File name:

Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe

Full analysis: https://app.any.run/tasks/84653540-c0e6-4842-8a28-c29aadf3237d
Verdict: Malicious activity
Analysis date: October 29, 2023, 01:53:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C518D202EDEBDC51E020DE3824F67E04

SHA1:

E70940C74C657F73545CFD24FE07535BC8E73826

SHA256:

A7B5CC4B68F16E7892F6BBC011A046104465D41CE4CD2D550C8E1FB61B2621C5

SSDEEP:

12288:XLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEb:bVP60BM2pMUN9keo+c+zEb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • target.exe (PID: 2488)
      • maintenanceservice_installer.exe (PID: 1012)
      • maintenanceservice_tmp.exe (PID: 2056)
      • setup.exe (PID: 1928)
      • target.exe (PID: 2948)
      • target.exe (PID: 2460)
      • target.tmp (PID: 2620)
      • target.exe (PID: 3752)
      • CptInstall.exe (PID: 2300)
      • msiexec.exe (PID: 560)
    • Application was dropped or rewritten from another process

      • Ninite.exe (PID: 3484)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • maintenanceservice_tmp.exe (PID: 2056)
      • default-browser-agent.exe (PID: 3324)
      • firefox.exe (PID: 2260)
      • firefox.exe (PID: 1860)
      • target.exe (PID: 2948)
      • target.exe (PID: 2460)
      • target.exe (PID: 3752)
    • Loads dropped or rewritten executable

      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • firefox.exe (PID: 2260)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 3484)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Reads settings of System Certificates

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Reads security settings of Internet Explorer

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Checks Windows Trust Settings

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Application launched itself

      • Ninite.exe (PID: 3484)
    • Searches for installed software

      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Reads Mozilla Firefox installation path

      • Ninite.exe (PID: 2980)
    • Adds/modifies Windows certificates

      • Ninite.exe (PID: 3484)
    • Process drops legitimate windows executable

      • target.exe (PID: 2488)
      • setup.exe (PID: 1928)
      • msiexec.exe (PID: 560)
    • Drops 7-zip archiver for unpacking

      • Ninite.exe (PID: 2980)
      • target.exe (PID: 2948)
    • The process drops Mozilla's DLL files

      • target.exe (PID: 2488)
      • setup.exe (PID: 1928)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • target.exe (PID: 3752)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • target.exe (PID: 3752)
    • The process drops C-runtime libraries

      • setup.exe (PID: 1928)
      • target.exe (PID: 2488)
      • msiexec.exe (PID: 560)
    • Loads DLL from Mozilla Firefox

      • setup.exe (PID: 1928)
      • csrss.exe (PID: 384)
      • default-browser-agent.exe (PID: 3324)
    • Creates a software uninstall entry

      • maintenanceservice_tmp.exe (PID: 2056)
      • maintenanceservice_installer.exe (PID: 1012)
    • Starts application with an unusual extension

      • setup.exe (PID: 1928)
    • Creates/Modifies COM task schedule object

      • setup.exe (PID: 1928)
    • Reads the Windows owner or organization settings

      • target.tmp (PID: 2620)
    • Executes as Windows Service

      • CptService.exe (PID: 3756)
  • INFO

    • Reads the computer name

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 3484)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • maintenanceservice_tmp.exe (PID: 2056)
      • default-browser-agent.exe (PID: 3324)
      • target.exe (PID: 2948)
      • target.exe (PID: 3752)
      • target.tmp (PID: 2620)
    • Checks supported languages

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 3484)
      • Ninite.exe (PID: 2980)
      • target.exe (PID: 2488)
      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • maintenanceservice_tmp.exe (PID: 2056)
      • nsCFFE.tmp (PID: 1808)
      • default-browser-agent.exe (PID: 3324)
      • target.exe (PID: 2948)
      • target.exe (PID: 2460)
      • target.exe (PID: 3752)
      • target.tmp (PID: 2620)
    • Checks proxy server information

