File name:

Adobe Unlicensed Pop-up Blocker - Copy.zip

Full analysis: https://app.any.run/tasks/e93870aa-a540-4a52-ac78-827bb3f248b6
Verdict: Malicious activity
Analysis date: March 29, 2025, 00:59:57
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

49232AA833B2F03E6015D9F9D7E2C64B

SHA1:

48F2B2BEFC199906617C498F51CBA2C7D6287F11

SHA256:

6AA8BDEEBF6B721174CA74FD1A5E2850DBF84787C05CF0C6B993EE7668239D32

SSDEEP:

98304:rIBeE52ytIKOXoeQ11BNAyUpJKe+TT/aQYioj04EeZrpk4pH9j95kBPtLuYCDM0W:T/Q88

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2432)
  • SUSPICIOUS

    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • cmd.exe (PID: 7964)
    • Executing commands from ".cmd" file

      • Start.exe (PID: 7920)
    • Reads security settings of Internet Explorer

      • Start.exe (PID: 7920)
    • Application launched itself

      • Start.exe (PID: 7892)
      • cmd.exe (PID: 6424)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7964)
    • Starts CMD.EXE for commands execution

      • Start.exe (PID: 7920)
      • cmd.exe (PID: 6424)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7964)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7964)
    • Uses NSLOOKUP.EXE to check DNS info

      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 5024)
      • cmd.exe (PID: 7264)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 7264)
      • cmd.exe (PID: 5024)
      • cmd.exe (PID: 7964)
    • Hides command output

      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 7264)
      • cmd.exe (PID: 5024)
    • Process uses IPCONFIG to clear DNS cache

      • cmd.exe (PID: 7964)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 7964)
  • INFO

    • Checks supported languages

      • Start.exe (PID: 7920)
      • Start.exe (PID: 7892)
      • wget.exe (PID: 4024)
      • dnsx.exe (PID: 5728)
    • Reads the computer name

      • Start.exe (PID: 7920)
      • Start.exe (PID: 7892)
      • wget.exe (PID: 4024)
    • Create files in a temporary directory

      • Start.exe (PID: 7892)
      • dnsx.exe (PID: 5728)
    • Manual execution by a user

      • Start.exe (PID: 7892)
      • Taskmgr.exe (PID: 4120)
      • Taskmgr.exe (PID: 6644)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2432)
    • Process checks computer location settings

