| File name: | Adobe Unlicensed Pop-up Blocker - Copy.zip |
| Full analysis: | https://app.any.run/tasks/e93870aa-a540-4a52-ac78-827bb3f248b6 |
| Verdict: | Malicious activity |
| Analysis date: | March 29, 2025, 00:59:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 49232AA833B2F03E6015D9F9D7E2C64B |
| SHA1: | 48F2B2BEFC199906617C498F51CBA2C7D6287F11 |
| SHA256: | 6AA8BDEEBF6B721174CA74FD1A5E2850DBF84787C05CF0C6B993EE7668239D32 |
| SSDEEP: | 98304:rIBeE52ytIKOXoeQ11BNAyUpJKe+TT/aQYioj04EeZrpk4pH9j95kBPtLuYCDM0W:T/Q88 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:03:28 20:59:20 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Adobe Unlicensed Pop-up Blocker - Copy/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | findstr /l /c:",108.138.7.97," | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 456 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68,18.245.60.82,18.245.60.84,18.245.60.93,18.245.60.99,18.66.102.104,18.66.102.110,18.66.102.118,18.66.102.19,18.66.102.27,18.66.102.33,18.66.102.35,18.66.102.55,18.66.102.66,18.66.102.71,18.66.102.75,18.66.102.84,18.66.102.97,18.66.102.99,18.66.112.126,18.66.112.13,18.66.112.32,18.66.112.45,18.66.112.55,18.66.112.7,18.66.112.77,18.66.112.78,18.66.122.104,18.66.122.107,18.66.122.12,18.66.122.122,18.66.122.31,18.66.122.32,18.66.122.49,18.66.122.62,18.66.122.72,18.66.122.73,18.66.122.92,18.66.147.113,18.66.147.12,18.66.147.31,18.66.147.35,3.160.150.100,3.160.150.113,3.160.150.17,3.160.150.2,3.160.150.30,3.160.150.41,3.160.150.65,3.160.150.66,3.160.150.68,3.160.150.82,3.160.150.97,3.160.246.125,3.160.246.62,3.160.246.7,3.160.246.71,3.161.82.11,3.161.82.24,3.161.82.32,3.161.82.38,3.161.82.40,3.161.82.56,3.161.82.58,3.161.82.79,3.161.82.84,3.161.82.87,3.161.82.93,3.161.82.94,3.165.148.111,3.165.148.43,3.165.148.54,3.165.148.91,3.167.227.102,3.167.227.106,3.167.227.109,3.167.227.115,3.167.227.21,3.167.227.60,3.167.227.73,3.167.227.81,52.222.236.116,52.222.236.128,52.222.236.2,52.222.236.25,52.222.236.48,52.222.236.70,52.222.236.97,52.222.236.99,54.230.10.100,54.230.10.108,54.230.10.127,54.230.10.14,54.230.10.15,54.230.10.29,54.230.10.54,54.230.10.61,65.9.66.10,65.9.66.28,65.9.66.5,65.9.66.70,99.86.4.17,99.86.4.25,99.86.4.45,99.86.4.57,99.86.4.71,99.86.4.74," | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 516 | findstr /l /c:",18.165.160.123," | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 660 | nslookup -type=ns ic.adobe.io | C:\Windows\SysWOW64\nslookup.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: nslookup Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 660 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106," | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 672 | findstr /l /c:",13.32.27.111," | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 672 | findstr /l /c:",18.245.31.129," | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 672 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68," | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 736 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73," | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 736 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68,18.245.60.82,18.245.60.84,18.245.60.93,18.245.60.99,18.66.102.104,18.66.102.110,18.66.102.118,18.66.102.19,18.66.102.27,18.66.102.33,18.66.102.35,18.66.102.55,18.66.102.66,18.66.102.71,18.66.102.75,18.66.102.84,18.66.102.97," | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Adobe Unlicensed Pop-up Blocker - Copy.zip | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2432) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4120) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | delete value | Name: | Preferences |
Value: | |||
| (PID) Process: | (4120) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | write | Name: | Preferences |
Value: 0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AA043AF67F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AA043AF67F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AA043AF67F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AA043AF67F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000AB043AF67F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028AB043AF67F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050AB043AF67F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AA043AF67F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070AB043AF67F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088AB043AF67F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