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Reads the machine GUID from the registry

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
    • Creates files or folders in the user directory

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • setup.exe (PID: 1928)
    • Create files in a temporary directory

      • Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe (PID: 3628)
      • Ninite.exe (PID: 2980)
      • target.exe (PID: 2488)
      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • target.exe (PID: 2460)
      • target.tmp (PID: 2620)
      • target.exe (PID: 3752)
    • Manual execution by a user

      • taskmgr.exe (PID: 2732)
      • WINWORD.EXE (PID: 2448)
      • WindowsAnytimeUpgradeui.exe (PID: 2372)
      • rundll32.exe (PID: 3044)
      • rundll32.exe (PID: 444)
      • rundll32.exe (PID: 3368)
      • explorer.exe (PID: 2736)
      • control.exe (PID: 2580)
    • Creates files in the program directory

      • setup.exe (PID: 1928)
      • maintenanceservice_installer.exe (PID: 1012)
      • target.exe (PID: 2948)
      • target.tmp (PID: 2620)
      • target.exe (PID: 3752)
    • Loads dropped or rewritten executable

      • firefox.exe (PID: 1860)
    • Application launched itself

      • firefox.exe (PID: 2260)
      • msiexec.exe (PID: 560)
    • Application was dropped or rewritten from another process

      • target.tmp (PID: 2620)
    • Dropped object may contain TOR URL's

      • msiexec.exe (PID: 560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 02:19:47+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
84
Monitored processes
30
Malicious processes
18
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start ninite 7zip chrome edge firefox net 48 revo installer.exe ninite.exe no specs ninite.exe taskmgr.exe no specs target.exe no specs setup.exe winword.exe no specs nscffe.tmp no specs maintenanceservice_installer.exe no specs maintenanceservice_tmp.exe no specs default-browser-agent.exe no specs firefox.exe no specs csrss.exe no specs firefox.exe no specs target.exe no specs target.exe no specs target.tmp no specs target.exe no specs explorer.exe no specs msiexec.exe no specs msiexec.exe no specs control.exe no specs windowsanytimeupgradeui.exe no specs msiexec.exe no specs zoomoutlookimplugin.exe no specs cptinstall.exe no specs cptservice.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
384%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\csrss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\csrsrv.dll
c:\windows\system32\basesrv.dll
c:\windows\system32\winsrv.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
444"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,Control_RunDLL C:\Windows\System32\main.cpl ,1C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
560C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
1012"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exensCFFE.tmp
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
115.4.0
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
1808"C:\Users\admin\AppData\Local\Temp\nsqBF81.tmp\nsCFFE.tmp" "C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Users\admin\AppData\Local\Temp\nsqBF81.tmp\nsCFFE.tmpsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsqbf81.tmp\nscffe.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
1860"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.4.0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
1928.\setup.exe -msC:\Users\admin\AppData\Local\Temp\7zS8B924CAF\setup.exe
target.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Exit code:
0
Version:
115.4.0
Modules
Images
c:\users\admin\appdata\local\temp\7zs8b924caf\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
2056"C:\Program Files\Mozilla Maintenance Service\maintenanceservice_tmp.exe" installC:\Program Files\Mozilla Maintenance Service\maintenanceservice_tmp.exemaintenanceservice_installer.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
115.4.0
Modules
Images
c:\program files\mozilla maintenance service\maintenanceservice_tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
2168C:\Windows\system32\MsiExec.exe -Embedding C9D752E105FCA043A856BB85A1D95F24 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2260"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
115.4.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
36 238
Read events
35 885
Write events
194
Delete events
159

Modification events

(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3628) Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3484) Ninite.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3484) Ninite.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3484) Ninite.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
392
Suspicious files
191
Text files
2 872
Unknown types
0

