URL:

https://crack4windows.com/crack?s=dx-toolbox-portable&id=76598

Full analysis: https://app.any.run/tasks/230c9475-3c2b-469b-89e4-5060222bfd4d
Verdict: Malicious activity
Analysis date: November 05, 2023, 01:16:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

6F71705F7A5C5CD3F9C8CC5E869AB7FDAF7850A2

SHA256:

9485B4D46516674DA60E52227E9A7E3E95D4F792E3B90B0FE026CBB18570AC21

SSDEEP:

3:N8KWD8SmGXWafrWmoMrSTQsn:2KWvxXWFqrgQs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DX Toolbox Portable 6.2.1.exe (PID: 588)
      • DX Toolbox Portable 6.2.1.exe (PID: 1860)
      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
      • 7za.exe (PID: 2532)
    • Uses Task Scheduler to run other applications

      • sitool.exe (PID: 2528)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
    • Drops 7-zip archiver for unpacking

      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 3896)
    • Application launched itself

      • iexplore.exe (PID: 3196)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 1852)
      • iexplore.exe (PID: 3196)
    • Create files in a temporary directory

      • DX Toolbox Portable 6.2.1.exe (PID: 1860)
      • DX Toolbox Portable 6.2.1.exe (PID: 588)
      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
      • 7za.exe (PID: 1836)
      • 7za.exe (PID: 2532)
      • 7za.exe (PID: 2640)
    • Checks supported languages

      • DX Toolbox Portable 6.2.1.exe (PID: 588)
      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
      • wmpnscfg.exe (PID: 3896)
      • DX Toolbox Portable 6.2.1.exe (PID: 1860)
      • DX Toolbox Portable 6.2.1.tmp (PID: 1820)
      • 7za.exe (PID: 1836)
      • 7za.exe (PID: 2532)
      • sitool.exe (PID: 2528)
      • 7za.exe (PID: 2640)
    • Reads the computer name

      • DX Toolbox Portable 6.2.1.tmp (PID: 1820)
      • wmpnscfg.exe (PID: 3896)
      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
      • sitool.exe (PID: 2528)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3896)
      • sitool.exe (PID: 2528)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1852)
    • Creates files or folders in the user directory

      • DX Toolbox Portable 6.2.1.tmp (PID: 1812)
      • sitool.exe (PID: 2528)
    • Reads the Internet Settings

      • explorer.exe (PID: 2412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
19
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs notepad.exe no specs notepad.exe no specs winrar.exe no specs dx toolbox portable 6.2.1.exe no specs dx toolbox portable 6.2.1.tmp no specs dx toolbox portable 6.2.1.exe dx toolbox portable 6.2.1.tmp 7za.exe no specs 7za.exe no specs 7za.exe no specs sitool.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\DX Toolbox Portable_6.2.1_Crack.txtC:\Windows\System32\notepad.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
588"C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exe" /SPAWNWND=$3027E /NOTIFYWND=$502A0 C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exe
DX Toolbox Portable 6.2.1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
157.235
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1852.14038\dx toolbox portable 6.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1628"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\DX Toolbox Portable_6.2.1_Crack.txtC:\Windows\System32\notepad.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1812"C:\Users\admin\AppData\Local\Temp\is-LL8EV.tmp\DX Toolbox Portable 6.2.1.tmp" /SL5="$40280,372163,121344,C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exe" /SPAWNWND=$3027E /NOTIFYWND=$502A0 C:\Users\admin\AppData\Local\Temp\is-LL8EV.tmp\DX Toolbox Portable 6.2.1.tmp
DX Toolbox Portable 6.2.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ll8ev.tmp\dx toolbox portable 6.2.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1820"C:\Users\admin\AppData\Local\Temp\is-GUAR3.tmp\DX Toolbox Portable 6.2.1.tmp" /SL5="$502A0,372163,121344,C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exe" C:\Users\admin\AppData\Local\Temp\is-GUAR3.tmp\DX Toolbox Portable 6.2.1.tmpDX Toolbox Portable 6.2.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-guar3.tmp\dx toolbox portable 6.2.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1836"C:\Users\admin\AppData\Local\Temp\is-S057T.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-S057T.tmp\sub.res" -p"mSR-@sM1tH"C:\Users\admin\AppData\Local\Temp\is-S057T.tmp\7za.exeDX Toolbox Portable 6.2.1.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-s057t.tmp\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1848"C:\Windows\system32\schtasks.exe" /Delete /tn "Microsoft\Windows\Windows Error Reporting\TerminalSysInfo" /fC:\Windows\System32\schtasks.exesitool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\DX Toolbox Portable 6.2.1.zip"C:\Program Files\WinRAR\WinRAR.exeiexplore.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1860"C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1852.14038\DX Toolbox Portable 6.2.1.exeWinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
157.235
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1852.14038\dx toolbox portable 6.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2396"explorer.exe" "C:\Users\admin\Desktop\DX Toolbox Portable 6.2.1"C:\Windows\explorer.exeDX Toolbox Portable 6.2.1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
21 689
Read events
21 508
Write events
178
Delete events
3

