File name:

test.png

Full analysis: https://app.any.run/tasks/46257705-f10b-44b0-9fce-c41719244c0e
Verdict: Malicious activity
Analysis date: June 28, 2025, 18:19:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: image/png
File info: PNG image data, 1280 x 720, 8-bit/color RGBA, non-interlaced
MD5:

E51B8F0DF38085CFB3A4D6317759A652

SHA1:

E57F9F634E789E61A7988D9F2347F12A72215AE5

SHA256:

8C8A3648BE75E2F6A26E40956DE641E62028B755CFBE8B095C9401AE1810C546

SSDEEP:

24576:9BtMda/6ODg6oGThJMH76uX7Jv+v4ZbWW8Jm+3KSGQ:9BtMda//Dg6oGThJq76uXVv84ZbWW8Jl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Cyybot_6_Ultimate.exe (PID: 2876)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
      • Cyybot_6_Ultimate.exe (PID: 8132)
    • Reads security settings of Internet Explorer

      • Cyybot_6_Ultimate.tmp (PID: 2232)
    • Reads the Windows owner or organization settings

      • Cyybot_6_Ultimate.tmp (PID: 7984)
  • INFO

    • Manual execution by a user

      • firefox.exe (PID: 6552)
      • Cyybot_6_Ultimate.exe (PID: 2876)
      • WinRAR.exe (PID: 4012)
    • Application launched itself

      • firefox.exe (PID: 1976)
      • firefox.exe (PID: 6552)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 1976)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 1976)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 1976)
    • The sample compiled with english language support

      • firefox.exe (PID: 1976)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Reads the software policy settings

      • slui.exe (PID: 7604)
    • Checks proxy server information

      • slui.exe (PID: 7604)
    • Create files in a temporary directory

      • Cyybot_6_Ultimate.exe (PID: 2876)
      • Cyybot_6_Ultimate.exe (PID: 8132)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Checks supported languages

      • Cyybot_6_Ultimate.exe (PID: 2876)
      • Cyybot_6_Ultimate.tmp (PID: 2232)
      • Cyybot_6_Ultimate.exe (PID: 8132)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Reads the computer name

      • Cyybot_6_Ultimate.tmp (PID: 2232)
      • Cyybot_6_Ultimate.exe (PID: 8132)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Process checks computer location settings

      • Cyybot_6_Ultimate.tmp (PID: 2232)
    • Compiled with Borland Delphi (YARA)

      • Cyybot_6_Ultimate.exe (PID: 8132)
      • Cyybot_6_Ultimate.exe (PID: 2876)
      • Cyybot_6_Ultimate.tmp (PID: 2232)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Detects InnoSetup installer (YARA)

      • Cyybot_6_Ultimate.exe (PID: 2876)
      • Cyybot_6_Ultimate.tmp (PID: 2232)
      • Cyybot_6_Ultimate.exe (PID: 8132)
      • Cyybot_6_Ultimate.tmp (PID: 7984)
    • Creates files in the program directory

      • Cyybot_6_Ultimate.tmp (PID: 7984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.png | Portable Network Graphics (100)

EXIF

PNG

ImageWidth: 1280
ImageHeight: 720
BitDepth: 8
ColorType: RGB with Alpha
Compression: Deflate/Inflate
Filter: Adaptive
Interlace: Noninterlaced
PixelsPerUnitX: 3780
PixelsPerUnitY: 3780
PixelUnits: meters

XMP

AdsCreated: 2025-06-24
AdsExtId: de0e5cd2-0d45-41a5-b73c-b7802ed2d52e
AdsFbId: 525265914179580
AdsTouchType: 2
ContainsAiGeneratedContent: Yes
Title: Untitled design - 1
Author: 🫣
CreatorTool: Canva (Renderer) doc=DAGrTaGohRg user=UAGrMyeAVnw brand=OXAAM.COM template=

Composite

ImageSize: 1280x720
Megapixels: 0.922
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
28
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start rundll32.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs rundll32.exe no specs winrar.exe no specs cyybot_6_ultimate.exe cyybot_6_ultimate.tmp no specs cyybot_6_ultimate.exe cyybot_6_ultimate.tmp

