File name:

4K Stogram 4904680 Portable Latest.zip

Full analysis: https://app.any.run/tasks/9d1ccdbc-8fcb-41a9-81ef-64f3ec0c65a4
Verdict: Malicious activity
Analysis date: April 06, 2025, 12:56:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
delphi
inno
installer
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

E741562E88D613F418801D2F1532CA7D

SHA1:

17D7364520E887CA6580057FB993CCFB265C3F77

SHA256:

90988D180F917379033337B76321608276ECEB357D417C52C5D01DB3E90D6A52

SSDEEP:

98304:Z6Gavik+f6vxiAphww11+LGWTc64hp4MT5WeR6EnwZJy+FBlfnSRB6U8LaNLAe/0:roLduQyhDSIfko

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2284)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
      • 4K Stogram 4904680 Portable Latest.exe (PID: 7784)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Reads security settings of Internet Explorer

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7700)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Reads the Windows owner or organization settings

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2284)
      • firefox.exe (PID: 1748)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2284)
      • firefox.exe (PID: 1748)
    • Checks supported languages

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7700)
      • 4K Stogram 4904680 Portable Latest.exe (PID: 7784)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Create files in a temporary directory

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
      • 4K Stogram 4904680 Portable Latest.exe (PID: 7784)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Manual execution by a user

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
      • firefox.exe (PID: 4228)
      • firefox.exe (PID: 744)
      • mmc.exe (PID: 5548)
      • mmc.exe (PID: 2088)
    • Reads the computer name

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7700)
      • 4K Stogram 4904680 Portable Latest.exe (PID: 7784)
      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Process checks computer location settings

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7700)
    • Checks proxy server information

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
      • slui.exe (PID: 7880)
    • Creates files or folders in the user directory

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Reads the machine GUID from the registry

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Creates files in the program directory

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Reads the software policy settings

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
      • slui.exe (PID: 7252)
      • slui.exe (PID: 7880)
    • Creates a software uninstall entry

      • 4K Stogram 4904680 Portable Latest.tmp (PID: 7824)
    • Compiled with Borland Delphi (YARA)

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
    • Application launched itself

      • firefox.exe (PID: 2332)
      • firefox.exe (PID: 1748)
      • firefox.exe (PID: 4228)
      • firefox.exe (PID: 5588)
      • firefox.exe (PID: 744)
    • Detects InnoSetup installer (YARA)

      • 4K Stogram 4904680 Portable Latest.exe (PID: 7680)
    • Reads security settings of Internet Explorer

      • mmc.exe (PID: 2088)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:04:06 12:35:46
ZipCRC: 0x7822c66d
ZipCompressedSize: 1914796
ZipUncompressedSize: 1914796
ZipFileName: 4K Stogram 4904680 Portable Latest.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
35
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe 4k stogram 4904680   portable latest.exe 4k stogram 4904680   portable latest.tmp no specs 4k stogram 4904680   portable latest.exe 4k stogram 4904680   portable latest.tmp firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs mmc.exe no specs mmc.exe

Process information

PID
CMD
Path
Indicators
Parent process
744"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
896"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5112 -childID 4 -isForBrowser -prefsHandle 3936 -prefMapHandle 5088 -prefsLen 29069 -prefMapSize 240426 -jsInitHandle 1288 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {aea7be10-3cdd-4fb7-b12d-cf412116d2de} 1748 "\\.\pipe\gecko-crash-server-pipe.1748" 21372370690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1052"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1904 -parentBuildID 20240213221259 -prefsHandle 1840 -prefMapHandle 1832 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9977af30-3cfa-49ec-a23a-fd49fc59571f} 5588 "\\.\pipe\gecko-crash-server-pipe.5588" 1cb326efd10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
1132"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5356 -childID 6 -isForBrowser -prefsHandle 5224 -prefMapHandle 5220 -prefsLen 29069 -prefMapSize 240426 -jsInitHandle 1288 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3eb29f40-3b3b-4cbe-94ed-64d3c56730e8} 1748 "\\.\pipe\gecko-crash-server-pipe.1748" 2137139f150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1244"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2764 -childID 1 -isForBrowser -prefsHandle 2756 -prefMapHandle 2752 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1528 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {dc0a38c2-efd2-4764-9d4c-2d02801a48d2} 5588 "\\.\pipe\gecko-crash-server-pipe.5588" 1cb373a1f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
1676"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3948 -childID 2 -isForBrowser -prefsHandle 3940 -prefMapHandle 3932 -prefsLen 22416 -prefMapSize 240426 -jsInitHandle 1288 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ac65c000-afff-40c2-b477-2cfe4fd1d5c4} 1748 "\\.\pipe\gecko-crash-server-pipe.1748" 2136abcc690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1748"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2088"C:\WINDOWS\system32\mmc.exe" "C:\WINDOWS\system32\taskschd.msc" /sC:\Windows\System32\mmc.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2284"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\4K Stogram 4904680 Portable Latest.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2332"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
Total events
28 493
Read events
28 449
Write events
43
Delete events
1

