File name:

FIFA 21_00868.exe

Full analysis: https://app.any.run/tasks/f9b1ffbf-c228-4487-88c0-59b488629962
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 03, 2024, 12:57:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BF063C97747FC43DBD0B74CC540913DE

SHA1:

79D9B261A7074442CE2C9F31E6CA6B0A8001062F

SHA256:

AA49D7526627C77BB9C987717C9E84E41A40D1D9DF73459DAA9D9CF64C538534

SSDEEP:

98304:GgzUiM4mKQTB2xjFwnjZyJzpX5Y1UgyxFZVB37f7PHRRkHBmkShNvZnz5nZ8XbcW:7HOx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
    • Creates a writable file in the system directory

      • pmropn.exe (PID: 3576)
    • Actions looks like stealing of personal data

      • pmropn.exe (PID: 3784)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • FIFA 21_00868.exe (PID: 1288)
      • pmropn.exe (PID: 3576)
    • Reads security settings of Internet Explorer

      • FIFA 21_00868.exe (PID: 1288)
      • pmropn.exe (PID: 3576)
    • Reads the Internet Settings

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
      • pmropn.exe (PID: 3784)
    • Adds/modifies Windows certificates

      • FIFA 21_00868.exe (PID: 1288)
      • pmservice.exe (PID: 3756)
      • pmropn.exe (PID: 3576)
    • Checks Windows Trust Settings

      • FIFA 21_00868.exe (PID: 1288)
      • pmropn.exe (PID: 3576)
    • Executable content was dropped or overwritten

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
    • Process requests binary or script from the Internet

      • FIFA 21_00868.exe (PID: 1288)
    • Searches for installed software

      • pmropn.exe (PID: 3576)
      • pmservice.exe (PID: 3756)
      • reg.exe (PID: 3828)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3784)
      • pmropn32.exe (PID: 3684)
      • FIFA 21_00868.exe (PID: 1288)
    • Executes as Windows Service

      • pmservice.exe (PID: 3756)
    • Creates a software uninstall entry

      • pmropn.exe (PID: 3784)
    • Starts CMD.EXE for commands execution

      • pmservice.exe (PID: 3756)
  • INFO

    • Reads the computer name

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
      • pmservice.exe (PID: 3756)
      • pmropn.exe (PID: 3784)
    • Checks proxy server information

      • FIFA 21_00868.exe (PID: 1288)
      • pmropn.exe (PID: 3576)
      • pmropn.exe (PID: 3784)
    • Checks supported languages

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
      • pmservice.exe (PID: 3756)
      • pmropn.exe (PID: 3784)
      • pmropn32.exe (PID: 3684)
    • Reads the machine GUID from the registry

      • FIFA 21_00868.exe (PID: 1288)
      • pmropn.exe (PID: 3576)
      • pmservice.exe (PID: 3756)
      • pmropn.exe (PID: 3784)
    • Creates files or folders in the user directory

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
      • pmropn.exe (PID: 3784)
    • Create files in a temporary directory

      • FIFA 21_00868.exe (PID: 1288)
      • ContentI3.exe (PID: 3388)
    • Creates files in the program directory

      • ContentI3.exe (PID: 3388)
      • pmropn.exe (PID: 3576)
      • pmservice.exe (PID: 3756)
      • pmropn.exe (PID: 3784)
    • Reads Environment values