8AB043AF67F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8AB043AF67F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0AB043AF67F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010AC043AF67F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AA043AF67F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AA043AF67F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040AC043AF67F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068AC043AF67F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090AC043AF67F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8AC043AF67F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8AC043AF67F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8AC043AF67F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028AB043AF67F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AA043AF67F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020AD043AF67F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040AD043AF67F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068AD043AF67F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050AB043AF67F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AA043AF67F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070AB043AF67F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088AB043AF67F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8AB043AF67F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8AB043AF67F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AA043AF67F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AE043AF67F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AE043AF67F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AE043AF67F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AE043AF67F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\iplist.txt | text | |
MD5:0EDD6149BE8543C5A0020F66FE2FA734 | SHA256:1D150CADD49AD8812E8984E8B04278F6DF013194C87FB597F8334688697054F9 | |||
| 2432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\pihole.txt | text | |
MD5:4940F66A06224D7532C364824ABAAFF4 | SHA256:5B0CC6A16937571C205A0704DD5AA0B13F4CA29A7E286F51EC551E80257E2EAF | |||
| 2432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\BlockIPs.cmd | text | |
MD5:D4C60D2D549FB0D94D026E0EB3C1177C | SHA256:991F75A4946FC7A151A5D3434E3540D0F8BBDAA9F9D7558B7562DE1D1FF046D7 | |||
| 5728 | dnsx.exe | C:\Users\admin\AppData\Local\Temp\hm865493207\CURRENT | text | |
MD5:6159AC332FBA78E3046D9F75EDB5E396 | SHA256:179AEE986B08DD1C9B42165766A9F86BE710E30D130C79FF234C4F8FBFB85F76 | |||
| 5728 | dnsx.exe | C:\Users\admin\AppData\Local\Temp\hm865493207\CURRENT.0 | text | |
MD5:6159AC332FBA78E3046D9F75EDB5E396 | SHA256:179AEE986B08DD1C9B42165766A9F86BE710E30D130C79FF234C4F8FBFB85F76 | |||
| 5728 | dnsx.exe | C:\Users\admin\AppData\Local\Temp\hm865493207\LOG | text | |
MD5:9F130A67F5CC088816B17E8F623C2E7E | SHA256:E4CB27C252F03D1AA5DF539F6D458D7F0DE689E739B0CBF929C2932026483DB8 | |||
| 3100 | findstr.exe | C:\Users\admin\Desktop\Adobe Unlicensed Pop-up Blocker - Copy\pihole_new.txt | text | |
MD5:4940F66A06224D7532C364824ABAAFF4 | SHA256:5B0CC6A16937571C205A0704DD5AA0B13F4CA29A7E286F51EC551E80257E2EAF | |||
| 5728 | dnsx.exe | C:\Users\admin\AppData\Local\Temp\hm865493207\000001.log | binary | |
MD5:CB6C5767B8005F418716595EBAABF895 | SHA256:43E490CD29BA5613457CEC9E938CA7ECDA1F48A1A2A5177B51BBFC8233B7D7A7 | |||
| 2692 | sort.exe | C:\Users\admin\Desktop\Adobe Unlicensed Pop-up Blocker - Copy\iplist_new.txt | text | |
MD5:04670BB08F43147DDFF945D420518EE4 | SHA256:FFEF8CBB1BC3ED53B6CF78443F39B80F924A4363CBC8EEBB41B8C11AE63C8AC6 | |||
| 5728 | dnsx.exe | C:\Users\admin\AppData\Local\Temp\hm865493207\MANIFEST-000000 | binary | |
MD5:CBA3CA9834B7BB57A118F54D112359DA | SHA256:135E8BB0B3D297C61E0B989D02D4445D9A16A7D4FFD1C66FCFF7B42E1BCC53AC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 184.24.77.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6668 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7196 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6668 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6668 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 184.24.77.12:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
6544 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3216 | svchost.exe | 172.172.255.216:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2112 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
2.100.168.192.in-addr.arpa |
| whitelisted |
ic.adobe.io |
| whitelisted |
a.dove.isdumb.one |
| unknown |