File name:

NinjaBrowser.exe

Full analysis: https://app.any.run/tasks/cb4f12ef-2831-4a76-b7a2-6b6eebb3b568
Verdict: Malicious activity
Analysis date: October 28, 2024, 15:58:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
phishing
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

DD562C2613F090317EDFC1A7FE3E57FC

SHA1:

6029E1EF2C3CFB753EEFA215FB5B5322C9FC58F3

SHA256:

77D44715BD0EAD14867D5C46DBA2E6E43B8BC303E88DA5309AB60F9828D1C876

SSDEEP:

49152:07HeQqhlQ6NY3fjvb96jM8SaHaSRAK+mWu/G4lq4Gk0+ngrNoqxvS9lcXlzUkqz3:I+QqZ8fjn8SaV6K1G47G0qNv4mXukqhZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 2172)
      • NinjaBrowser.exe (PID: 3524)
    • Uses Task Scheduler to run other applications

      • NinjaBrowser.tmp (PID: 1784)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NinjaBrowser.exe (PID: 6264)
      • NinjaBrowser.exe (PID: 5756)
      • NinjaBrowser.tmp (PID: 1784)
      • installer.exe (PID: 7116)
      • setup.exe (PID: 6340)
      • installer.exe (PID: 3600)
      • setup.exe (PID: 6912)
    • Reads security settings of Internet Explorer

      • NinjaBrowser.tmp (PID: 5332)
    • Reads the Windows owner or organization settings

      • NinjaBrowser.tmp (PID: 1784)
    • Application launched itself

      • setup.exe (PID: 6340)
      • chrmstp.exe (PID: 7872)
      • NinjaBrowser.exe (PID: 6196)
  • INFO

    • Create files in a temporary directory

      • NinjaBrowser.exe (PID: 5756)
      • NinjaBrowser.tmp (PID: 1784)
      • NinjaBrowser.exe (PID: 6264)
    • Checks supported languages

      • NinjaBrowser.tmp (PID: 5332)
      • NinjaBrowser.exe (PID: 5756)
      • NinjaBrowser.tmp (PID: 1784)
      • NinjaBrowser.exe (PID: 6264)
    • Reads the computer name

      • NinjaBrowser.tmp (PID: 5332)
      • NinjaBrowser.tmp (PID: 1784)
    • Process checks computer location settings

      • NinjaBrowser.tmp (PID: 5332)
    • Reads the software policy settings

      • NinjaBrowser.tmp (PID: 1784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 78336
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: NinjaBrowser
FileDescription: NinjaBrowser Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: NinjaBrowser
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
232
Monitored processes
96
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ninjabrowser.exe ninjabrowser.tmp no specs ninjabrowser.exe ninjabrowser.tmp #PHISHING svchost.exe schtasks.exe no specs conhost.exe no specs installer.exe setup.exe setup.exe no specs installer.exe setup.exe ninjabrowser.exe no specs ninjabrowser.exe no specs #PHISHING ninjabrowser.exe ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs chrmstp.exe no specs chrmstp.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs ninjabrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1432"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=4112,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=4256 /prefetch:8C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Exit code:
0
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
1528"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=4084,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=5428 /prefetch:8C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Exit code:
0
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
1528"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=renderer --extension-process --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=55 --field-trial-handle=9552,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=9804 /prefetch:2C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Exit code:
0
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
c:\windows\syswow64\version.dll
1764"C:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\CR_0E8BB.tmp\setup.exe" --system-level --verbose-logging --create-shortcuts=0 --install-level=1C:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\CR_0E8BB.tmp\setup.exesetup.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
HIGH
Description:
Ninja Browser Installer
Exit code:
73
Version:
128.0.6613.122
Modules
Images
c:\users\admin\appdata\local\temp\is-48qqp.tmp\cr_0e8bb.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1784"C:\Users\admin\AppData\Local\Temp\is-D4C1B.tmp\NinjaBrowser.tmp" /SL5="$90232,820736,820736,C:\Users\admin\AppData\Local\Temp\NinjaBrowser.exe" /SPAWNWND=$7021A /NOTIFYWND=$50272 C:\Users\admin\AppData\Local\Temp\is-D4C1B.tmp\NinjaBrowser.tmp
NinjaBrowser.exe
User:
admin
Company:
NinjaBrowser
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d4c1b.tmp\ninjabrowser.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2172C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2196"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3224,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=3244 /prefetch:1C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Exit code:
0
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
c:\windows\syswow64\version.dll
2236"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=4704,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=4992 /prefetch:8C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Exit code:
0
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
2708"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=renderer --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=79 --field-trial-handle=9668,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=8640 /prefetch:1C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exeNinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
LOW
Description:
Ninja Browser
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
c:\windows\syswow64\version.dll
3524"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --field-trial-handle=2192,i,10709461147761543548,5472967797908369332,262144 --variations-seed-version --mojo-platform-channel-handle=2236 /prefetch:3C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\NinjaBrowser.exe
NinjaBrowser.exe
User:
admin
Company:
The Ninja Browser Authors
Integrity Level:
MEDIUM
Description:
Ninja Browser
Version:
128.0.6613.122
Modules
Images
c:\program files (x86)\ninjabrowser\ninjabrowser\application\ninjabrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\program files (x86)\ninjabrowser\ninjabrowser\application\128.0.6613.122\chrome_elf.dll
Total events
6 106
Read events
5 937
Write events
148
Delete events
21

