File name:

PizDec.exe

Full analysis: https://app.any.run/tasks/65e25ec0-e7d9-4ebb-b117-89a1851a7c3f
Verdict: Malicious activity
Analysis date: May 03, 2024, 10:31:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

F179FB92462522ADCEC42BA2F679D9E0

SHA1:

0BC06EA16957413A0B8F1B09DA991CE28DA0AC90

SHA256:

94856A3718B2E959B2BA1DC09A859CE43E4BDEE0672F7D90E51803A6EFDC6907

SSDEEP:

49152:6PIS84YVn0VqPtN1jMg/weQMGlVqTmUPQhFQFkOauGACRNjzKdzsuFyO1MhY0WKK:6Pv8nZ005jzIeQ7VqTxvFra88zwxFyO/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PizDec.exe (PID: 3980)
      • NVIDIA Container.exe (PID: 4052)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 2104)
      • wscript.exe (PID: 2040)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PizDec.exe (PID: 3980)
      • NVIDIA Container.exe (PID: 4052)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
    • Reads security settings of Internet Explorer

      • PizDec.exe (PID: 3980)
      • PizDec.exe (PID: 4068)
      • NVIDIA Container.exe (PID: 4052)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
    • Reads the Internet Settings

      • PizDec.exe (PID: 3980)
      • PizDec.exe (PID: 4068)
      • NVIDIA Container.exe (PID: 4052)
      • wscript.exe (PID: 2104)
      • cmd.exe (PID: 1024)
      • wscript.exe (PID: 2040)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Executing commands from a ".bat" file

      • PizDec.exe (PID: 4068)
      • wscript.exe (PID: 2104)
      • NVIDIA Container.exe (PID: 1980)
    • Starts CMD.EXE for commands execution

      • PizDec.exe (PID: 4068)
      • wscript.exe (PID: 2104)
      • NVIDIA Container.exe (PID: 1980)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 2104)
    • The process executes VB scripts

      • cmd.exe (PID: 1024)
    • Executed via WMI

      • schtasks.exe (PID: 2260)
      • schtasks.exe (PID: 2240)
      • schtasks.exe (PID: 2284)
      • schtasks.exe (PID: 2236)
      • schtasks.exe (PID: 2256)
      • schtasks.exe (PID: 860)
      • schtasks.exe (PID: 1596)
      • schtasks.exe (PID: 2172)
      • schtasks.exe (PID: 1676)
      • schtasks.exe (PID: 2332)
      • schtasks.exe (PID: 2512)
      • schtasks.exe (PID: 2520)
      • schtasks.exe (PID: 1044)
      • schtasks.exe (PID: 956)
      • schtasks.exe (PID: 1964)
      • schtasks.exe (PID: 960)
      • schtasks.exe (PID: 1520)
      • schtasks.exe (PID: 2408)
      • schtasks.exe (PID: 2548)
      • schtasks.exe (PID: 1480)
      • schtasks.exe (PID: 2704)
      • schtasks.exe (PID: 1128)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2764)
      • schtasks.exe (PID: 2664)
      • schtasks.exe (PID: 2716)
      • schtasks.exe (PID: 2420)
      • schtasks.exe (PID: 1612)
      • schtasks.exe (PID: 2380)
      • schtasks.exe (PID: 2436)
      • schtasks.exe (PID: 2416)
      • schtasks.exe (PID: 924)
      • schtasks.exe (PID: 2668)
      • schtasks.exe (PID: 2828)
      • schtasks.exe (PID: 2884)
      • schtasks.exe (PID: 2776)
      • schtasks.exe (PID: 2564)
      • schtasks.exe (PID: 2552)
      • schtasks.exe (PID: 2912)
      • schtasks.exe (PID: 2792)
      • schtasks.exe (PID: 2936)
      • schtasks.exe (PID: 2880)
      • schtasks.exe (PID: 2960)
      • schtasks.exe (PID: 2852)
      • schtasks.exe (PID: 3008)
      • schtasks.exe (PID: 2376)
      • schtasks.exe (PID: 1032)
      • schtasks.exe (PID: 2972)
    • The process creates files with name similar to system file names

      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
    • Application launched itself

      • NVIDIA Container.exe (PID: 2060)
    • Probably delay the execution using 'w32tm.exe'

      • cmd.exe (PID: 3028)
  • INFO

    • Checks supported languages

      • PizDec.exe (PID: 3980)
      • NVIDIA Container.exe (PID: 4052)
      • PizDec.exe (PID: 4068)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Reads the computer name

      • PizDec.exe (PID: 3980)
      • NVIDIA Container.exe (PID: 4052)
      • PizDec.exe (PID: 4068)
      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Create files in a temporary directory

      • PizDec.exe (PID: 3980)
      • PizDec.exe (PID: 4068)
      • NVIDIA Container.exe (PID: 1980)
    • Creates files or folders in the user directory

      • PizDec.exe (PID: 4068)
    • Reads the machine GUID from the registry

      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Reads Environment values

      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Reads product name

      • NVIDIA Container.exe (PID: 2060)
      • NVIDIA Container.exe (PID: 1980)
      • audiodg.exe (PID: 3172)
    • Checks proxy server information

      • wscript.exe (PID: 2040)
    • Creates files in the program directory

      • NVIDIA Container.exe (PID: 1980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:09 09:27:22+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 1465856
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x167d7e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription:
FileVersion: 0.0.0.0
InternalName: PizDec.exe
LegalCopyright:
OriginalFileName: PizDec.exe
ProductVersion: 0.0.0.0
AssemblyVersion: 0.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
97
Monitored processes
60
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start pizdec.exe nvidia container.exe pizdec.exe no specs cmd.exe no specs wscript.exe no specs wscript.exe no specs cmd.exe no specs nvidia container.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs nvidia container.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs w32tm.exe no specs audiodg.exe