      • pmropn.exe (PID: 3576)
      • pmropn.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:25 11:50:50+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.22
CodeSize: 4035584
InitializedDataSize: 1672704
UninitializedDataSize: -
EntryPoint: 0x34f7d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fifa 21_00868.exe contenti3.exe pmropn.exe pmservice.exe no specs reg.exe no specs pmropn.exe cmd.exe no specs unsecapp.exe no specs pmropn32.exe no specs pmropn32.exe no specs pmropn32.exe no specs fifa 21_00868.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1264"C:\Users\admin\AppData\Local\Temp\FIFA 21_00868.exe" C:\Users\admin\AppData\Local\Temp\FIFA 21_00868.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\fifa 21_00868.exe
c:\windows\system32\ntdll.dll
1288"C:\Users\admin\AppData\Local\Temp\FIFA 21_00868.exe" C:\Users\admin\AppData\Local\Temp\FIFA 21_00868.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\fifa 21_00868.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2292"C:\PROGRA~1\PREMIE~1\pmropn32.exe" 3784C:\Program Files\PremierOpinion\pmropn32.execmd.exe
User:
SYSTEM
Company:
VoiceFive, Inc.
Integrity Level:
HIGH
Description:
PremierOpinion
Exit code:
3221226540
Version:
1.0.14.10 (Build 14.10)
Modules
Images
c:\program files\premieropinion\pmropn32.exe
c:\windows\system32\ntdll.dll
2856/C C:\PROGRA~1\PREMIE~1\pmropn32.exe 3784C:\Windows\System32\cmd.exepmservice.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2860C:\Windows\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\System32\wbem\unsecapp.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sink to receive asynchronous callbacks for WMI client application
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3276C:\PROGRA~1\PREMIE~1\pmropn32.exe 3784C:\Program Files\PremierOpinion\pmropn32.execmd.exe
User:
SYSTEM
Company:
VoiceFive, Inc.
Integrity Level:
HIGH
Description:
PremierOpinion
Exit code:
3221226540
Version:
1.0.14.10 (Build 14.10)
Modules
Images
c:\program files\premieropinion\pmropn32.exe
c:\windows\system32\ntdll.dll
3388"C:\Users\admin\AppData\Local\Temp\PremierOpinion\ContentI3.exe" -c:1538 -t:InstallUnionC:\Users\admin\AppData\Local\Temp\PremierOpinion\ContentI3.exe
FIFA 21_00868.exe
User:
admin
Company:
VoiceFive Networks, Inc.
Integrity Level:
HIGH
Description:
PremierOpinion Installer
Exit code:
0
Version:
1.0.8.1 (Build 1)
Modules
Images
c:\users\admin\appdata\local\temp\premieropinion\contenti3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3576C:\Program Files\PremierOpinion\pmropn.exe -install -uninst:PremierOpinion -t:InstallUnion -bid:$zewJ6KYQF1VrFSg6DPOPN -o:0C:\Program Files\PremierOpinion\pmropn.exe
ContentI3.exe
User:
admin
Company:
VoiceFive, Inc.
Integrity Level:
HIGH
Description:
PremierOpinion
Exit code:
0
Version:
1.3.340.310 (Build 340.310)
Modules
Images
c:\program files\premieropinion\pmropn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
3684"C:\PROGRA~1\PREMIE~1\pmropn32.exe" 3784C:\Program Files\PremierOpinion\pmropn32.execmd.exe
User:
SYSTEM
Company:
VoiceFive, Inc.
Integrity Level:
HIGH
Description:
PremierOpinion
Exit code:
0
Version:
1.0.14.10 (Build 14.10)
Modules
Images
c:\program files\premieropinion\pmropn32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3756"C:\Program Files\PremierOpinion\pmservice.exe" /serviceC:\Program Files\PremierOpinion\pmservice.exeservices.exe
User:
SYSTEM
Company:
VoiceFive, Inc.
Integrity Level:
SYSTEM
Description:
PremierOpinion
Exit code:
0
Version:
1.1.26.110 (Build 26.110)
Modules
Images
c:\program files\premieropinion\pmservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\userenv.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
Total events
20 720
Read events
20 599
Write events
118
Delete events
3

Modification events

(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1288) FIFA 21_00868.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
Executable files
19
Suspicious files
29
Text files
43
Unknown types
0

