File name:

hidden (1).exe

Full analysis: https://app.any.run/tasks/bc1d8355-3e83-48fa-8850-18504b910103
Verdict: Malicious activity
Analysis date: April 25, 2026, 11:49:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
arch-exec
arch-doc
openssl
tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 10 sections
MD5:

42B7F5E3996640D0013EF8D4DFBF8930

SHA1:

0B3C9771F1011B7145B26A53D1E1DA499A40C745

SHA256:

78AC9CE64413343F365F067C715D9CB67B2F5EC2F25648699EFDF72C142444EE

SSDEEP:

49152:+rBNqAZIFjcc2q9Hb87jIIIW/uF3p5G/tdn1Gt:sB8Vc4b87jaF3p541Gt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • hidden (1).exe (PID: 1296)
    • Process drops python dynamic module

      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 5700)
    • Loads Python modules

      • python.exe (PID: 2960)
      • python.exe (PID: 7840)
      • python.exe (PID: 5700)
      • python.exe (PID: 2312)
      • python.exe (PID: 4692)
      • python.exe (PID: 7392)
      • python.exe (PID: 7312)
    • Executable content was dropped or overwritten

      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 2960)
      • python.exe (PID: 7840)
      • python.exe (PID: 5700)
    • OpenSSL has been detected (YARA)

      • python.exe (PID: 2960)
    • Application launched itself

      • python.exe (PID: 5700)
  • INFO

    • Creates files or folders in the user directory

      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 2960)
      • python.exe (PID: 7840)
      • python.exe (PID: 5700)
      • python.exe (PID: 7312)
      • python.exe (PID: 7392)
    • Checks supported languages

      • python.exe (PID: 2960)
      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 7840)
      • python.exe (PID: 5700)
      • python.exe (PID: 2312)
      • python.exe (PID: 4692)
      • python.exe (PID: 7312)
      • python.exe (PID: 7392)
    • Python executable

      • python.exe (PID: 2960)
      • python.exe (PID: 7840)
      • python.exe (PID: 2312)
      • python.exe (PID: 5700)
      • python.exe (PID: 4692)
      • python.exe (PID: 7392)
      • python.exe (PID: 7312)
    • Reads the computer name

      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 2960)
      • python.exe (PID: 2312)
      • python.exe (PID: 7840)
      • python.exe (PID: 5700)
      • python.exe (PID: 4692)
      • python.exe (PID: 7392)
      • python.exe (PID: 7312)
    • The sample compiled with english language support

      • hidden (1).exe (PID: 1296)
      • python.exe (PID: 2960)
      • python.exe (PID: 5700)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • python.exe (PID: 2960)
      • python.exe (PID: 5700)
      • python.exe (PID: 7840)
    • Create files in a temporary directory

      • python.exe (PID: 2960)
      • python.exe (PID: 5700)
      • python.exe (PID: 2312)
      • python.exe (PID: 7840)
      • python.exe (PID: 4692)
      • python.exe (PID: 7392)
      • python.exe (PID: 7312)
    • Reads the machine GUID from the registry

      • python.exe (PID: 2960)
      • python.exe (PID: 5700)
      • python.exe (PID: 7840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:04:25 11:49:14+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.41
CodeSize: 1148928
InitializedDataSize: 1809920
UninitializedDataSize: 1024
EntryPoint: 0x13e0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start hidden (1).exe python.exe conhost.exe no specs python.exe conhost.exe no specs python.exe conhost.exe no specs python.exe no specs python.exe no specs python.exe no specs python.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Users\admin\AppData\Local\Temp\hidden (1).exe" C:\Users\admin\AppData\Local\Temp\hidden (1).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\hidden (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2312C:\Users\admin\AppData\Roaming\Google\python\python.exe C:\Users\admin\AppData\Roaming\Google\python\Lib\site-packages\pip\_vendor\pyproject_hooks\_in_process\_in_process.py prepare_metadata_for_build_wheel C:\Users\admin\AppData\Local\Temp\tmpvp167urgC:\Users\admin\AppData\Roaming\Google\python\python.exepython.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
2876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepython.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2960"C:\Users\admin\AppData\Roaming\Google\python\python.exe" C:\Users\admin\AppData\Roaming\Google\python\get-pip.pyC:\Users\admin\AppData\Roaming\Google\python\python.exe
hidden (1).exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
4692C:\Users\admin\AppData\Roaming\Google\python\python.exe C:\Users\admin\AppData\Roaming\Google\python\Lib\site-packages\pip\_vendor\pyproject_hooks\_in_process\_in_process.py prepare_metadata_for_build_wheel C:\Users\admin\AppData\Local\Temp\tmpxd_40fj7C:\Users\admin\AppData\Roaming\Google\python\python.exepython.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\version.dll
5700"C:\Users\admin\AppData\Roaming\Google\python\python.exe" -m pip install cryptography fernet requests --no-build-isolationC:\Users\admin\AppData\Roaming\Google\python\python.exe
hidden (1).exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
5876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepython.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7312C:\Users\admin\AppData\Roaming\Google\python\python.exe C:\Users\admin\AppData\Roaming\Google\python\Lib\site-packages\pip\_vendor\pyproject_hooks\_in_process\_in_process.py build_wheel C:\Users\admin\AppData\Local\Temp\tmpoww9s2d2C:\Users\admin\AppData\Roaming\Google\python\python.exepython.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\version.dll
7392C:\Users\admin\AppData\Roaming\Google\python\python.exe C:\Users\admin\AppData\Roaming\Google\python\Lib\site-packages\pip\_vendor\pyproject_hooks\_in_process\_in_process.py build_wheel C:\Users\admin\AppData\Local\Temp\tmpf99v97uiC:\Users\admin\AppData\Roaming\Google\python\python.exepython.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.14.2
Modules
Images
c:\users\admin\appdata\roaming\google\python\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\google\python\python314.dll
c:\users\admin\appdata\roaming\google\python\vcruntime140.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
7752\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepython.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
14 597
Read events
14 597
Write events
0
Delete events
0

