.tmp\TreeSizeFreeSetup.tmp" /SL5="$501E2,8509609,798208,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe" C:\Users\admin\AppData\Local\Temp\is-J5LOT.tmp\TreeSizeFreeSetup.tmpTreeSizeFreeSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-j5lot.tmp\treesizefreesetup.tmp
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2844"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe" /SPAWNWND=$1020C /NOTIFYWND=$501E2 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe
TreeSizeFreeSetup.tmp
User:
admin
Company:
JAM Software
Integrity Level:
HIGH
Description:
TreeSize Free Setup
Exit code:
1
Version:
4.5.2.600
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\treesizefreesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3544"C:\Users\admin\AppData\Local\Temp\is-UVGTR.tmp\TreeSizeFreeSetup.tmp" /SL5="$2020E,8509609,798208,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\TreeSizeFreeSetup.exe" /SPAWNWND=$1020C /NOTIFYWND=$501E2 C:\Users\admin\AppData\Local\Temp\is-UVGTR.tmp\TreeSizeFreeSetup.tmpTreeSizeFreeSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-uvgtr.tmp\treesizefreesetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
3580"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2196 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 383
Read events
17 242
Write events
137
Delete events
4

Modification events

(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30914338
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30914338
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
5
Suspicious files
9
Text files
56
Unknown types
11

Dropped files

PID
Process
Filename
Type
3580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1E11E75149C17A93653DA7DC0B8CF53F_4FFC8B6E591E7926DD7B665DC25789F7der
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\treesize_free[1].htmhtml
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6der
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\treesize_free[1].htmhtml
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\style[1].csstext
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\main[1].jstext
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1E11E75149C17A93653DA7DC0B8CF53F_4FFC8B6E591E7926DD7B665DC25789F7binary
MD5:
SHA256:
3580iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\css_0NXaEWVqGMHAGyPB8b4sDeqTwDS7uhbYuCfVjYfiBug[1].csstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
48
DNS requests
12
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3580
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAr45v4Os%2FkBPyR6iuXf6yg%3D
US
der
471 b
whitelisted
3580
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEATyHnj0NJ94AzyUAOztteM%3D
US
der
471 b
whitelisted
2196
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
2196
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
3580
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3580
iexplore.exe
GET
200
8.248.135.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7db772841edbbdad
US
compressed
4.70 Kb
whitelisted
3580
iexplore.exe
GET
200
8.248.135.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1dc7cf10cc804bc1
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3580
iexplore.exe
116.202.3.251:443
www.jam-software.com
334,Udyog Vihar
IN
suspicious
3580
iexplore.exe
8.248.135.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2196
iexplore.exe
116.202.5.43:443
customers.jam-software.de
334,Udyog Vihar
IN
unknown
2196
iexplore.exe
116.202.3.251:443
www.jam-software.com
334,Udyog Vihar
IN
suspicious
3580
iexplore.exe
116.202.5.43:443
customers.jam-software.de
334,Udyog Vihar
IN
unknown
78.47.225.43:443
matomo.jam-software.com
Hetzner Online GmbH
DE
suspicious
2196
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2196
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3580
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3580
iexplore.exe
78.47.225.43:443
matomo.jam-software.com
Hetzner Online GmbH
DE
suspicious

DNS requests

Domain
IP
Reputation
www.jam-software.com
  • 116.202.3.251
suspicious
ctldl.windowsupdate.com
  • 8.248.135.254
  • 8.241.78.126
  • 8.241.90.254
  • 8.253.190.120
  • 67.26.73.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
matomo.jam-software.com
  • 78.47.225.43
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
customers.jam-software.de
  • 116.202.5.43
unknown
matomo.jam-software.de
  • 78.47.225.43
suspicious
downloads.jam-software.de
  • 116.202.5.43
unknown
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

PID
Process
Class
Message
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3580
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
No debug info