Dropped files

PID
Process
Filename
Type
2980Ninite.exeC:\Users\admin\AppData\Local\Temp\f10c4857-75fd-11ee-b150-12a9866c77de\target.exe_f10c4859-75fd-11ee-b150-12a9866c77de
MD5:
SHA256:
2980Ninite.exeC:\Users\admin\AppData\Local\Temp\f10c4857-75fd-11ee-b150-12a9866c77de\target.exe
MD5:
SHA256:
3628Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:ECD4278C121843AD9625F3B126E457A4
SHA256:FC14D035BCA8E6F14AD6D63B076C1FABB20B6E96E43B011BD7DC0D251A674731
3628Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3628Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:B57EDD9E20EBA23484C4E1B61EA89A98
SHA256:C313F50AFB03B33B5DE37B5471BE81B2A7622D32C116103F08E76C4C7AC7D8CA
3628Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:5E5DA4EDED7497A574D5B433320DC9E1
SHA256:89E71EEDDE34009D490D0D2857A3DDC234CBB021D60A581A9B293AF5987D9455
3628Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:C781D9ADB0AC057A7403CC39F1B92833
SHA256:E3D68A9E8748C760BADF61A5696BA972172EAF5E34F7EFD22DF4C0F136B46C27
2980Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5E90A49B7C94ED1B43D2DC2806533186binary
MD5:1D715F4BDA1A3CF70F9CCCB70A20846A
SHA256:2400D354B9C5F87968A52CFE8EACE443A752269CC6405A9B6F8068D07E630787
2980Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2980Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5E90A49B7C94ED1B43D2DC2806533186binary
MD5:35A7A51A6C36CD7DF0B5F1E89467EE74
SHA256:42462EDDE0CB7DD6865F9E7EDCEA05B468659F7EB7392BBF8CDEB73FED17CEC6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
29
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3628
Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe
GET
200
108.138.2.195:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
der
2.02 Kb
unknown
2980
Ninite.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1928
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAbIA3O5BkP2HqFg4r59AwA%3D
unknown
binary
471 b
unknown
2980
Ninite.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?74df863f18601d35
unknown
compressed
61.6 Kb
unknown
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
der
1.39 Kb
unknown
2980
Ninite.exe
GET
200
23.53.40.154:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQ37wcyZxrJgc8qNi5OFHENpA%3D%3D
unknown
binary
503 b
unknown
2980
Ninite.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAQLzyqCxF%2FnlRF7A2AcLO8%3D
unknown
der
471 b
unknown
2980
Ninite.exe
GET
200
23.53.40.154:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQ3%2Bw4qitsXkhP9EeOB%2Bb1%2BsQ%3D%3D
unknown
der
503 b
unknown
2980
Ninite.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D
unknown
binary
471 b
unknown
3628
Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
binary
1.39 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3628
Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe
108.138.2.195:80
o.ss2.us
AMAZON-02
US
unknown
3628
Ninite 7Zip Chrome Edge Firefox NET 48 Revo Installer.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
2980
Ninite.exe
65.9.66.56:443
AMAZON-02
US
unknown
2980
Ninite.exe
34.117.35.28:443
download-installer.cdn.mozilla.net
GOOGLE-CLOUD-PLATFORM
US
unknown
2980
Ninite.exe
209.197.3.8:80
STACKPATH-CDN
US
whitelisted
2980
Ninite.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
2980
Ninite.exe
23.53.40.154:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2980
Ninite.exe
49.12.202.237:443
7-zip.org
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
o.ss2.us
  • 108.138.2.195
  • 108.138.2.173
  • 108.138.2.107
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
download-installer.cdn.mozilla.net
  • 34.117.35.28
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
r3.o.lencr.org
  • 23.53.40.154
  • 23.53.40.161
shared
7-zip.org
  • 49.12.202.237
unknown
www.revouninstaller.com
  • 146.20.152.114
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
netcologne.dl.sourceforge.net
  • 78.35.24.122
unknown

Threats

No threats detected
No debug info