      • Start.exe (PID: 7920)
    • Reads the machine GUID from the registry

      • dnsx.exe (PID: 5728)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 4120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:03:28 20:59:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Adobe Unlicensed Pop-up Blocker - Copy/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
669
Monitored processes
534
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe no specs rundll32.exe no specs start.exe no specs start.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs ping.exe no specs findstr.exe no specs cmd.exe no specs nslookup.exe findstr.exe no specs cmd.exe no specs nslookup.exe findstr.exe no specs cmd.exe no specs nslookup.exe findstr.exe no specs wget.exe findstr.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs findstr.exe no specs dnsx.exe sort.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs ipconfig.exe no specs netsh.exe no specs taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
456findstr /l /c:",108.138.7.97," C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
456C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68,18.245.60.82,18.245.60.84,18.245.60.93,18.245.60.99,18.66.102.104,18.66.102.110,18.66.102.118,18.66.102.19,18.66.102.27,18.66.102.33,18.66.102.35,18.66.102.55,18.66.102.66,18.66.102.71,18.66.102.75,18.66.102.84,18.66.102.97,18.66.102.99,18.66.112.126,18.66.112.13,18.66.112.32,18.66.112.45,18.66.112.55,18.66.112.7,18.66.112.77,18.66.112.78,18.66.122.104,18.66.122.107,18.66.122.12,18.66.122.122,18.66.122.31,18.66.122.32,18.66.122.49,18.66.122.62,18.66.122.72,18.66.122.73,18.66.122.92,18.66.147.113,18.66.147.12,18.66.147.31,18.66.147.35,3.160.150.100,3.160.150.113,3.160.150.17,3.160.150.2,3.160.150.30,3.160.150.41,3.160.150.65,3.160.150.66,3.160.150.68,3.160.150.82,3.160.150.97,3.160.246.125,3.160.246.62,3.160.246.7,3.160.246.71,3.161.82.11,3.161.82.24,3.161.82.32,3.161.82.38,3.161.82.40,3.161.82.56,3.161.82.58,3.161.82.79,3.161.82.84,3.161.82.87,3.161.82.93,3.161.82.94,3.165.148.111,3.165.148.43,3.165.148.54,3.165.148.91,3.167.227.102,3.167.227.106,3.167.227.109,3.167.227.115,3.167.227.21,3.167.227.60,3.167.227.73,3.167.227.81,52.222.236.116,52.222.236.128,52.222.236.2,52.222.236.25,52.222.236.48,52.222.236.70,52.222.236.97,52.222.236.99,54.230.10.100,54.230.10.108,54.230.10.127,54.230.10.14,54.230.10.15,54.230.10.29,54.230.10.54,54.230.10.61,65.9.66.10,65.9.66.28,65.9.66.5,65.9.66.70,99.86.4.17,99.86.4.25,99.86.4.45,99.86.4.57,99.86.4.71,99.86.4.74,"C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
516findstr /l /c:",18.165.160.123," C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
660nslookup -type=ns ic.adobe.ioC:\Windows\SysWOW64\nslookup.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
nslookup
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
660C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,"C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
672findstr /l /c:",13.32.27.111," C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
672findstr /l /c:",18.245.31.129," C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
672C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68,"C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
736C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,"C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
736C:\WINDOWS\system32\cmd.exe /S /D /c" echo ,108.138.26.27,108.138.26.51,108.138.26.70,108.138.26.72,108.138.7.117,108.138.7.47,108.138.7.8,108.138.7.97,13.224.81.100,13.224.81.101,13.224.81.107,13.224.81.11,13.224.81.122,13.224.81.123,13.224.81.126,13.224.81.128,13.224.81.15,13.224.81.16,13.224.81.19,13.224.81.21,13.224.81.3,13.224.81.34,13.224.81.38,13.224.81.39,13.224.81.41,13.224.81.51,13.224.81.57,13.224.81.68,13.224.81.70,13.224.81.8,13.224.81.81,13.224.81.89,13.224.81.9,13.224.81.92,13.224.81.98,13.224.81.99,13.32.121.18,13.32.121.2,13.32.121.24,13.32.121.34,13.32.121.43,13.32.121.44,13.32.121.55,13.32.121.60,13.32.121.64,13.32.121.83,13.32.121.84,13.32.121.90,13.32.27.106,13.32.27.111,13.32.27.114,13.32.27.128,13.32.27.28,13.32.27.30,13.32.27.49,13.32.27.9,13.32.99.120,13.32.99.124,13.32.99.56,13.32.99.6,13.32.99.68,13.32.99.7,13.32.99.81,13.32.99.99,13.35.58.53,13.35.58.70,13.35.58.73,13.35.58.77,143.204.98.10,143.204.98.103,143.204.98.105,143.204.98.125,143.204.98.128,143.204.98.31,143.204.98.46,143.204.98.96,18.165.160.100,18.165.160.105,18.165.160.110,18.165.160.123,18.165.160.129,18.165.160.13,18.165.160.20,18.165.160.29,18.165.160.41,18.165.160.48,18.165.160.50,18.165.160.58,18.165.160.68,18.165.160.69,18.165.160.70,18.165.160.79,18.165.160.81,18.165.160.92,18.165.160.95,18.172.112.109,18.172.112.123,18.172.112.20,18.172.112.45,18.172.112.73,18.172.112.74,18.172.112.89,18.172.112.97,18.245.31.103,18.245.31.104,18.245.31.112,18.245.31.113,18.245.31.115,18.245.31.121,18.245.31.123,18.245.31.129,18.245.31.18,18.245.31.2,18.245.31.26,18.245.31.32,18.245.31.44,18.245.31.48,18.245.31.51,18.245.31.52,18.245.31.74,18.245.31.78,18.245.31.79,18.245.31.84,18.245.31.92,18.245.31.96,18.245.46.11,18.245.46.112,18.245.46.129,18.245.46.4,18.245.46.41,18.245.46.42,18.245.46.44,18.245.46.66,18.245.60.100,18.245.60.109,18.245.60.16,18.245.60.4,18.245.60.5,18.245.60.55,18.245.60.62,18.245.60.68,18.245.60.82,18.245.60.84,18.245.60.93,18.245.60.99,18.66.102.104,18.66.102.110,18.66.102.118,18.66.102.19,18.66.102.27,18.66.102.33,18.66.102.35,18.66.102.55,18.66.102.66,18.66.102.71,18.66.102.75,18.66.102.84,18.66.102.97,"C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
12 929
Read events
12 919
Write events
9
Delete events
1

