File name:

Ninite 7Zip Chrome Firefox VLC Installer.exe

Full analysis: https://app.any.run/tasks/6787836c-81a2-4136-96ee-a5d80be93ffa
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 13, 2025, 14:14:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

7C609637676D4C34F86121E140A7B9E4

SHA1:

8B29C33359C937EA6EA848298E12830B9133A69B

SHA256:

6C4FE02E904654C041CAF4B9390DFD1DD305E02C5A9C8761C9AD47AC894E9E13

SSDEEP:

12288:lLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEr:5VP60BM2pMUN9keo+c+zEr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6424)
      • Ninite.exe (PID: 6740)
    • Executable content was dropped or overwritten

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Checks Windows Trust Settings

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Application launched itself

      • Ninite.exe (PID: 6424)
    • Searches for installed software

      • Ninite.exe (PID: 6740)
    • Drops 7-zip archiver for unpacking

      • Ninite.exe (PID: 6740)
    • Process requests binary or script from the Internet

      • Ninite.exe (PID: 6740)
    • Potential Corporate Privacy Violation

      • Ninite.exe (PID: 6740)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 128)
  • INFO

    • Reads the computer name

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6424)
      • Ninite.exe (PID: 6740)
    • Checks supported languages

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6424)
      • Ninite.exe (PID: 6740)
      • msiexec.exe (PID: 6032)
      • msiexec.exe (PID: 128)
    • The sample compiled with english language support

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Create files in a temporary directory

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • msiexec.exe (PID: 3420)
      • Ninite.exe (PID: 6740)
    • Reads the machine GUID from the registry

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Checks proxy server information

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Reads the software policy settings

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
    • Creates files or folders in the user directory

      • Ninite 7Zip Chrome Firefox VLC Installer.exe (PID: 6336)
      • Ninite.exe (PID: 6740)
      • msiexec.exe (PID: 128)
    • Process checks computer location settings

      • Ninite.exe (PID: 6424)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ninite 7zip chrome firefox vlc installer.exe ninite.exe no specs ninite.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3420msiexec.exe /i "C:\Users\admin\AppData\Local\Temp\D1A972~1\GoogleChromeStandaloneEnterprise64.msi" /qn /norestart REBOOT=ReallySuppress ALLUSERS=1 NOGOOGLEUPDATEPING=1 /Le "C:\Users\admin\AppData\Local\Temp\D1A972~1\msi_log.txt" C:\Windows\SysWOW64\msiexec.exeNinite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6032C:\Windows\syswow64\MsiExec.exe -Embedding 0EEAD24D143946C59B875811BEEB4F6CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6336"C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Firefox VLC Installer.exe" C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Firefox VLC Installer.exe
explorer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Version:
0,1,1,1183
Modules
Images
c:\users\admin\appdata\local\temp\ninite 7zip chrome firefox vlc installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6424Ninite.exe "9af46778b305bcc0a228e2234f69abd8ee86a763" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Firefox VLC Installer.exe"C:\Users\admin\AppData\Local\Temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\Ninite.exeNinite 7Zip Chrome Firefox VLC Installer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Version:
0,1,1,1482
Modules
Images
c:\users\admin\appdata\local\temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6740"C:\Users\admin\AppData\Local\Temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\Ninite.exe" "9af46778b305bcc0a228e2234f69abd8ee86a763" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Firefox VLC Installer.exe" /relaunchC:\Users\admin\AppData\Local\Temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\Ninite.exe
Ninite.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
HIGH
Description:
Ninite
Version:
0,1,1,1482
Modules
Images
c:\users\admin\appdata\local\temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
11 534
Read events
11 426
Write events
12
Delete events
96