Modification events

(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3196) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
6
Suspicious files
33
Text files
89
Unknown types
0

Dropped files

PID
Process
Filename
Type
2900iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:59AE1F431D504ED6175FE1EBF65B54D3
SHA256:9F41973C510F37BFE29B83735920B45F8305D30735D6D0DFE22CAFFCA5B959EB
2900iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:8202A1CD02E7D69597995CABBE881A12
SHA256:58F381C3A0A0ACE6321DA22E40BD44A597BD98B9C9390AB9258426B5CF75A7A5
2900iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:51AD9DCEBA84232B58AF06362633A5CF
SHA256:4A051C9AF654884960B5CDF6E4A612A9D9A1178BEDDC6EA675CEB27EC96312EB
2900iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2900iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:CACAB7596666619DD6A1444DDBBC0F95
SHA256:EF8A3D06031AD3AAAD95C07868D9763F882266C97D7D5398580503799758FAEB
2900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\font-awesome.min[1].csstext
MD5:896A3C827FAEE7A1CE4BFF06119353EE
SHA256:215D1D51EABCF8FA96BEAB4BDD8E27784CA893C680C9212E60BDEA4CA4984E6F
2900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\style[1].csstext
MD5:45057D5CF2DE48072CB6A168D4BD0418
SHA256:121E0A7E530C80775D03CCA8EA60C897022133D0712846D937644CFA68085B09
2900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\jquery-1.5.1.min[1].jstext
MD5:CFDFD16F60F1052C798932182429A13C
SHA256:5CBCF1327E260EB4A3B24E98049CB44A840B8AA883E97D82EF5707E461F031FD
2900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.validate.min[1].jstext
MD5:25F6E41F357AF9720DC9DDC13354120D
SHA256:D41F775199C0EEACD2DDCD2134B0428618193102B523C75DAD2EA3695BB0BF67
2900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.validate.unobtrusive.min[1].jstext
MD5:DE486A6852828DE84E85AA15B792E424
SHA256:8BE4750EE4C973A07CE989BC481E8A1F1E37D7BECE26FA960D5D98C7122E0494
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
56
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2900
iexplore.exe
GET
301
188.114.97.3:80
http://free1app.site/download?id=H02xcSVFzuc&s=C0B24C23
unknown
unknown
2900
iexplore.exe
GET
200
23.53.40.99:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0e999d988f45e6a1
unknown
compressed
4.66 Kb
unknown
2900
iexplore.exe
GET
200
23.53.40.99:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3d3cbb4cde0035c1
unknown
compressed
4.66 Kb
unknown
2900
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2900
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2900
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
2900
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDCjDk6BcP0YRJkTzSsQwBD
unknown
binary
472 b
unknown
1812
DX Toolbox Portable 6.2.1.tmp
GET
200
188.114.97.3:80
http://avkit.org/home/getchannel
unknown
binary
1 b
unknown
3196
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
1812
DX Toolbox Portable 6.2.1.tmp
POST
200
142.250.184.206:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
2900
iexplore.exe
23.53.40.99:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
2900
iexplore.exe
142.250.186.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2900
iexplore.exe
188.114.96.3:443
free1app.site
CLOUDFLARENET
NL
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2900
iexplore.exe
142.250.184.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
3196
iexplore.exe
188.114.96.3:443
free1app.site
CLOUDFLARENET
NL
unknown
2900
iexplore.exe
142.250.13.156:443
stats.g.doubleclick.net
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.53.40.99
  • 23.53.40.113
whitelisted
ocsp.pki.goog
  • 142.250.186.163
whitelisted
www.google-analytics.com
  • 142.250.184.206
whitelisted
stats.g.doubleclick.net
  • 142.250.13.156
  • 142.250.13.157
  • 142.250.13.154
  • 142.250.13.155
whitelisted
www.googletagmanager.com
  • 142.250.186.40
whitelisted
region1.google-analytics.com
  • 216.239.34.36
  • 216.239.32.36
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
  • 23.36.162.84
  • 23.36.162.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

PID
Process
Class
Message
1812
DX Toolbox Portable 6.2.1.tmp
Unknown Traffic
ET HUNTING Suspicious Empty User-Agent
No debug info