Modification events

(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Adobe Unlicensed Pop-up Blocker - Copy.zip
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4120) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:delete valueName:Preferences
Value:
(PID) Process:(4120) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AA043AF67F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AA043AF67F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AA043AF67F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AA043AF67F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000AB043AF67F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028AB043AF67F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050AB043AF67F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AA043AF67F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070AB043AF67F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088AB043AF67F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8AB043AF67F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8AB043AF67F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0AB043AF67F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010AC043AF67F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AA043AF67F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AA043AF67F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040AC043AF67F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068AC043AF67F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090AC043AF67F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8AC043AF67F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8AC043AF67F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8AC043AF67F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028AB043AF67F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AA043AF67F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020AD043AF67F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040AD043AF67F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068AD043AF67F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AA043AF67F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050AB043AF67F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AA043AF67F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070AB043AF67F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088AB043AF67F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8AB043AF67F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8AB043AF67F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AA043AF67F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0AD043AF67F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AE043AF67F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AE043AF67F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AE043AF67F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AE043AF67F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000
Executable files
3
Suspicious files
2
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
2432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\iplist.txttext
MD5:0EDD6149BE8543C5A0020F66FE2FA734
SHA256:1D150CADD49AD8812E8984E8B04278F6DF013194C87FB597F8334688697054F9
2432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\pihole.txttext
MD5:4940F66A06224D7532C364824ABAAFF4
SHA256:5B0CC6A16937571C205A0704DD5AA0B13F4CA29A7E286F51EC551E80257E2EAF
2432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2432.31995\Adobe Unlicensed Pop-up Blocker - Copy\BlockIPs.cmdtext
MD5:D4C60D2D549FB0D94D026E0EB3C1177C
SHA256:991F75A4946FC7A151A5D3434E3540D0F8BBDAA9F9D7558B7562DE1D1FF046D7
5728dnsx.exeC:\Users\admin\AppData\Local\Temp\hm865493207\CURRENTtext
MD5:6159AC332FBA78E3046D9F75EDB5E396
SHA256:179AEE986B08DD1C9B42165766A9F86BE710E30D130C79FF234C4F8FBFB85F76
5728dnsx.exeC:\Users\admin\AppData\Local\Temp\hm865493207\CURRENT.0text
MD5:6159AC332FBA78E3046D9F75EDB5E396
SHA256:179AEE986B08DD1C9B42165766A9F86BE710E30D130C79FF234C4F8FBFB85F76
5728dnsx.exeC:\Users\admin\AppData\Local\Temp\hm865493207\LOGtext
MD5:9F130A67F5CC088816B17E8F623C2E7E
SHA256:E4CB27C252F03D1AA5DF539F6D458D7F0DE689E739B0CBF929C2932026483DB8
3100findstr.exeC:\Users\admin\Desktop\Adobe Unlicensed Pop-up Blocker - Copy\pihole_new.txttext
MD5:4940F66A06224D7532C364824ABAAFF4
SHA256:5B0CC6A16937571C205A0704DD5AA0B13F4CA29A7E286F51EC551E80257E2EAF
5728dnsx.exeC:\Users\admin\AppData\Local\Temp\hm865493207\000001.logbinary
MD5:CB6C5767B8005F418716595EBAABF895
SHA256:43E490CD29BA5613457CEC9E938CA7ECDA1F48A1A2A5177B51BBFC8233B7D7A7
2692sort.exeC:\Users\admin\Desktop\Adobe Unlicensed Pop-up Blocker - Copy\iplist_new.txttext
MD5:04670BB08F43147DDFF945D420518EE4
SHA256:FFEF8CBB1BC3ED53B6CF78443F39B80F924A4363CBC8EEBB41B8C11AE63C8AC6
5728dnsx.exeC:\Users\admin\AppData\Local\Temp\hm865493207\MANIFEST-000000binary
MD5:CBA3CA9834B7BB57A118F54D112359DA
SHA256:135E8BB0B3D297C61E0B989D02D4445D9A16A7D4FFD1C66FCFF7B42E1BCC53AC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
25
DNS requests
1 441
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
184.24.77.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6668
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7196
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6668
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6668
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
184.24.77.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.172.255.216:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 184.24.77.12
  • 184.24.77.37
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.129
  • 20.190.159.128
  • 40.126.31.69
  • 40.126.31.128
  • 20.190.159.130
  • 20.190.159.0
  • 20.190.159.23
whitelisted
client.wns.windows.com
  • 172.172.255.216
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
2.100.168.192.in-addr.arpa
whitelisted
ic.adobe.io
whitelisted
a.dove.isdumb.one
  • 104.21.96.1
  • 104.21.112.1
  • 104.21.48.1
  • 104.21.80.1
  • 104.21.64.1
  • 104.21.32.1
  • 104.21.16.1
unknown

Threats

No threats detected
No debug info