File name:

TopEngineer-Updater.exe (PC-001251)

Full analysis: https://app.any.run/tasks/48cfdcde-99a8-46af-b26a-84fd637ebfbd
Verdict: Malicious activity
Analysis date: May 16, 2023, 03:34:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

C572454CFD832FF1CABB6B6681791CD8

SHA1:

A937F4EEA1001AE479E32BC817FF9CD173ED7DD1

SHA256:

8ADD2DF7A82B2FFE395199A93B5CA9986B5020DAB8100D2B9A112C2AD0387687

SSDEEP:

24576:wNCqKiNQ//5PPhGNV4AiaaOUjqZ39Lu8V3VSL7gP9A:w/Nm/5XhG34AiRO1/tVFSL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FontReg.exe (PID: 3824)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Reads the Internet Settings

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Reads Internet Explorer settings

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Executable content was dropped or overwritten

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Reads settings of System Certificates

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
  • INFO

    • Checks supported languages

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
      • FontReg.exe (PID: 3824)
    • Reads the machine GUID from the registry

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Creates files or folders in the user directory

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Checks proxy server information

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Reads Environment values

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Create files in a temporary directory

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
      • iexplore.exe (PID: 3976)
      • iexplore.exe (PID: 3536)
      • iexplore.exe (PID: 1592)
    • The process checks LSA protection

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Application launched itself

      • iexplore.exe (PID: 3976)
      • iexplore.exe (PID: 3536)
    • Reads the computer name

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
    • Creates files in the program directory

      • TopEngineer-Updater.exe (PC-001251).exe (PID: 1140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

AssemblyVersion: 1.1.3.80
ProductVersion: 1.1.3.80
ProductName: TopEngineer-Updater
OriginalFileName: TopEngineer-Updater.exe
LegalTrademarks: -
LegalCopyright: TopEngineer © 2022
InternalName: TopEngineer-Updater.exe
FileVersion: 1.1.3.80
FileDescription: TopEngineer-Updater
CompanyName: TopEngineer
Comments: Средство обновления программных продуктов TopEngineer
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.1.3.80
FileVersionNumber: 1.1.3.80
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x25e09e
UninitializedDataSize: -
InitializedDataSize: 304640
CodeSize: 2474496
LinkerVersion: 8
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2022:11:16 06:39:43+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 16-Nov-2022 06:39:43
Comments: Средство обновления программных продуктов TopEngineer
CompanyName: TopEngineer
FileDescription: TopEngineer-Updater
FileVersion: 1.1.3.80
InternalName: TopEngineer-Updater.exe
LegalCopyright: TopEngineer © 2022
LegalTrademarks: -
OriginalFilename: TopEngineer-Updater.exe
ProductName: TopEngineer-Updater
ProductVersion: 1.1.3.80
Assembly Version: 1.1.3.80

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 16-Nov-2022 06:39:43
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x0025C0A4
0x0025C200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.85978
.rsrc
0x00260000
0x0004A400
0x0004A400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.17516
.reloc
0x002AC000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.10191

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.65647
1014
UNKNOWN
UNKNOWN
RT_VERSION
2
4.28117
2440
UNKNOWN
UNKNOWN
RT_ICON
3
3.97342
4264
UNKNOWN
UNKNOWN
RT_ICON
4
3.5232
9640
UNKNOWN
UNKNOWN
RT_ICON
5
3.33078
16936
UNKNOWN
UNKNOWN
RT_ICON
6
3.00785
38056
UNKNOWN
UNKNOWN
RT_ICON
7
2.8442
67624
UNKNOWN
UNKNOWN
RT_ICON
8
2.69204
152104
UNKNOWN
UNKNOWN
RT_ICON
9
7.91587
10127
UNKNOWN
UNKNOWN
RT_ICON
32512
3.07075
132
UNKNOWN
UNKNOWN
RT_GROUP_ICON

