File name:

FFlag Pack_37247527.exe

Full analysis: https://app.any.run/tasks/c694287d-a365-4d12-8d9d-f162b187569e
Verdict: Malicious activity
Analysis date: January 07, 2024, 11:35:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

93D16508432C3FF3512EB9DE584F48E6

SHA1:

6ED9FD4D190AFC6C5154730D85CF883FD3AD4D2E

SHA256:

BE5357F63B036DA79D198978CBC5B652EA02B1CCFCB1538352442CDC7F4D5549

SSDEEP:

98304:F7GowcdPyJC8JRlobIlEQBYIXwUOZkj0o14vZGcwhnVx/mp9814L/fKBUe3VBOUu:R/JiB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
      • DownloadHelperTray.exe (PID: 2840)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2688)
    • Reads settings of System Certificates

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
      • DownloadHelperTray.exe (PID: 2840)
    • Reads the Internet Settings

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • setup37247527.exe (PID: 1636)
      • OfferInstaller.exe (PID: 1844)
      • cmd.exe (PID: 980)
      • msiexec.exe (PID: 2748)
      • DownloadHelperTray.exe (PID: 2840)
    • Reads security settings of Internet Explorer

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
    • The process creates files with name similar to system file names

      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2688)
    • Reads the Windows owner or organization settings

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2688)
    • Searches for installed software

      • setup37247527.exe (PID: 1264)
    • Get information on the list of running processes

      • cmd.exe (PID: 2332)
      • cmd.exe (PID: 3016)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2332)
      • cmd.exe (PID: 3016)
    • Executing commands from a ".bat" file

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
    • Starts CMD.EXE for commands execution

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
    • Start notepad (likely ransomware note)

      • FFlag Pack_37247527.exe (PID: 2408)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 2688)
      • setup37247527.exe (PID: 1264)
    • Changes default file association

      • msiexec.exe (PID: 2688)
  • INFO

    • Checks supported languages

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1636)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2688)
      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2748)
      • DownloadHelperTray.exe (PID: 2840)
    • Drops the executable file immediately after the start

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2688)
    • Reads the machine GUID from the registry

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • setup37247527.exe (PID: 1636)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2688)
      • msiexec.exe (PID: 2748)
      • DownloadHelperTray.exe (PID: 2840)
    • Creates files or folders in the user directory

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2688)
      • DownloadHelperTray.exe (PID: 2840)
    • Checks proxy server information

      • FFlag Pack_37247527.exe (PID: 2408)
    • Reads the computer name

      • FFlag Pack_37247527.exe (PID: 2408)
      • setup37247527.exe (PID: 1264)
      • setup37247527.exe (PID: 1636)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2688)
      • msiexec.exe (PID: 2748)
      • DownloadHelperTray.exe (PID: 2840)
    • Reads Environment values

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
      • msiexec.exe (PID: 2748)
      • DownloadHelperTray.exe (PID: 2840)
    • Process drops legitimate windows executable

      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2688)
    • Reads product name

      • setup37247527.exe (PID: 1264)
      • OfferInstaller.exe (PID: 1844)
    • Create files in a temporary directory

      • setup37247527.exe (PID: 1636)
      • OfferInstaller.exe (PID: 1844)
      • setup37247527.exe (PID: 1264)
      • msiexec.exe (PID: 2688)
      • msiexec.exe (PID: 2748)
    • Application launched itself