Dropped files

PID
Process
Filename
Type
3388ContentI3.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\pmf[1].bin
MD5:
SHA256:
3388ContentI3.exeC:\Users\admin\AppData\Local\Temp\osi107A.tmp
MD5:
SHA256:
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:1BBB371E5B58E821C7C239F40A10CC5E
SHA256:3844EA7761E37AF16DC8F7F04D11285768FAFB1BC4DD48EC9B647A7FBC566E32
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:25298E43560955067891C1FDB08CE83A
SHA256:80CEF386A47C51277D7683EEA6C9C980E714C65EB9947CD26167445583C33F2D
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:EAA8208C83475B7FD6C3BC5706A6141A
SHA256:07B1B976278BBE2B08B48D2C911A879AAA0C11FB1DC18B7A65878D0F4A30B973
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:FBCA16C617894E6813A43DCCFE86FAE4
SHA256:7A3FAF715196B7F990CBF9EB77A419D24BB22E0754EDF9FF363514FFDDC61E82
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1CE5CC1EBA55051EF1051B539B325CAbinary
MD5:2C4F642329075D0FEFBD0963C1837C6F
SHA256:69A4F93AA614E8ED38A1448CBCA080A2B1B992F0D5C86EA8EE96A852FC51B5C7
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:8E3ADA28C9A2945E23B9300A7DF7C978
SHA256:22208F530B6A075908735F930A9F0C7BDC8AB0FC0C63A716AC1A95A963B9EB67
1288FIFA 21_00868.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1CE5CC1EBA55051EF1051B539B325CAbinary
MD5:579B11D1E32A2315A80C61BBEE3113B8
SHA256:6F5496098AE06846F5A0D1E02EB0F2FBC158717F8679DF647DCE560423F07AE4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
63
DNS requests
16
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1288
FIFA 21_00868.exe
GET
304
23.32.238.154:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7013747a3395c37f
unknown
unknown
1288
FIFA 21_00868.exe
POST
404
35.190.60.70:80
http://dlsft.com/callback/geo/
unknown
html
716 b
unknown
1288
FIFA 21_00868.exe
GET
200
172.217.17.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
1288
FIFA 21_00868.exe
GET
200
172.217.17.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
1288
FIFA 21_00868.exe
GET
200
172.217.17.131:80
http://ocsp.pki.goog/s/gts1d4/0keShi7yRCM/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCsv8pCRp4QTwlHpeDlD%2BBJ
unknown
binary
472 b
unknown
1288
FIFA 21_00868.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1288
FIFA 21_00868.exe
GET
200
23.32.238.154:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?dae978e3df742998
unknown
compressed
65.2 Kb
unknown
1288
FIFA 21_00868.exe
GET
200
23.32.238.49:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOevXStTY5a9WyT3pmSp3Z5%2BQ%3D%3D
unknown
binary
503 b
unknown
1288
FIFA 21_00868.exe
POST
200
165.193.78.234:80
http://post.securestudies.com/TapAction.aspx?campaign_id=1538&tpi=InstallUnion&action_id=0
unknown
text
25 b
unknown
3576
pmropn.exe
HEAD
302
165.193.78.250:80
http://www.premieropinion.com/About.aspx
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1288
FIFA 21_00868.exe
35.190.60.70:80
dlsft.com
GOOGLE
US
whitelisted
1288
FIFA 21_00868.exe
35.190.60.70:443
dlsft.com
GOOGLE
US
whitelisted
1288
FIFA 21_00868.exe
23.32.238.154:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1288
FIFA 21_00868.exe
172.217.17.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1288
FIFA 21_00868.exe
163.172.67.175:443
img.programas-gratis.net
Online S.a.s.
FR
unknown
1288
FIFA 21_00868.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
1288
FIFA 21_00868.exe
23.32.238.49:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
dlsft.com
  • 35.190.60.70
unknown
ctldl.windowsupdate.com
  • 23.32.238.154
  • 2.19.198.57
  • 2.19.198.64
  • 23.32.238.161
  • 2.19.198.41
  • 23.32.238.121
  • 23.32.238.113
  • 2.19.198.65
  • 2.19.198.66
whitelisted
ocsp.pki.goog
  • 172.217.17.131
whitelisted
img.programas-gratis.net
  • 163.172.67.175
unknown
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 23.32.238.49
  • 23.32.238.27
  • 184.24.77.56
  • 184.24.77.46
  • 184.24.77.45
  • 184.24.77.80
  • 184.24.77.53
  • 184.24.77.54
  • 184.24.77.55
  • 184.24.77.49
  • 184.24.77.52
shared
dpd.securestudies.com
  • 13.32.121.27
  • 13.32.121.122
  • 13.32.121.51
  • 13.32.121.93
whitelisted
post.securestudies.com
  • 165.193.78.234
malicious
rules.securestudies.com
  • 65.151.140.93
malicious
www.premieropinion.com
  • 165.193.78.250
unknown

Threats

PID
Process
Class
Message
1288
FIFA 21_00868.exe
A Network Trojan was detected
ET MALWARE Possible Malicious Macro DL EXE Feb 2016
1288
FIFA 21_00868.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info