File name:

4kvideodownloaderplus_1.3.0_x64_online.exe.7z

Full analysis: https://app.any.run/tasks/95b4e2e1-8b97-4d82-8c49-35798605893b
Verdict: Malicious activity
Analysis date: November 08, 2023, 00:57:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

B4FBBBBCC42EC7CE4860B17712BEDC09

SHA1:

67B165DE7BA6CC330C04C69779D976A3E136FA08

SHA256:

99EE9912DD654A28D5541EB6D17CDF9966DBFB8A9C952EBCD37E8501C80601BB

SSDEEP:

24576:aRrAJ8S1IHstsOmTr468UuNm61LRvVhbL4x9l4KE93uo:aRrAJX1IHstsOmTr468UuNm61dvVhn4Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
  • SUSPICIOUS

    • Searches for installed software

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Reads the Internet Settings

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Starts itself from another location

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3864)
      • VSSVC.exe (PID: 536)
    • Reads security settings of Internet Explorer

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Checks Windows Trust Settings

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Reads settings of System Certificates

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3440)
    • Checks supported languages

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
    • Reads the computer name

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Reads the machine GUID from the registry

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
      • msiexec.exe (PID: 316)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Create files in a temporary directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3140)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 684)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3668)
      • wmpnscfg.exe (PID: 1436)
    • Creates files in the program directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3516)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 2528)
    • Checks proxy server information

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 1988)
    • Creates files or folders in the user directory

      • 4kvideodownloaderplus_1.3.0_x64_online.exe (PID: 3540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
12
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe 4kvideodownloaderplus_1.3.0_x64_online.exe wmpnscfg.exe no specs vssvc.exe no specs wmpnscfg.exe no specs msiexec.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe no specs 4kvideodownloaderplus_1.3.0_x64_online.exe 4kvideodownloaderplus_1.3.0_x64_online.exe vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
536C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
684"C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exeWinRAR.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1436"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1988"C:\Users\admin\AppData\Local\Temp\{610F71E0-4105-4745-B71E-740C6062B1D6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.22387\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{610F71E0-4105-4745-B71E-740C6062B1D6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{610f71e0-4105-4745-b71e-740c6062b1d6}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2528"C:\Users\admin\AppData\Local\Temp\{82350F55-3145-47FF-9C8F-DC7F9379FA79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe" -q -burn.elevated BurnPipe.{B1FEBF09-D911-4E3A-9E51-B7A8B564FC87} {125FE115-4EED-4CDB-9FD6-96571A76B860} 1988C:\Users\admin\AppData\Local\Temp\{82350F55-3145-47FF-9C8F-DC7F9379FA79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
HIGH
Description:
4K Video Downloader+
Exit code:
0
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{82350f55-3145-47ff-9c8f-dc7f9379fa79}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3140"C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exeWinRAR.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3440"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\4kvideodownloaderplus_1.3.0_x64_online.exe.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3516"C:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe" -q -burn.elevated BurnPipe.{4CACEE48-40D3-44C4-96BA-33C33F75F838} {BD36EC45-5965-41A1-844C-89D30710BFA9} 3540C:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
HIGH
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{3305b89f-4395-46ec-a356-ead8e9aeff3e}\.be\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3540"C:\Users\admin\AppData\Local\Temp\{887B5C96-8F80-41D6-83A7-A75373A459AA}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\Rar$EXb3440.4138\4kvideodownloaderplus_1.3.0_x64_online.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{887B5C96-8F80-41D6-83A7-A75373A459AA}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
4kvideodownloaderplus_1.3.0_x64_online.exe
User:
admin
Company:
Open Media LLC
Integrity Level:
MEDIUM
Description:
4K Video Downloader+
Exit code:
1633
Version:
1.3.0.38
Modules
Images
c:\users\admin\appdata\local\temp\{887b5c96-8f80-41d6-83a7-a75373a459aa}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
16 740
Read events
16 464
Write events
264
Delete events
12

Modification events

(PID) Process:(3440) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
18
Suspicious files
17
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
35164kvideodownloaderplus_1.3.0_x64_online.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\thm.xmlxml
MD5:F234C46082FFCAF1004DA31962709D56
SHA256:1F4AA5D6F28A7FC702538AD36898E0A1B21116900B7B871370F1D4651C165C2F
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\thm.wxlxml
MD5:5D492AF2E8C9B2AB58CA1A10248C726F
SHA256:ACCF0D8BFCEF21F5F80730D90705446FC0253174A484FD73B6523A092224322D
31404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{887B5C96-8F80-41D6-83A7-A75373A459AA}\.cr\4kvideodownloaderplus_1.3.0_x64_online.exeexecutable
MD5:2A47B91EC88A580A8102115DC73BC7FD
SHA256:95826225C042DFA7480607EFE6A8B53AF52BE8BBD4C2E524E924C7D5F1245012
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.be\4kvideodownloaderplus_1.3.0_x64_online.exeexecutable
MD5:2A47B91EC88A580A8102115DC73BC7FD
SHA256:95826225C042DFA7480607EFE6A8B53AF52BE8BBD4C2E524E924C7D5F1245012
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\wixstdba.dllexecutable
MD5:FE7E0BD53F52E6630473C31299A49FDD
SHA256:2BEA14D70943A42D344E09B7C9DE5562FA7E109946E1C615DD584DA30D06CC80
35164kvideodownloaderplus_1.3.0_x64_online.exeC:\ProgramData\Package Cache\{ecc33ed1-4838-4865-9923-2db6b1f8715d}\state.rsmbinary
MD5:4A748A8560E5D241DC71D38496F6A929
SHA256:3BF65754FE7CB38D6E74121B5FE0C795BFAA9EE683E86D52B80C1D01F83E2221
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\license.rtftext
MD5:98B9690C6BE606696FFA742B54EB1324
SHA256:267C58546C73A33C402B2FD80186E6B161FBD27163C77821BC2ACFE58E8090E5
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\.ba\BootstrapperApplicationData.xmlxml
MD5:D200F0B9042705613F83E9B133773D89
SHA256:EF22A63D5EB3467A6D0F023FF6DCC9117E9DD5CEE36563F386E337283DCEFE07
35404kvideodownloaderplus_1.3.0_x64_online.exeC:\Users\admin\AppData\Local\Temp\{3305B89F-4395-46EC-A356-EAD8E9AEFF3E}\application_msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.53.42.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?97aa1e308c258f62
unknown
compressed
4.66 Kb
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
184.24.77.54:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOcNuqqzKHf7JIFiI2kDa4qpA%3D%3D
unknown
binary
503 b
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.53.42.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b2e5b6223be8cd2c
unknown
compressed
61.6 Kb
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
95.101.148.135:80
Akamai International B.V.
NL
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
23.35.228.137:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
92.223.124.62:443
dl.4kdownload.com
G-Core Labs S.A.
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
23.53.42.26:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
3540
4kvideodownloaderplus_1.3.0_x64_online.exe
184.24.77.54:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1988
4kvideodownloaderplus_1.3.0_x64_online.exe
92.223.124.62:443
dl.4kdownload.com
G-Core Labs S.A.
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.35.228.137
whitelisted
dl.4kdownload.com
  • 92.223.124.62
whitelisted
ctldl.windowsupdate.com
  • 23.53.42.26
  • 23.53.41.250
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
r3.o.lencr.org
  • 184.24.77.54
  • 184.24.77.48
shared

Threats

No threats detected
No debug info