Process information

PID
CMD
Path
Indicators
Parent process
860schtasks.exe /create /tn "lsass" /sc ONLOGON /tr "'C:\NVIDIA\DisplayDriver\535.21\lsass.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
924schtasks.exe /create /tn "cmd" /sc ONLOGON /tr "'C:\NVIDIA\DisplayDriver\535.21\cmd.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
956schtasks.exe /create /tn "wininit" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-00A1-0412-0000-0000000FF1CE}-C\wininit.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
960schtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 6 /tr "'C:\MSOCache\All Users\{90140000-001B-0C0A-0000-0000000FF1CE}-C\dllhost.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1024"C:\Windows\system32\cmd.exe" /c "C:\Users\admin\AppData\Local\Temp\3635.tmp\3636.tmp\3637.bat C:\Users\admin\AppData\Local\Temp\PizDec.exe"C:\Windows\System32\cmd.exePizDec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1032schtasks.exe /create /tn "audiodga" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\audiodg.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1044schtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-001B-0C0A-0000-0000000FF1CE}-C\dllhost.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1128schtasks.exe /create /tn "wininitw" /sc MINUTE /mo 6 /tr "'C:\MSOCache\All Users\{90140000-00A1-0412-0000-0000000FF1CE}-C\wininit.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1480schtasks.exe /create /tn "dwmd" /sc MINUTE /mo 12 /tr "'C:\NVIDIA\DisplayDriver\dwm.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1520schtasks.exe /create /tn "ctfmonc" /sc MINUTE /mo 13 /tr "'C:\NVIDIA\DisplayDriver\535.21\ctfmon.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
17 260
Read events
17 181
Write events
75
Delete events
4

Modification events

(PID) Process:(3980) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3980) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3980) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3980) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4052) NVIDIA Container.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4052) NVIDIA Container.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4052) NVIDIA Container.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4052) NVIDIA Container.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4068) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4068) PizDec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
19
Suspicious files
2
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
3980PizDec.exeC:\Users\admin\AppData\Local\Temp\PizDec.exeexecutable
MD5:6520885628FE337B8665099479CC1D4D
SHA256:13D8121844734F49D93956B30FFAB57A220E5FE1345A0BCF89E4DF9CD37AB4F4
4068PizDec.exeC:\Users\admin\AppData\Roaming\6.VBStext
MD5:9E242F8F35222DB7713BF96248C7434C
SHA256:5D173C4F51D33EA28CE3A5AA715BC7140F7BCC82C4B99FAD2A2D3474C476C731
4052NVIDIA Container.exeC:\NVIDIA\DisplayDriver\535.21\mxJne99RtKqQDunPUGdos.battext
MD5:7784D810F5FF3AFA8DF50E360EB90E7D
SHA256:0385DBF94FC27705560CF0B6B04E9A37181DB486EE8F7573C5AD2217D18F4CA0
4068PizDec.exeC:\Users\admin\AppData\Local\Temp\3635.tmp\3636.tmp\3637.battext
MD5:C7DA66CAB92E95DAF435DC74FA5CA35A
SHA256:4AB885B4B48037707771CC63658513D3D82A80CF97FBCDF4558E35BC3ADC2B92
2060NVIDIA Container.exeC:\NVIDIA\DisplayDriver\535.21\6203df4a6bafc7text
MD5:0D8862DE584A05CC7CBA81C133D2FA12
SHA256:CAA0729C49072FF263FF695B5D487215A74DDB8F640A9E1B28485401BB90647A
2060NVIDIA Container.exeC:\NVIDIA\DisplayDriver\535.21\SearchFilterHost.exeexecutable
MD5:4A591F46C87B49A7DE93F5AC771CD4AB
SHA256:B495E22042B08F27B690DA18986EC74D5054A65D05D5CF41FDECD5751482CCBD
2060NVIDIA Container.exeC:\NVIDIA\DisplayDriver\535.21\lsass.exeexecutable
MD5:4A591F46C87B49A7DE93F5AC771CD4AB
SHA256:B495E22042B08F27B690DA18986EC74D5054A65D05D5CF41FDECD5751482CCBD
2060NVIDIA Container.exeC:\MSOCache\All Users\{90140000-0019-040C-0000-0000000FF1CE}-C\96094160f8fe35text
MD5:2BBB9BE0E372535DDF7D894ED2BFAC52
SHA256:626BB83F9913173AA1B9E6CEDB7C5DE0126C23B742D3B6BEFF26F659EF8C99C3
2060NVIDIA Container.exeC:\MSOCache\All Users\{90140000-00BA-0C0A-0000-0000000FF1CE}-C\SearchProtocolHost.exeexecutable
MD5:4A591F46C87B49A7DE93F5AC771CD4AB
SHA256:B495E22042B08F27B690DA18986EC74D5054A65D05D5CF41FDECD5751482CCBD
4052NVIDIA Container.exeC:\NVIDIA\DisplayDriver\535.21\zajaYJ4rqwpmDK2a6yrvwdV.vbevbe
MD5:D7DF2670AD0C6C7B9CC48122F20F086C
SHA256:D3BF5C54DE984DD2D1D779494DEB8A995CC062EB5F25C465D0DE78D99B8CC52B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
3172
audiodg.exe
49.13.77.253:80
narzieo9.beget.tech
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
narzieo9.beget.tech
  • 49.13.77.253
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info