Modification events

(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
19
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
25
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
39
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
46
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
53
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:InstallerProgress
Value:
59
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\128.0.6613.122\Installer\setup.exe
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NinjaBrowser
Operation:writeName:UninstallArguments
Value:
--uninstall --system-level
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NinjaBrowser NinjaBrowser
Operation:writeName:DisplayName
Value:
Ninja Browser
(PID) Process:(6340) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NinjaBrowser NinjaBrowser
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\128.0.6613.122\Installer\setup.exe" --uninstall --system-level
Executable files
16
Suspicious files
851
Text files
919
Unknown types
6

Dropped files

PID
Process
Filename
Type
1784NinjaBrowser.tmpC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\is-IF9SL.tmp
MD5:
SHA256:
1784NinjaBrowser.tmpC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\installer.exe
MD5:
SHA256:
7116installer.exeC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\CR_0E8BB.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
6340setup.exeC:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\128.0.6613.122\Installer\chrome.7z
MD5:
SHA256:
6264NinjaBrowser.exeC:\Users\admin\AppData\Local\Temp\is-D4C1B.tmp\NinjaBrowser.tmpexecutable
MD5:0C131231D692DDE7B722E97F1CF3D127
SHA256:625E4D9A7715FBBC37F8CFC1D290D20147A9F847067BB1A42D810C114D78E55D
6340setup.exeC:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\chrome_proxy.exeexecutable
MD5:0272D0482CD6FD152720887CC3769485
SHA256:2D738F8A519707C0D031C64F13462A8430A143E90E366D87A6F589D8520DD2AE
7116installer.exeC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\CR_0E8BB.tmp\setup.exeexecutable
MD5:489BADC2E0CE304ADE67AEBA90CA5E3C
SHA256:C0BEDCDD05F3D67370785443077BA671162E884EDD914E8479F1E13FE49D5817
1784NinjaBrowser.tmpC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\is-LB099.tmpexecutable
MD5:DD562C2613F090317EDFC1A7FE3E57FC
SHA256:77D44715BD0EAD14867D5C46DBA2E6E43B8BC303E88DA5309AB60F9828D1C876
3600installer.exeC:\Users\admin\AppData\Local\Temp\is-48QQP.tmp\CR_F8BBB.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
1784NinjaBrowser.tmpC:\Program Files (x86)\NinjaBrowser\2810155918\is-H9FOH.tmpexecutable
MD5:DD562C2613F090317EDFC1A7FE3E57FC
SHA256:77D44715BD0EAD14867D5C46DBA2E6E43B8BC303E88DA5309AB60F9828D1C876
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
96
DNS requests
127
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1552
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.43:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6284
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5236
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5236
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1248
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1784
NinjaBrowser.tmp
152.42.139.18:443
d.ninja-browser.com
US
unknown
4360
SearchApp.exe
104.126.37.177:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1552
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1552
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
d.ninja-browser.com
  • 152.42.139.18
unknown
www.bing.com
  • 104.126.37.177
  • 104.126.37.170
  • 104.126.37.186
  • 104.126.37.161
  • 104.126.37.160
  • 104.126.37.171
  • 104.126.37.185
  • 104.126.37.179
  • 104.126.37.155
  • 2a02:26f0:480:36::212:4008
  • 2a02:26f0:480:36::212:4016
  • 2.23.209.141
  • 2.23.209.177
  • 2.23.209.150
  • 2.23.209.144
  • 2.23.209.158
  • 2.23.209.176
  • 2.23.209.160
  • 2.23.209.149
  • 2.23.209.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.68
  • 40.126.32.74
  • 40.126.32.138
  • 20.190.160.17
whitelisted
th.bing.com
  • 104.126.37.177
  • 104.126.37.176
  • 104.126.37.123
  • 104.126.37.163
  • 104.126.37.186
  • 104.126.37.170
  • 104.126.37.155
  • 104.126.37.171
  • 104.126.37.185
whitelisted
go.microsoft.com
  • 23.52.181.141
whitelisted
crl.microsoft.com
  • 2.16.164.43
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted

Threats

PID
Process
Class
Message
2172
svchost.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing domain by CrossDomain ( .ninja-browser .com)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
3524
NinjaBrowser.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Domain chain identified as Phishing (pageszone)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
3524
NinjaBrowser.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Domain chain identified as Phishing (pageszone)
3524
NinjaBrowser.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Domain chain identified as Phishing (pageszone)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
3524
NinjaBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info