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start topengineer-updater.exe (pc-001251).exe fontreg.exe no specs iexplore.exe no specs iexplore.exe iexplore.exe iexplore.exe topengineer-updater.exe (pc-001251).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1140"C:\Users\admin\Desktop\TopEngineer-Updater.exe (PC-001251).exe" C:\Users\admin\Desktop\TopEngineer-Updater.exe (PC-001251).exe
explorer.exe
User:
admin
Company:
TopEngineer
Integrity Level:
HIGH
Description:
TopEngineer-Updater
Exit code:
0
Version:
1.1.3.80
Modules
Images
c:\users\admin\desktop\topengineer-updater.exe (pc-001251).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1592"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3536 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1992"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3976 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3536"C:\Program Files\Internet Explorer\iexplore.exe" http://topengineer.ru/u.php?http://topengineer.ru/programms/sreda-kmd-rusC:\Program Files\Internet Explorer\iexplore.exe
TopEngineer-Updater.exe (PC-001251).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3824"C:\Users\admin\AppData\Local\Temp\topEn_fonts\FontReg.exe" /copyC:\Users\admin\AppData\Local\Temp\topEn_fonts\FontReg.exeTopEngineer-Updater.exe (PC-001251).exe
User:
admin
Integrity Level:
HIGH
Description:
Font Registration Utility (x86-32)
Exit code:
0
Version:
2.1.3.0
Modules
Images
c:\users\admin\appdata\local\temp\topen_fonts\fontreg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3948"C:\Users\admin\Desktop\TopEngineer-Updater.exe (PC-001251).exe" C:\Users\admin\Desktop\TopEngineer-Updater.exe (PC-001251).exeexplorer.exe
User:
admin
Company:
TopEngineer
Integrity Level:
MEDIUM
Description:
TopEngineer-Updater
Exit code:
3221226540
Version:
1.1.3.80
Modules
Images
c:\users\admin\desktop\topengineer-updater.exe (pc-001251).exe
c:\windows\system32\ntdll.dll
3976"C:\Program Files\Internet Explorer\iexplore.exe" https://www.youtube.com/watch?v=RlrfLUhoYT8C:\Program Files\Internet Explorer\iexplore.exeTopEngineer-Updater.exe (PC-001251).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
25 301
Read events
25 028
Write events
272
Delete events
1

Modification events

(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(1140) TopEngineer-Updater.exe (PC-001251).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
82E3F17AA787D901
Executable files
32
Suspicious files
75
Text files
230
Unknown types
5

