File name:

Request for Quotation (RFQ#196).zip

Full analysis: https://app.any.run/tasks/0ef5467b-a424-4349-8f50-51e2a8114cda
Verdict: Malicious activity
Analysis date: January 21, 2024, 03:09:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D69DC6569B385C0467185D002E252D89

SHA1:

25938A66CCE0078C76A15F351CBD19C8FCC2B081

SHA256:

80239619C4CA44380C6269873A5B6B695585CCFCF278E0F2C72698658A3A6FD8

SSDEEP:

49152:pZL1zufKjTpcSPBeJJTXAlSr1/2ueI1HEafmKIDBsuN3FcTuYx/uEjF5RX:/RzvjTCVAlet2XmHxfmKIPNYx/RX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 128)
      • passfab-for-rar.exe (PID: 2364)
      • passfab-for-rar.exe (PID: 2880)
      • passfab-for-rar.tmp (PID: 3036)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 128)
    • Executable content was dropped or overwritten

      • passfab-for-rar.exe (PID: 2364)
      • passfab-for-rar.exe (PID: 2880)
      • passfab-for-rar.tmp (PID: 3036)
    • Reads the Windows owner or organization settings

      • passfab-for-rar.tmp (PID: 3036)
    • Searches for installed software

      • PassFab for RAR.exe (PID: 1028)
    • Drops 7-zip archiver for unpacking

      • passfab-for-rar.tmp (PID: 3036)
    • Reads the Internet Settings

      • PassFab for RAR.exe (PID: 1028)
    • Reads settings of System Certificates

      • PassFab for RAR.exe (PID: 1028)
    • Checks Windows Trust Settings

      • PassFab for RAR.exe (PID: 1028)
    • Reads security settings of Internet Explorer

      • PassFab for RAR.exe (PID: 1028)
    • Checks for external IP

      • PassFab for RAR.exe (PID: 1028)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 1596)
      • passfab-for-rar.exe (PID: 2364)
      • WinRAR.exe (PID: 1816)
      • WinRAR.exe (PID: 2760)
      • passfab-for-rar.exe (PID: 2816)
      • WinRAR.exe (PID: 2440)
      • WinRAR.exe (PID: 1852)
      • passfab-for-rar.exe (PID: 2852)
      • passfab-for-rar.exe (PID: 2880)
      • msedge.exe (PID: 3088)
    • Checks supported languages

      • passfab-for-rar.exe (PID: 2364)
      • passfab-for-rar.tmp (PID: 2844)
      • passfab-for-rar.exe (PID: 2880)
      • passfab-for-rar.tmp (PID: 3036)
      • PassFab for RAR.exe (PID: 1028)
    • Create files in a temporary directory

      • passfab-for-rar.exe (PID: 2364)
      • passfab-for-rar.exe (PID: 2880)
    • Reads the computer name

      • passfab-for-rar.tmp (PID: 3036)
      • PassFab for RAR.exe (PID: 1028)
    • Creates files in the program directory

      • passfab-for-rar.tmp (PID: 3036)
      • PassFab for RAR.exe (PID: 1028)
    • Checks proxy server information

      • PassFab for RAR.exe (PID: 1028)
    • Reads the machine GUID from the registry

      • PassFab for RAR.exe (PID: 1028)
    • Application launched itself

      • msedge.exe (PID: 3216)
      • msedge.exe (PID: 3088)
    • Creates files or folders in the user directory

      • PassFab for RAR.exe (PID: 1028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2021:01:28 09:25:36
ZipCRC: 0x4022fcaa
ZipCompressedSize: 3481287
ZipUncompressedSize: 3514368
ZipFileName: Proforma Invoice and Bank swift-REG.PI-0086547654.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
32
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe no specs PhotoViewer.dll no specs winrar.exe no specs PhotoViewer.dll no specs winrar.exe no specs winrar.exe no specs passfab-for-rar.exe no specs passfab-for-rar.exe passfab-for-rar.tmp no specs passfab-for-rar.exe no specs passfab-for-rar.exe passfab-for-rar.tmp passfab for rar.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
332"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1664 --field-trial-handle=1392,i,13088095921636639689,10143933916324804991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\PassFab for RAR\PassFab for RAR.exe"C:\Program Files\PassFab for RAR\PassFab for RAR.exe
passfab-for-rar.tmp
User:
admin
Company:
PassFab
Integrity Level:
HIGH
Exit code:
0
Version:
9.5.2.2
Modules
Images
c:\program files\passfab for rar\passfab for rar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\passfab for rar\softwarelog.dll
c:\program files\passfab for rar\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
1588"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3584 --field-trial-handle=1392,i,13088095921636639689,10143933916324804991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\your_file.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1816"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\your_file.zip" C:\Users\admin\Desktop\your_file\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\your_file\setup.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1976"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2296 --field-trial-handle=1392,i,13088095921636639689,10143933916324804991,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2364"C:\Users\admin\Desktop\passfab-for-rar.exe" C:\Users\admin\Desktop\passfab-for-rar.exe
explorer.exe
User:
admin
Company:
PassFab, Inc.
Integrity Level:
HIGH
Description:
PassFab for RAR Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\passfab-for-rar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
9 447
Read events
9 292
Write events
149
Delete events
6