Modification events

(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\4K Stogram 4904680 Portable Latest.zip
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(2284) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
15
Suspicious files
414
Text files
71
Unknown types
1

Dropped files

PID
Process
Filename
Type
5588firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
77844K Stogram 4904680 Portable Latest.exeC:\Users\admin\AppData\Local\Temp\is-C027L.tmp\4K Stogram 4904680 Portable Latest.tmpexecutable
MD5:3F2A44DF972F7030A544A5B1A23E0A16
SHA256:9F0479E4B42B15626EE905D32FE8398842B529E771E76EB0F6E3487E9C560650
2284WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2284.441\4K Stogram 4904680 Portable Latest.exeexecutable
MD5:D0708E59CEBFD7BC3FF3493F4F8BF827
SHA256:97562611305E73E4F2D708D704D152A28661F5B58305D7A4193C1F1B123DC45D
78244K Stogram 4904680 Portable Latest.tmpC:\Users\admin\AppData\Local\Temp\is-7549C.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
78244K Stogram 4904680 Portable Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
2284WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2284.441\.Storeexecutable
MD5:15596B41DBA42CDCCE4F677FBBC86B6E
SHA256:377ABC9D367E61CB5C4761BF48DCFDF5BCD3822F303E0F972D7F4C8295A2EA79
78244K Stogram 4904680 Portable Latest.tmpC:\Users\admin\AppData\Local\Temp\is-7549C.tmp\idp.dllexecutable
MD5:55C310C0319260D798757557AB3BF636
SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED
76804K Stogram 4904680 Portable Latest.exeC:\Users\admin\AppData\Local\Temp\is-0VG9U.tmp\4K Stogram 4904680 Portable Latest.tmpexecutable
MD5:3F2A44DF972F7030A544A5B1A23E0A16
SHA256:9F0479E4B42B15626EE905D32FE8398842B529E771E76EB0F6E3487E9C560650
78244K Stogram 4904680 Portable Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:E60183A593CF21A7C647591AA135BE5D
SHA256:B4029DD6DD528B07B7B4194E2F2682F6209DE4ABEFA4434A552EB5B532912D4F
78244K Stogram 4904680 Portable Latest.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
68
TCP/UDP connections
175
DNS requests
176
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.31:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7824
4K Stogram 4904680 Portable Latest.tmp
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
7824
4K Stogram 4904680 Portable Latest.tmp
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
8020
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5588
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5588
firefox.exe
POST
200
184.24.77.80:80
http://r10.o.lencr.org/
unknown
whitelisted
5588
firefox.exe
POST
200
184.24.77.53:80
http://r11.o.lencr.org/
unknown
whitelisted
8020
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5588
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/cgo
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.31:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7824
4K Stogram 4904680 Portable Latest.tmp
188.114.97.3:443
wildernesscredit.xyz
CLOUDFLARENET
NL
unknown
7824
4K Stogram 4904680 Portable Latest.tmp
142.250.186.99:80
c.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.31
  • 23.216.77.26
  • 23.216.77.22
  • 23.216.77.30
  • 23.216.77.28
  • 23.216.77.20
  • 23.216.77.21
  • 23.216.77.29
  • 23.216.77.25
whitelisted
google.com
  • 142.250.185.142
whitelisted
client.wns.windows.com
  • 20.7.2.167
  • 20.197.71.89
whitelisted
login.live.com
  • 20.190.160.64
  • 40.126.32.76
  • 20.190.160.131
  • 20.190.160.130
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.14
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
wildernesscredit.xyz
  • 188.114.97.3
  • 188.114.96.3
unknown
c.pki.goog
  • 142.250.186.99
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted

Threats

No threats detected
No debug info