Modification events

(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
800000009E456AAB217EDB01
(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
DECAF3A7DA81E14C8B003E4A16226C88C32D0FAB94E0299C0A92BDC4515D1957
(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
800000009E456AAB217EDB01
(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
BAE384FFC869698A09DC6CC52D4E381E87CF00C0E0255134A400026A6D7C728E
(PID) Process:(128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\14376d.rbs
Value:
31161889
(PID) Process:(128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\14376d.rbsLow
Value:
(PID) Process:(128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
Operation:writeName:C:\WINDOWS\Installer\2ddc40.msi
Value:
0
Executable files
4
Suspicious files
46
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6740Ninite.exeC:\Users\admin\AppData\Local\Temp\d1a9728c-ea14-11ef-b4ea-18f7786f96ee\GoogleChromeStandaloneEnterprise64.msi_d1a9728e-ea14-11ef-b4ea-18f7786f96ee
MD5:
SHA256:
6740Ninite.exeC:\Users\admin\AppData\Local\Temp\d1a9728c-ea14-11ef-b4ea-18f7786f96ee\GoogleChromeStandaloneEnterprise64.msi
MD5:
SHA256:
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:24CCE91A1241B4C56B4A067784EE75B7
SHA256:5E8C273BE60A7A18CE6E2D202D29869C6A51338CCDE9D4F909ABFB3C8881D56C
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\Local\Temp\ce31b3d0-ea14-11ef-b4ea-18f7786f96ee\Ninite.exeexecutable
MD5:2DB961F33492AC4088372BE922BA6140
SHA256:80571DA5E27885171E00C57A3E099367EE1CE932ED9B2BC1CC7E473A54F73D2A
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:05298F6DBDC62DE23CE89C2C7720D850
SHA256:F217F8F507F8FDC7D3A0AE0FD05C336A31C4C01EBB5ECB1C4362BBF11AD02898
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3Dbinary
MD5:6016A6C853C4FBFF840571F1E57E27CE
SHA256:5364FBAB8962D25774B6EC055F55F24F7114475F7284B5E0C18945015F031E6F
128msiexec.exeC:\Windows\Installer\14376a.msi
MD5:
SHA256:
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:5FB8AE305DFD8752116D11B8A2499D93
SHA256:ECECC90A6972C9D9E2182AAB8A6AE5CB0FEE0339AAEB87B0330CBDA15064C1B4
6336Ninite 7Zip Chrome Firefox VLC Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3Dbinary
MD5:400D075D0718167F711E0C9DD3AB9A28
SHA256:90A22BD90AA9F0110E516AD35E97CD3F815AE79E0B8696339726F750E3C6371D
6740Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_89854CA6A0F0936A4D2ECA78845CEA25binary
MD5:B76C39E7734BEE71ACDCD60855DD056E
SHA256:3DFFE59A1029A4C285105267C1C9661F9A8A29E160D3231C7A6E0C1FD798D2C2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
53
DNS requests
30
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11
unknown
whitelisted
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
6740
Ninite.exe
GET
200
142.250.184.227:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6740
Ninite.exe
GET
200
142.250.184.227:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6740
Ninite.exe
GET
200
142.250.184.195:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEBuawmx6rLdhEnKZ5i4hwHY%3D
unknown
whitelisted
4264
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4264
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
184.86.251.30:443
Akamai International B.V.
DE
unknown
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
65.9.66.60:443
ninite.com
AMAZON-02
US
whitelisted
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
18.66.145.213:80
ocsp.rootca1.amazontrust.com
AMAZON-02
US
whitelisted
6336
Ninite 7Zip Chrome Firefox VLC Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
whitelisted
5064
SearchApp.exe
184.86.251.28:443
Akamai International B.V.
DE
unknown
6740
Ninite.exe
65.9.66.60:443
ninite.com
AMAZON-02
US
whitelisted
1076
svchost.exe
2.19.106.8:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5872
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
20.190.160.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
ninite.com
  • 65.9.66.60
  • 65.9.66.107
  • 65.9.66.56
  • 65.9.66.14
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.145.213
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
go.microsoft.com
  • 2.19.106.8
whitelisted
login.live.com
  • 20.190.160.3
  • 20.190.160.17
  • 20.190.160.131
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.138
  • 20.190.160.2
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
dl.google.com
  • 216.58.206.46
whitelisted
c.pki.goog
  • 142.250.184.227
whitelisted
o.pki.goog
  • 142.250.184.195
whitelisted

Threats

PID
Process
Class
Message
6740
Ninite.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
6740
Ninite.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info