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
51
Suspicious files
101
Text files
161
Unknown types
0

Dropped files

PID
Process
Filename
Type
2364passfab-for-rar.exeC:\Users\admin\AppData\Local\Temp\is-MD3N5.tmp\passfab-for-rar.tmpexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
2880passfab-for-rar.exeC:\Users\admin\AppData\Local\Temp\is-55SE2.tmp\passfab-for-rar.tmpexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\AgentSupport.dllexecutable
MD5:E1381BBFB19202F14D42248E9CD8310E
SHA256:5BA9335A99CAC291BE94CCA284183AB7801A666C4EB0E29AEEB9754FC1849481
1816WinRAR.exeC:\Users\admin\Desktop\your_file\setup.zipcompressed
MD5:FCFCD825D1694C2CE3B044531CD8CFCD
SHA256:064607002AAEF52A5B0B062EC6E6A601181BA9543A606A5A2771404D6BD64EA8
1816WinRAR.exeC:\Users\admin\Desktop\your_file\password.jpgimage
MD5:2948C33559CAD0388BFC6207711B1DFE
SHA256:26067F4F52E0BDF1BBBA027A623357B15C126D8D5F39CD93500AE66167C9462D
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\unins000.exeexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-HRDF9.tmpexecutable
MD5:E9B3C02BA1766E9637841E451B73BA2D
SHA256:BA15A5E842842B05659313A3FB2709ECBA719AC7D788326C81F3E03B53F5FB5A
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-0V86M.tmptext
MD5:9E30D0AD0D0B80763F907E80FF3FD407
SHA256:BFA5DDC88B835AA5D54F12AC3E485BAD37B26D223B2C43F310EBE8CB1CB21FCC
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-43Q2Q.tmpexecutable
MD5:E1381BBFB19202F14D42248E9CD8310E
SHA256:5BA9335A99CAC291BE94CCA284183AB7801A666C4EB0E29AEEB9754FC1849481
3036passfab-for-rar.tmpC:\Program Files\PassFab for RAR\is-1UB3M.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
46
DNS requests
63
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1028
PassFab for RAR.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1dca91aa850e3165
GB
compressed
4.66 Kb
unknown
1028
PassFab for RAR.exe
GET
521
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=8B7DFEA9-8F1E-4D30-BE73-5F76513E1DA3&IP=192.168.100.165&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
html
6.72 Kb
unknown
1028
PassFab for RAR.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
US
text
155 b
unknown
1028
PassFab for RAR.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
US
binary
471 b
unknown
1028
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1028
PassFab for RAR.exe
GET
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=5FDC52A6-45A4-4539-A5C5-483B59E586D9&IP=192.168.100.165&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
unknown
1028
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1028
PassFab for RAR.exe
GET
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=CCA51D53-A10B-438B-AD6C-64E85BBBBC5E&IP=192.168.100.165&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
unknown
1028
PassFab for RAR.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1028
PassFab for RAR.exe
POST
200
216.239.32.178:80
http://www.google-analytics.com/collect
US
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1028
PassFab for RAR.exe
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
1028
PassFab for RAR.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
1028
PassFab for RAR.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1028
PassFab for RAR.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1028
PassFab for RAR.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
3088
msedge.exe
239.255.255.250:1900
whitelisted
1028
PassFab for RAR.exe
172.67.179.206:8080
recoverlostpassword.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
recoverlostpassword.com
  • 172.67.179.206
  • 104.21.56.69
whitelisted
cbs.passfab.com
  • 104.18.24.142
  • 104.18.25.142
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted

Threats

PID
Process
Class
Message
1028
PassFab for RAR.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1028
PassFab for RAR.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1028
PassFab for RAR.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1028
PassFab for RAR.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
7 ETPRO signatures available at the full report
No debug info