File name:

Wallhack-by-Osama-47_60470.exe

Full analysis: https://app.any.run/tasks/715c223c-71f0-4aba-adaa-4314f2db4a64
Verdict: Malicious activity
Analysis date: January 08, 2022, 22:25:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A84AD3A6452CED122F473E30AA485FBB

SHA1:

ECFFB742F7C45C3FF1A78A0C16C7D58884D7AF62

SHA256:

595BAFCAC1AD3B716140C95A703CF9184C4316255E587FF8DB38A8C4ABE0A153

SSDEEP:

24576:JXwOrRsREoFOi3aL2uWWOoWv8GdDAF5AYZedk2k55wkJNsxKGxhh:JgwRccLB6tU8dk2k55wg6KGx3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ALERTBLACK-AND-WHITE.exe (PID: 3096)
      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
      • 7zFM.exe (PID: 2844)
    • Drops executable file immediately after starts

      • Wallhack-by-Osama-47_60470.exe (PID: 3204)
    • Changes settings of System certificates

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
  • SUSPICIOUS

    • Checks supported languages

      • Wallhack-by-Osama-47_60470.exe (PID: 3204)
      • ALERTBLACK-AND-WHITE.exe (PID: 3096)
      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • cmd.exe (PID: 3604)
      • cmd.exe (PID: 3500)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
      • cmd.exe (PID: 1536)
      • cmd.exe (PID: 3384)
      • 7zFM.exe (PID: 2844)
    • Executable content was dropped or overwritten

      • Wallhack-by-Osama-47_60470.exe (PID: 3204)
      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
    • Reads the computer name

      • Wallhack-by-Osama-47_60470.exe (PID: 3204)
      • ALERTBLACK-AND-WHITE.exe (PID: 3096)
      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
      • 7zFM.exe (PID: 2844)
    • Application launched itself

      • ALERTBLACK-AND-WHITE.exe (PID: 3096)
      • cmd.exe (PID: 1536)
    • Starts CMD.EXE for commands execution

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • cmd.exe (PID: 1536)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 3604)
      • cmd.exe (PID: 3500)
    • Adds / modifies Windows certificates

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
    • Creates a directory in Program Files

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
    • Creates files in the program directory

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
    • Creates/Modifies COM task schedule object

      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
    • Creates a software uninstall entry

      • ALERTqBLACK-AND-WHITE.exe (PID: 3108)
  • INFO

    • Checks supported languages

      • sc.exe (PID: 852)
      • sc.exe (PID: 4016)
      • find.exe (PID: 2368)
      • find.exe (PID: 3364)
      • timeout.exe (PID: 2828)
    • Reads the computer name

      • sc.exe (PID: 852)
      • sc.exe (PID: 4016)
    • Checks Windows Trust Settings

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
    • Reads settings of System Certificates

      • ALERTBLACK-AND-WHITE.exe (PID: 2476)
    • Manual execution by user

      • 7zFM.exe (PID: 2844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

ProductVersion: 1.0.4.049
ProductName: ALERT BLACK-AND-WHITE
OriginalFileName: ALERTBLACK-AND-WHITE.exe
LegalCopyright: ALERT BLACK-AND-WHITE MONKEY(c). All rights reserved
InternalName: ALERTBLACK-AND-WHITE.exe
FileVersion: 1.0.4.049
FileDescription: ALERT BLACK-AND-WHITE
CompanyName: ALERT BLACK-AND-WHITE MONKEY
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.0.4.49
FileVersionNumber: 1.0.4.49
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1942f
UninitializedDataSize: -
InitializedDataSize: 89088
CodeSize: 101888
LinkerVersion: 8
PEType: PE32
TimeStamp: 2012:12:31 01:38:51+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 31-Dec-2012 00:38:51
Detected languages:
  • English - United States
CompanyName: ALERT BLACK-AND-WHITE MONKEY
FileDescription: ALERT BLACK-AND-WHITE
FileVersion: 1.0.4.049
InternalName: ALERTBLACK-AND-WHITE.exe
LegalCopyright: ALERT BLACK-AND-WHITE MONKEY(c). All rights reserved
OriginalFilename: ALERTBLACK-AND-WHITE.exe
ProductName: ALERT BLACK-AND-WHITE
ProductVersion: 1.0.4.049

