File name:

ManageEngine_ADManager_Plus_Tools.exe

Full analysis: https://app.any.run/tasks/cd0dd711-5277-4608-8bfb-7aacac23aae1
Verdict: Malicious activity
Analysis date: December 19, 2023, 13:37:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1EBC0807A0B2970118F601CABB180299

SHA1:

1670BCAD09D41236E253FCA8AB6E224006A254E9

SHA256:

595266BB32DEE95527847C8CA21AE37DB17EA3A22C4192D31545B87BA8D31CB8

SSDEEP:

98304:JWhrVS5Tf+S+PCgXvObz46cJarU/N3gpkq2QBIcUB8rx0g3cHzKQuGedMIXbG4st:t4EfQEzWj0KfvLBjN9XwiDLH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2268)
      • ADSMFreeWindows_7zip.exe (PID: 188)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1044)
    • Searches for installed software

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Drops 7-zip archiver for unpacking

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Executing commands from a ".bat" file

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Starts CMD.EXE for commands execution

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • The process drops C-runtime libraries

      • ADSMFreeWindows_7zip.exe (PID: 188)
    • Process drops legitimate windows executable

      • ADSMFreeWindows_7zip.exe (PID: 188)
    • Reads the Internet Settings

      • cmd.exe (PID: 2624)
      • wscript.exe (PID: 2564)
      • wscript.exe (PID: 2368)
    • The process executes VB scripts

      • cmd.exe (PID: 2624)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 2564)
      • wscript.exe (PID: 2368)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 2564)
      • wscript.exe (PID: 2368)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 2564)
      • wscript.exe (PID: 2368)
  • INFO

    • Reads the computer name

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2268)
      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
      • FreeTool.exe (PID: 2472)
      • FreeTool.exe (PID: 3040)
    • Create files in a temporary directory

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2268)
      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Checks supported languages

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2268)
      • ADSMFreeWindows_7zip.exe (PID: 188)
      • FreeTool.exe (PID: 2472)
      • FreeTool.exe (PID: 3040)
    • Reads the machine GUID from the registry

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
      • FreeTool.exe (PID: 2472)
      • FreeTool.exe (PID: 3040)
    • Creates files in the program directory

      • ManageEngine_ADManager_Plus_Tools.exe (PID: 2020)
    • Application launched itself

      • iexplore.exe (PID: 2636)
    • Manual execution by a user

      • wscript.exe (PID: 2368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.ax | DirectShow filter (56.9)
.exe | Win64 Executable (generic) (7.7)
.exe | Win32 Executable (generic) (1.2)
.exe | Generic Win/DOS Executable (0.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:09:20 12:18:20+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 431104
InitializedDataSize: 510976
UninitializedDataSize: -
EntryPoint: 0x41d17
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ZOHO Corp
FileDescription: InstallScript Setup Launcher Unicode
FileVersion: 4
InternalName: Setup
LegalCopyright: Copyright (c) 2018 Flexera. All Rights Reserved.
OriginalFileName: InstallShield Setup.exe
ProductName: ADManager Plus Free Tools
ProductVersion: 4
InternalBuildNumber: 185990
ISInternalVersion: 24.0.573
ISInternalDescription: InstallScript Setup Launcher Unicode
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
14
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start manageengine_admanager_plus_tools.exe manageengine_admanager_plus_tools.exe no specs vssvc.exe no specs cmd.exe no specs adsmfreewindows_7zip.exe no specs iexplore.exe cmd.exe no specs wscript.exe no specs freetool.exe no specs iexplore.exe wscript.exe no specs freetool.exe no specs freetool.exe manageengine_admanager_plus_tools.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188.\ADSMFREEWINDOWS_7zip.exe -yC:\ManageEngine\ADManager Plus Free Tools\ADSMFreeWindows_7zip.execmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
19.00
Modules
Images
c:\manageengine\admanager plus free tools\adsmfreewindows_7zip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
900"C:\ManageEngine\ADManager Plus Free Tools\bin\FreeTool.exe" C:\ManageEngine\ADManager Plus Free Tools\bin\FreeTool.exewscript.exe
User:
admin
Company:
adventnet
Integrity Level:
MEDIUM
Description:
FreeTool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\manageengine\admanager plus free tools\bin\freetool.exe
c:\windows\system32\ntdll.dll
1044C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2020C:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\ManageEngine_ADManager_Plus_Tools.exe -package:"C:\Users\admin\AppData\Local\Temp\ManageEngine_ADManager_Plus_Tools.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\ManageEngine_ADManager_Plus_Tools.exe"C:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\ManageEngine_ADManager_Plus_Tools.exeManageEngine_ADManager_Plus_Tools.exe
User:
admin
Company:
ZOHO Corp
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher Unicode
Exit code:
0
Version:
4.0
Modules
Images
c:\users\admin\appdata\local\temp\{18348a4e-c590-4c53-b4d9-8f9ca9950c47}\manageengine_admanager_plus_tools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2044"C:\Users\admin\AppData\Local\Temp\ManageEngine_ADManager_Plus_Tools.exe" C:\Users\admin\AppData\Local\Temp\ManageEngine_ADManager_Plus_Tools.exeexplorer.exe
User:
admin
Company:
ZOHO Corp
Integrity Level:
MEDIUM
Description:
InstallScript Setup Launcher Unicode
Exit code:
3221226540
Version:
4.0
Modules
Images
c:\users\admin\appdata\local\temp\manageengine_admanager_plus_tools.exe
c:\windows\system32\ntdll.dll
2096cmd.exe /c C:\Users\admin\AppData\Local\Temp\{B91549D9-8175-4134-8400-2A3B1AC35CF4}\{13405F8E-4962-435B-B10D-21BB8261B4B4}\runsfx.bat "C:\ManageEngine\ADManager Plus Free Tools" > "C:\ManageEngine\ADManager Plus Free Tools\logs\unziplog.txt" 2>&1 C:\Windows\System32\cmd.exeManageEngine_ADManager_Plus_Tools.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2268"C:\Users\admin\AppData\Local\Temp\ManageEngine_ADManager_Plus_Tools.exe" C:\Users\admin\AppData\Local\Temp\ManageEngine_ADManager_Plus_Tools.exe
explorer.exe
User:
admin
Company:
ZOHO Corp
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher Unicode
Exit code:
0
Version:
4.0
Modules
Images
c:\users\admin\appdata\local\temp\manageengine_admanager_plus_tools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2368"C:\Windows\System32\WScript.exe" "C:\ManageEngine\ADManager Plus Free Tools\bin\run.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2472"C:\ManageEngine\ADManager Plus Free Tools\bin\FreeTool.exe" C:\ManageEngine\ADManager Plus Free Tools\bin\FreeTool.exewscript.exe
User:
admin
Company:
adventnet
Integrity Level:
HIGH
Description:
FreeTool
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\manageengine\admanager plus free tools\bin\freetool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2564"C:\Windows\System32\WScript.exe" "C:\ManageEngine\ADManager Plus Free Tools\bin\run.vbs" C:\Windows\System32\wscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
18 791
Read events
18 678
Write events
112
Delete events
1