Dropped files

PID
Process
Filename
Type
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Roaming\TopEngineer\Updater\settings.iniini
MD5:22CF84D7621DE2AD019DC1236DAC24C1
SHA256:46B1AD818D06BDC7274BE942D6CB5D039E41F863FB2F7F6B13BD99081BF12768
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\FontReg.exe.tmpexecutable
MD5:CE49C477E640463A4F4173E01B661101
SHA256:0A76DD4304C1C0FB3454E888ACC92F7423C22181035E37B6153519F7D7075C10
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\GOST2304A.ttfbinary
MD5:806AB72E8791436AAA55717D0302A927
SHA256:3814390198D86FE176BFEB3F594749A3ED027260B450F0A4B18684CADC0C8F10
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\Topengineer.ttf.tmpbinary
MD5:D42CDA4BA747E262F87831E90E3F2BD2
SHA256:9D537DB5F1F284F59E9AEE4AF4F2BADB3648B4DBF964E23800E209C0B5B31D0C
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\TeklaStructuresFont.ttf.tmpbinary
MD5:CA90D76EB32857561E719D33DF823055
SHA256:10061CC736ACB576BE63B5BFC581C1903CB9F6B282BA4894914DE70CEC7F9E18
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\FontReg.exeexecutable
MD5:CE49C477E640463A4F4173E01B661101
SHA256:0A76DD4304C1C0FB3454E888ACC92F7423C22181035E37B6153519F7D7075C10
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Roaming\TopEngineer\Updater\TopEngineer-Updater.logtext
MD5:836BAE8A936EF14703900A11D497B456
SHA256:C996A09547BADDD63455CF23537F83DD7C5AF21D2A27AECAE847CE5AB03E49E5
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\Temp\topEn_fonts\GOST2304A.ttf.tmpbinary
MD5:806AB72E8791436AAA55717D0302A927
SHA256:3814390198D86FE176BFEB3F594749A3ED027260B450F0A4B18684CADC0C8F10
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\TopEngineer\TopEngineer-Updater.exe_(_Url_qki5gcmhjq50w02knelb5fpy52izlnl5\1.1.3.80\user.configxml
MD5:CC260C890CF71B559C3FFF45ABA333CD
SHA256:8E6FFF8599C06234D477F5BEA36437852D50C63AF392216FE1D629869E0B5D35
1140TopEngineer-Updater.exe (PC-001251).exeC:\Users\admin\AppData\Local\TopEngineer\TopEngineer-Updater.exe_(_Url_qki5gcmhjq50w02knelb5fpy52izlnl5\1.1.3.80\v2r0mrpa.newcfgxml
MD5:BC21B5A06522A9BF2F1064A4F2E6F9A2
SHA256:A7593609330DAA15EA5773E73D7DCC6DCE8311C0F540AC5BA640FBE7118326AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
61
DNS requests
35
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
302
5.255.255.70:80
http://yandex.ru/
RU
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
301
77.88.55.242:80
http://ya.ru/
RU
whitelisted
1592
iexplore.exe
GET
301
49.13.14.191:80
http://topengineer.ru/programms/sreda-kmd-rus
DE
suspicious
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
200
49.13.14.191:80
http://self.topengineer.ru/version.php
DE
text
25 b
suspicious
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
200
172.217.169.195:80
http://www.google.ru/
US
html
51.6 Kb
whitelisted
1592
iexplore.exe
GET
142.250.185.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
503
49.13.14.191:80
http://topengineer.ru/forum/viewforum.php?f=48&sid=ca3cbf6062e3784418321076fa93093a
DE
html
3.93 Kb
suspicious
1140
TopEngineer-Updater.exe (PC-001251).exe
GET
503
49.13.14.191:80
http://topengineer.ru/forum/viewforum.php?f=48&sid=ca3cbf6062e3784418321076fa93093a
DE
html
3.93 Kb
suspicious
1140
TopEngineer-Updater.exe (PC-001251).exe
POST
404
49.13.14.191:80
http://update.topengineer.ru/server/check_license//12A9866C77DE
DE
html
517 b
suspicious
1592
iexplore.exe
GET
200
49.13.14.191:80
http://topengineer.ru/favicon.ico
DE
image
14.7 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
3416
svchost.exe
239.255.255.250:1900
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
49.13.14.191:80
self.topengineer.ru
Hetzner Online GmbH
DE
suspicious
4
System
192.168.100.255:138
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
77.88.55.242:443
ya.ru
YANDEX LLC
RU
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
77.88.55.242:80
ya.ru
YANDEX LLC
RU
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
5.255.255.70:80
yandex.ru
YANDEX LLC
RU
whitelisted
1140
TopEngineer-Updater.exe (PC-001251).exe
142.251.140.67:80
google.ru
GOOGLE
US
unknown
1140
TopEngineer-Updater.exe (PC-001251).exe
213.180.204.24:443
sso.passport.yandex.ru
YANDEX LLC
RU
whitelisted

DNS requests

Domain
IP
Reputation
self.topengineer.ru
  • 49.13.14.191
suspicious
update.topengineer.ru
  • 49.13.14.191
suspicious
topengineer.ru
  • 49.13.14.191
unknown
ya.ru
  • 77.88.55.242
  • 5.255.255.242
whitelisted
google.ru
  • 142.251.140.67
whitelisted
www.google.ru
  • 172.217.169.195
whitelisted
yandex.ru
  • 5.255.255.70
  • 5.255.255.77
  • 77.88.55.88
  • 77.88.55.60
whitelisted
dzen.ru
  • 62.217.160.2
unknown
sso.passport.yandex.ru
  • 213.180.204.24
whitelisted
www.youtube.com
  • 172.217.18.14
  • 142.250.181.238
  • 216.58.212.174
  • 142.250.185.238
  • 142.250.184.238
  • 142.250.186.78
  • 142.250.184.206
  • 142.250.186.110
  • 172.217.23.110
  • 142.250.186.142
  • 172.217.16.206
  • 142.250.185.206
  • 142.250.186.174
  • 172.217.18.110
  • 172.217.16.142
  • 142.250.186.46
whitelisted

Threats

PID
Process
Class
Message
1140
TopEngineer-Updater.exe (PC-001251).exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
No debug info