Process information

PID
CMD
Path
Indicators
Parent process
892"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4044 -prefsLen 44823 -prefMapHandle 4072 -prefMapSize 272997 -jsInitHandle 4076 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4088 -initialChannelId {2f7b1fde-35b0-4c12-8f72-51964ffbdb72} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
1480"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3352 -prefsLen 36996 -prefMapHandle 3356 -prefMapSize 272997 -ipcHandle 3364 -initialChannelId {a9783511-b708-460e-8316-6c5ab7286fb4} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1976"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1984"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5124 -prefsLen 39068 -prefMapHandle 5128 -prefMapSize 272997 -jsInitHandle 5132 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5140 -initialChannelId {3cda2791-b773-4875-8b30-99c00e639656} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2232"C:\Users\admin\AppData\Local\Temp\is-8AR9P.tmp\Cyybot_6_Ultimate.tmp" /SL5="$C033E,188143679,907776,C:\Users\admin\Desktop\Cyybot_6_Ultimate.exe" C:\Users\admin\AppData\Local\Temp\is-8AR9P.tmp\Cyybot_6_Ultimate.tmpCyybot_6_Ultimate.exe
User:
admin
Company:
Emlece Cypher Studios
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8ar9p.tmp\cyybot_6_ultimate.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2404"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6324 -prefsLen 39501 -prefMapHandle 6336 -prefMapSize 272997 -jsInitHandle 6404 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6152 -initialChannelId {1eb638ac-9aa0-4a86-b98b-d03e6c49f8aa} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 15 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
2848"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4836 -prefsLen 44905 -prefMapHandle 4748 -prefMapSize 272997 -ipcHandle 4868 -initialChannelId {e125a45c-3063-441e-84ea-85ae433ffe70} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2876"C:\Users\admin\Desktop\Cyybot_6_Ultimate.exe" C:\Users\admin\Desktop\Cyybot_6_Ultimate.exe
explorer.exe
User:
admin
Company:
Emlece Cypher Studios
Integrity Level:
MEDIUM
Description:
CyyBot 6 Setup
Version:
Modules
Images
c:\users\admin\desktop\cyybot_6_ultimate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
3940"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 2160 -prefsLen 39777 -prefMapHandle 2272 -prefMapSize 272997 -jsInitHandle 2276 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5376 -initialChannelId {6ace0fcf-d278-4733-8823-87533a48e187} -parentPid 1976 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1976" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 16 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
19 675
Read events
19 669
Write events
6
Delete events
0

Modification events

(PID) Process:(5768) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Photo Viewer\Viewer
Operation:writeName:MainWndPos
Value:
6000000033000000A00400007502000000000000
(PID) Process:(1976) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
33
Suspicious files
1 150
Text files
866
Unknown types
2

Dropped files

PID
Process
Filename
Type
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:203FC7E1249E6BE9F4F8FD5AAEA04E10
SHA256:101A45B67FF9A1A6C403238E195461144D6D2DC5912B58AF59FCDC5CD7AB5A10
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:203FC7E1249E6BE9F4F8FD5AAEA04E10
SHA256:101A45B67FF9A1A6C403238E195461144D6D2DC5912B58AF59FCDC5CD7AB5A10
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1976firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:3134ED3F12E4F4F8643DB90043B0FD7B
SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:5EAAF8971C810A037FCCB138D808561D
SHA256:A4962FD20380E301298C4514F2CBA08B668763E542D7F50FF39301DF364A9455
1976firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
60
TCP/UDP connections
190
DNS requests
289
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.5:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4580
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1976
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
1976
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
1976
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/k58
unknown
whitelisted
1976
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/azY
unknown
whitelisted
1976
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/azY
unknown
whitelisted
1976
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/azY
unknown
whitelisted
1976
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/we2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
592
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.5:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4580
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4580
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.216.77.5
  • 23.216.77.31
  • 23.216.77.34
  • 23.216.77.27
  • 23.216.77.28
  • 23.216.77.23
  • 23.216.77.29
  • 23.216.77.21
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 40.126.31.1
  • 40.126.31.3
  • 40.126.31.0
  • 20.190.159.130
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.131
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2200
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2200
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2200
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
No debug info