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0060
Pages in file: 0x0001
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000060

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 31-Dec-2012 00:38:51
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00018DDE
0x00018E00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.67402
.rdata
0x0001A000
0x00003BCA
0x00003C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.71339
.data
0x0001E000
0x00004DEC
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.45098
.rsrc
0x00023000
0x000115A8
0x00011600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.80989

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.01659
1656
Latin 1 / Western European
English - United States
RT_MANIFEST
5
1.43775
52
UNKNOWN
English - United States
RT_STRING
500
3.09294
184
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
MSVCRT.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
14
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
852sc query NPF C:\Windows\system32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1536C:\Windows\system32\cmd.exe /d /c timeout 10 & cmd /d /c rd /s /q "C:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE"C:\Windows\system32\cmd.exeALERTBLACK-AND-WHITE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
32
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2368FIND /C "RUNNING"C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2476"C:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE\ALERTBLACK-AND-WHITE.exe" "C:\Users\admin\AppData\Local\Temp\Wallhack-by-Osama-47_60470.exe" -catC:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE\ALERTBLACK-AND-WHITE.exe
ALERTBLACK-AND-WHITE.exe
User:
admin
Company:
ALERT BLACK-AND-WHITEMONKEY
Integrity Level:
HIGH
Description:
ALERT BLACK-AND-WHITE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\alertblack-and-white\alertblack-and-white.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2828timeout 10 C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
2844"C:\Program Files\7-Zip\7zFM.exe" C:\Program Files\7-Zip\7zFM.exeExplorer.EXE
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
21.03 beta
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\7-zip\7zfm.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
3096"C:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE\ALERTBLACK-AND-WHITE.exe" "C:\Users\admin\AppData\Local\Temp\Wallhack-by-Osama-47_60470.exe"C:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE\ALERTBLACK-AND-WHITE.exeWallhack-by-Osama-47_60470.exe
User:
admin
Company:
ALERT BLACK-AND-WHITEMONKEY
Integrity Level:
MEDIUM
Description:
ALERT BLACK-AND-WHITE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\alertblack-and-white\alertblack-and-white.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3108"C:\Program Files\ALERTBLACK-AND-WHITEmrbMonkey\ALERTqBLACK-AND-WHITE.exe" C:\Program Files\ALERTBLACK-AND-WHITEmrbMonkey\ALERTqBLACK-AND-WHITE.exe
ALERTBLACK-AND-WHITE.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Installer
Exit code:
0
Version:
21.03 beta
Modules
Images
c:\program files\alertblack-and-whitemrbmonkey\alertqblack-and-white.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
3204"C:\Users\admin\AppData\Local\Temp\Wallhack-by-Osama-47_60470.exe" C:\Users\admin\AppData\Local\Temp\Wallhack-by-Osama-47_60470.exe
Explorer.EXE
User:
admin
Company:
ALERT BLACK-AND-WHITE MONKEY
Integrity Level:
MEDIUM
Description:
ALERT BLACK-AND-WHITE
Exit code:
0
Version:
1.0.4.049
Modules
Images
c:\users\admin\appdata\local\temp\wallhack-by-osama-47_60470.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
3364FIND /C "RUNNING"C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\usp10.dll
Total events
7 905
Read events
7 827
Write events
78
Delete events
0

Modification events

(PID) Process:(3204) Wallhack-by-Osama-47_60470.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3204) Wallhack-by-Osama-47_60470.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3204) Wallhack-by-Osama-47_60470.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3204) Wallhack-by-Osama-47_60470.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3096) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3096) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3096) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3096) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2476) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2476) ALERTBLACK-AND-WHITE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
10
Suspicious files
7
Text files
97
Unknown types
6

