File name:

4kvideodownloaderplus_1.3.0_x64_online.exe.7z

Full analysis: https://app.any.run/tasks/95b4e2e1-8b97-4d82-8c49-35798605893b
Verdict: Malicious activity
Analysis date: November 08, 2023, 00:57:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

B4FBBBBCC42EC7CE4860B17712BEDC09

SHA1:

67B165DE7BA6CC330C04C69779D976A3E136FA08

SHA256:

99EE9912DD654A28D5541EB6D17CDF9966DBFB8A9C952EBCD37E8501C80601BB

SSDEEP:

24576:aRrAJ8S1IHstsOmTr468UuNm61LRvVhbL4x9l4KE93uo:aRrAJX1IHstsOmTr468UuNm61dvVhn4Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
  • SUSPICIOUS

    • Searches for installed software

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Reads the Internet Settings

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Starts itself from another location

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3864)
      • VSSVC.exe (PID: 536)
    • Checks Windows Trust Settings

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Reads security settings of Internet Explorer

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Reads settings of System Certificates

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
  • INFO

    • Create files in a temporary directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Checks supported languages

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Reads the machine GUID from the registry

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Reads the computer name

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3440)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
    • Checks proxy server information

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Creates files in the program directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Creates files or folders in the user directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
12
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe 4kvideodownloaderplus_1.3.0_x64_online.exe wmpnscfg.exe no specs vssvc.exe no specs wmpnscfg.exe no specs msiexec.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe 4kvideodownloaderplus_1.3.0_x64_online.exe vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
536C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
684"C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exeWinRAR.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1436"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1988"C:\Users\admin\AppData\Local\Temp\{610F71E0-4105-4745-B71E-740C6062B1D6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{610F71E0-4105-4745-B71E-740C6062B1D6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{610f71e0-4105-4745-b71e-740c6062b1d6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2528"C:\Users\admin\AppData\Local\Temp\{82350F55-3145-47FF-9C8F-DC7F9379FA79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe" -q -burn.elevated BurnPipe.{B1FEBF09-D911-4E3A-9E51-B7A8B564FC87} {125FE115-4EED-4CDB-9FD6-96571A76B860} 1988C:\Users\admin\AppData\Local\Temp\{82350F55-3145-47FF-9C8F-DC7F9379FA79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
HIGH
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{82350f55-3145-47ff-9c8f-dc7f9379fa79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3140"C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exeWinRAR.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3440"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\4kvideodownloaderplus_1.3.0_x64_online.exe.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3516"C:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe" -q -burn.elevated BurnPipe.{4CACEE48-40D3-44C4-96BA-33C33F75F838} {BD36EC45-5965-41A1-844C-89D30710BFA9} 3540C:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
HIGH
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{3305b89f-4395-46ec-a356-ead8e9aeff3e}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3540"C:\Users\admin\AppData\Local\Temp\{887B5C96-8F80-41D6-83A7-A75373A459AA}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{887B5C96-8F80-41D6-83A7-A75373A459AA}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{887b5c96-8f80-41d6-83a7-a75373a459aa}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
16 740
Read events
16 464
Write events
264
Delete events
12

Modification events

(PID) Process:(3440) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
18
Suspicious files
17
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
35164kvideodownloaderplus_1.3.0_x64_online.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exeexecutable
MD5:8AE74FE676CF429DE0233DEA70A93634
SHA256:61B74757886C050CFFB49D1FB087BE299EAD442FD0407B2B5B8C91225072D22E
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\license.rtftext
MD5:98B9690C6BE606696FFA742B54EB1324
SHA256:267C58546C73A33C402B2FD80186E6B161FBD27163C77821BC2ACFE58E8090E5
35164kvideodownloaderplus_1.3.0_x64_online.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:C6832D53A155F4E87CB0E486772394B8
SHA256:20BA2C8E3D9D9A1A29555106F43B1103A6109D26FB45162A54B3B6C71EC9B0D8
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\logo.pngimage
MD5:20986FECAD1C10339E192993E72BBC4E
SHA256:2FAB77079C0E9E6BAE57C3F783936243A6F43550D08CAB690C09B4409D4EA669
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:BDE131A141F61C095C28D3F94C7DCAB9
SHA256:7735FDB9E966F2D5D845D7A8C5F9D77D7F7CC97D4263175CD2B6B8C11796B031
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exeexecutable
MD5:2A47B91EC88A580A8102115DC73BC7FD
SHA256:95826225C042DFA7480607EFE6A8B53AF52BE8BBD4C2E524E924C7D5F1245012
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\wixstdba.dllexecutable
MD5:FE7E0BD53F52E6630473C31299A49FDD
SHA256:2BEA14D70943A42D344E09B7C9DE5562FA7E109946E1C615DD584DA30D06CC80
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\application_msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.53.42.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?97aa1e308c258f62
unknown
compressed
4.66 Kb
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.53.42.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b2e5b6223be8cd2c
unknown
compressed
61.6 Kb
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
184.24.77.54:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOcNuqqzKHf7JIFiI2kDa4qpA%3D%3D
unknown
binary
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
95.101.148.135:80
Akamai International B.V.
NL
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
23.35.228.137:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
92.223.124.62:443
dl.4kdownload.com
G-Core Labs S.A.
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
23.53.42.26:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
184.24.77.54:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1988
4kvideodownloaderplus_1.3.0_x64_online.exe
92.223.124.62:443
dl.4kdownload.com
G-Core Labs S.A.
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.35.228.137
whitelisted
dl.4kdownload.com
  • 92.223.124.62
whitelisted
ctldl.windowsupdate.com
  • 23.53.42.26
  • 23.53.41.250
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
r3.o.lencr.org
  • 184.24.77.54
  • 184.24.77.48
shared

Threats

No threats detected
No debug info