Modification events

(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
73
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) ManageEngine_ADManager_Plus_Tools.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:FirstRun
Value:
0
Executable files
57
Suspicious files
37
Text files
147
Unknown types
0

Dropped files

PID
Process
Filename
Type
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\setup.initext
MD5:677E9FDD75F82EA7DD048F7284073334
SHA256:E4F9ADE2A1D02E4EC631AE9D6F67D19B467CD880A7C09F4A635CE860775BED9C
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\layout.binbinary
MD5:E8F3F013A689DA9855CEF054C8B31914
SHA256:AC465CC562D24BCDCCD90459E7013C121588E4BFC6CCBDAE5B25FE6FE6B2814F
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\data1.hdrcompressed
MD5:2A2ADBB238DA165019ABB696145A8B35
SHA256:860720C038D7D41D301299AF2054A33DF6744E308EB5CFBE6FFB981C91F93B65
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\data1.cabcompressed
MD5:6F5BE362A0D67620AE2066EAE6067BAC
SHA256:1403BA947890421F15805B491F939491DDE614E08F9E0CECB96222117E0C2E08
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\setup.exeexecutable
MD5:1AC6637C93D1CC5AD627B27E3E47FBAD
SHA256:0D970885EC0DCF88492BE79CBFB52AC4303EC94534C747DF2817546B512C55C0
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\0x0409.initext
MD5:A108F0030A2CDA00405281014F897241
SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\ISSetup.dllexecutable
MD5:9C9F06532BBC96493531AAA57BC0FC57
SHA256:60EBC86C2DD03056AD48ADC6D2468FD54C548A55D2D305577EB7E079D90AC13F
2268ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\Disk1\Setup.bmpimage
MD5:11E4F68ACADEAB56B92594A7338732E8
SHA256:EDAB74CB0D8F9ECB2E7179EDACA8D70058033F35DF4D11BFB80F54F2CD9BCD73
2020ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{18348A4E-C590-4C53-B4D9-8F9CA9950C47}\0x0409.initext
MD5:A108F0030A2CDA00405281014F897241
SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
2020ManageEngine_ADManager_Plus_Tools.exeC:\Users\admin\AppData\Local\Temp\{B91549D9-8175-4134-8400-2A3B1AC35CF4}\{13405f8e-4962-435b-b10d-21bb8261b4b4}\ManageLUUninstall.battext
MD5:1CA621BBE05FEC20409F10C411C4FEE2
SHA256:28FD4CCDD9E54BA420D6BF94308CCB040FEDB91E2246FD9C59D315CC554C5A90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
15
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2568
iexplore.exe
GET
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5ec677613e627608
unknown
unknown
2568
iexplore.exe
GET
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1614a6962a048846
unknown
unknown
2636
iexplore.exe
GET
200
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1790e83fddbcbdef
unknown
compressed
4.66 Kb
unknown
2636
iexplore.exe
GET
200
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5aed898efcc03447
unknown
compressed
4.66 Kb
unknown
2636
iexplore.exe
GET
200
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c08bccfb6615b425
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2568
iexplore.exe
185.20.209.211:443
www.manageengine.com
Computerline GmbH
CH
unknown
2568
iexplore.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2636
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
2636
iexplore.exe
46.228.146.128:80
ctldl.windowsupdate.com
LLNW
US
unknown

DNS requests

Domain
IP
Reputation
www.manageengine.com
  • 185.20.209.211
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
  • 46.228.146.128
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
unknown

Threats

No threats detected
No debug info