Modification events

No data
Executable files
51
Suspicious files
1 692
Text files
1 214
Unknown types
235

Dropped files

PID
Process
Filename
Type
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\pythonw.exeexecutable
MD5:CE34CDA31EAE4589F5B158253DD55F54
SHA256:58B39B6D8DC9F51A94F1A3143E49B7498FB804A101F2B33BAA14BD72D45298F8
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\python-3.14.2-embed-amd64.zipcompressed
MD5:FD5220307B5BE48CEB9092BE8B37598C
SHA256:2ED7CCDA80E9E28AB5877902A9A325586C8A7B7B3E6731D944565BEE082E216C
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\vcruntime140.dllexecutable
MD5:32DA96115C9D783A0769312C0482A62D
SHA256:8B10C53241726B0ACC9F513157E67FCB01C166FEC69E5E38CA6AADA8F9A3619F
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\select.pydexecutable
MD5:6B181CF903A5903F9D8D711A731578D3
SHA256:A0F7B2E00144794E497D11FFFC14E7A968F59E207C702CA7B262B7037065B5BA
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\_elementtree.pydexecutable
MD5:A32C4F3818E9F7454A995798E742F351
SHA256:20086A4DCCBF8BF3DF3894665DD69D8C73CC6BDAB5076AC4481C3983A02C605E
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\python3.dllexecutable
MD5:3740E03E444C539461FEDCF191758226
SHA256:28A395FB2BDA5E71084478ABEA00DA9AB1C1DFEB7C4856C258518BEE9CC146F1
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\python.exeexecutable
MD5:9BD26657353D7441A72F29AB43F1FD37
SHA256:FDA7026477256845AFAB371E354C4D512896665F1761939CB5887D0A9DEC257A
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\python314.dllexecutable
MD5:23B7BEC4BB8CF109503029B50F5EADD5
SHA256:7FFE3AB11342DB03CC18B026F27485C0F74F5BF10F239F1F6573394900596394
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\vcruntime140_1.dllexecutable
MD5:C0C0B4C611561F94798B62EB43097722
SHA256:497A280550443E3E9F89E428E51CB795139CA8944D5DEDD54A7083C00E7164E5
1296hidden (1).exeC:\Users\admin\AppData\Roaming\Google\python\LICENSE.txttext
MD5:F5220A3766378179DBFB98C1EAE9A464
SHA256:935CF13E19F8C31B497D20B05D73623431A226B230C3599BC30FA3348979BC68
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
39
TCP/UDP connections
36
DNS requests
26
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
312 b
whitelisted
1296
hidden (1).exe
GET
200
151.101.64.223:443
https://www.python.org/ftp/python/3.14.2/python-3.14.2-embed-amd64.zip
US
binary
5.00 Mb
unknown
5316
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
3352
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5008
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5008
SIHClient.exe
GET
200
20.165.94.54:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5008
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
5008
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3352
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3352
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
92.123.104.29:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1296
hidden (1).exe
151.101.64.223:443
www.python.org
FASTLY
US
whitelisted
1296
hidden (1).exe
151.101.0.175:443
bootstrap.pypa.io
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 92.123.104.29
  • 92.123.104.26
  • 92.123.104.33
  • 92.123.104.32
  • 92.123.104.24
  • 92.123.104.30
  • 92.123.104.34
  • 92.123.104.37
  • 92.123.104.21
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.250.154.101
  • 142.250.154.139
  • 142.250.154.138
  • 142.250.154.113
  • 142.250.154.102
  • 142.250.154.100
whitelisted
www.python.org
  • 151.101.64.223
  • 151.101.0.223
  • 151.101.128.223
  • 151.101.192.223
whitelisted
bootstrap.pypa.io
  • 151.101.0.175
  • 151.101.64.175
  • 151.101.192.175
  • 151.101.128.175
unknown
pypi.org
  • 151.101.192.223
  • 151.101.128.223
  • 151.101.0.223
  • 151.101.64.223
whitelisted
files.pythonhosted.org
  • 151.101.64.223
  • 151.101.192.223
  • 151.101.128.223
  • 151.101.0.223
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
ET FILE_SHARING File Hosting Service Domain Domain in DNS Lookup (files .pythonhosted .org)
2960
python.exe
Misc activity
ET INFO Observed File Hosting Service Domain (files .pythonhosted .org in TLS SNI)
3352
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7840
python.exe
Misc activity
ET INFO Observed File Hosting Service Domain (files .pythonhosted .org in TLS SNI)
2232
svchost.exe
Misc activity
ET FILE_SHARING File Hosting Service Domain Domain in DNS Lookup (files .pythonhosted .org)
5700
python.exe
Misc activity
ET INFO Observed File Hosting Service Domain (files .pythonhosted .org in TLS SNI)
No debug info