Dropped files

PID
Process
Filename
Type
3204Wallhack-by-Osama-47_60470.exeC:\Users\admin\AppData\Local\ALERTBLACK-AND-WHITE\ALERTBLACK-AND-WHITE.exeexecutable
MD5:E9D374BA6D719126A1C58081B9816DFD
SHA256:324AA7983E0E3E622371D8CF2C4CA637A0E0423185B5C79BFF7C70CDA5277E5C
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0A7BCDF380DFFCC21AA09E330DA7A6A4
SHA256:B74390918795117359D72F258473FE45F1A54272B3367587FF6CD0AF33B20638
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:D802A4EF2DC6515F04EC421AC816D979
SHA256:827C2D41FA743E902A1F24AD12A6070F38C096DCF275EB2DB8F0D7F51921CE61
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:54E9306F95F32E50CCD58AF19753D929
SHA256:45F94DCEB18A8F738A26DA09CE4558995A4FE02B971882E8116FC9B59813BB72
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\Local\Temp\TarE67.tmpcat
MD5:D99661D0893A52A0700B8AE68457351A
SHA256:BDD5111162A6FA25682E18FA74E37E676D49CAFCB5B7207E98E5256D1EF0D003
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:8C143F58862F94F00B66E852E747B614
SHA256:CE07B7EFC344A70B883B6AF425C7217A618344E446322867C346ACBA6B5D9362
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FBEEAA791A94DCDD9AAD52C3FCC602D0der
MD5:C5BCFEAA011639B528691FCDB366BEEF
SHA256:636F2938A74D474843E8EE84BB5DE14E1671CCE6383B3DCA238598C475F91951
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
2476ALERTBLACK-AND-WHITE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FBEEAA791A94DCDD9AAD52C3FCC602D0binary
MD5:A7A1B0C598DCA6E6AF7079F7B2F51113
SHA256:D7BFF393CC69EF096E9534D4C8507A5069B8C3F276E4ADBD5F3734C17CB85705
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
6
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2476
ALERTBLACK-AND-WHITE.exe
GET
200
23.37.41.57:80
http://x1.c.lencr.org/
NL
der
717 b
whitelisted
2476
ALERTBLACK-AND-WHITE.exe
GET
200
184.25.50.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6673e19e61d5b752
US
compressed
59.9 Kb
whitelisted
2476
ALERTBLACK-AND-WHITE.exe
GET
200
184.25.50.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9b2e1c393cb1c8a
US
compressed
4.70 Kb
whitelisted
2476
ALERTBLACK-AND-WHITE.exe
GET
200
2.16.186.35:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSxfXNrVS8w%2BVncMssPkARMKw%3D%3D
unknown
der
503 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2476
ALERTBLACK-AND-WHITE.exe
104.26.12.39:443
softwaregetcompany.com
Cloudflare Inc
US
unknown
2476
ALERTBLACK-AND-WHITE.exe
184.25.50.8:80
ctldl.windowsupdate.com
Time Warner Cable Internet LLC
US
unknown
2476
ALERTBLACK-AND-WHITE.exe
23.37.41.57:80
x1.c.lencr.org
Akamai Technologies, Inc.
NL
suspicious
2476
ALERTBLACK-AND-WHITE.exe
2.16.186.35:80
r3.o.lencr.org
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
softwaregetcompany.com
  • 104.26.12.39
  • 104.26.13.39
  • 172.67.70.9
unknown
ctldl.windowsupdate.com
  • 184.25.50.8
  • 184.25.51.113
whitelisted
x1.c.lencr.org
  • 23.37.41.57
whitelisted
r3.o.lencr.org
  • 2.16.186.35
  • 2.16.186.8
shared

Threats

No threats detected
No debug info