      • msiexec.exe (PID: 2688)
    • The process drops C-runtime libraries

      • setup37247527.exe (PID: 1264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:21 20:16:16+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.22
CodeSize: 4345344
InitializedDataSize: 5646336
UninitializedDataSize: -
EntryPoint: 0x39649e
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Download Manager
FileVersion: 1
InternalName: Download Manager
LegalCopyright: Download Manager
OriginalFileName: Download Manager
ProductName: Download Manager
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
19
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fflag pack_37247527.exe setup37247527.exe setup37247527.exe no specs offerinstaller.exe cmd.exe no specs tasklist.exe no specs find.exe no specs timeout.exe no specs notepad.exe no specs cmd.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe downloadhelpertray.exe cmd.exe no specs find.exe no specs tasklist.exe no specs timeout.exe no specs fflag pack_37247527.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\FFlag Pack_37247527.exe" C:\Users\admin\AppData\Local\Temp\FFlag Pack_37247527.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Download Manager
Exit code:
3221226540
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\fflag pack_37247527.exe
c:\windows\system32\ntdll.dll
980"C:\Windows\system32\cmd.exe" /C "anyPDF-h20-5.msi" /quietC:\Windows\System32\cmd.exeOfferInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1028find /I "1844"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1264C:\Users\admin\AppData\Local\setup37247527.exe hhwnd=196904 hreturntoinstaller hextras=id:d12f7fcb4ca6ce8-DE-errorC:\Users\admin\AppData\Local\setup37247527.exe
FFlag Pack_37247527.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup37247527.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1636C:\Users\admin\AppData\Local\setup37247527.exe hreadyC:\Users\admin\AppData\Local\setup37247527.exeFFlag Pack_37247527.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup37247527.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1844"C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe" C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferInstaller.exe
setup37247527.exe
User:
admin
Company:
Adaware
Integrity Level:
HIGH
Description:
OfferInstaller
Exit code:
0
Version:
7.14.2.0
Modules
Images
c:\users\admin\appdata\local\temp\ec05d89197b949eb6957b79472e8723d\offerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2028find /I "1264"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2332C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\H2OCleanup.bat""C:\Windows\System32\cmd.exesetup37247527.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2404"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\link.txtC:\Windows\System32\notepad.exeFFlag Pack_37247527.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2408"C:\Users\admin\AppData\Local\Temp\FFlag Pack_37247527.exe" C:\Users\admin\AppData\Local\Temp\FFlag Pack_37247527.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Download Manager
Exit code:
0
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\fflag pack_37247527.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
36 026
Read events
35 819
Write events
201
Delete events
6

Modification events

(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2408) FFlag Pack_37247527.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1264) setup37247527.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\ServiceHide.dll
Executable files
264
Suspicious files
19
Text files
31
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\869CC3B84BEE922ABCE8CDCAA964F3D9_6F32A0985879EB33E63263938C358721binary
MD5:D6FB633ED853123D97A174FDF8D2F725
SHA256:B53E5BDF87653F4E9DA5FC8C47B354D69643E299221B7D352DD584141119466C
1264setup37247527.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\GenericSetup.dllexecutable
MD5:08112F27DCD8F1D779231A7A3E944CB1
SHA256:11C6A8470A3F2B2BE9B8CAFE5F9A0AFCE7303BFD02AB783A0F0EE09A184649FA
1264setup37247527.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\Ninject.dllexecutable
MD5:8DB691813A26E7D0F1DB5E2F4D0D05E3
SHA256:3043A65F11AC204E65BCA142FF4166D85F1B22078B126B806F1FECB2A315C701
1264setup37247527.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\vcruntime140.dllexecutable
MD5:1A84957B6E681FCA057160CD04E26B27
SHA256:9FAEAA45E8CC986AF56F28350B38238B03C01C355E9564B849604B8D690919C5
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\Local\setup37247527.exeexecutable
MD5:29D3A70CEC060614E1691E64162A6C1E
SHA256:CC70B093A19610E9752794D757AEC9EF07CA862EA9267EC6F9CC92B2AA882C72
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\869CC3B84BEE922ABCE8CDCAA964F3D9_6F32A0985879EB33E63263938C358721binary
MD5:6A85AE6A67D675BC5C868F44FE595571
SHA256:A869FDD2441D6045E9A181F1D9CCD9333748716D00D09BA53E3A5E51AAA86A47
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:3D7A391E92B9FE139F4E3E635C94D13D
SHA256:CA93DC01C4DCE21FF2D3839A1D27F514A3BF3A34DE204003227C014208689CEC
1264setup37247527.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\OfferSDK.dllexecutable
MD5:B199DCD6824A02522A4D29A69AB65058
SHA256:9310A58F26BE8BD453CDE5CA6AA05042942832711FBDEB5430A2840232BFA5E4
2408FFlag Pack_37247527.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:4BB4253ADC1F82B0E986696A735046F1
SHA256:D9C5480C0038839AA1160452A02BD088616DAFC8CE64F4BF458F07B7D695F16D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
31
DNS requests
16
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2408
FFlag Pack_37247527.exe
GET
200
172.217.23.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2408
FFlag Pack_37247527.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c9575644cc14e32
unknown
compressed
4.66 Kb
unknown
2408
FFlag Pack_37247527.exe
GET
200
172.217.23.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
2408
FFlag Pack_37247527.exe
GET
200
172.217.23.99:80
http://ocsp.pki.goog/s/gts1d4/BLyg_-h63RA/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEACRI2vGqzWlEof0zfA2Du0%3D
unknown
binary
471 b
unknown
2408
FFlag Pack_37247527.exe
GET
200
172.217.23.99:80
http://ocsp.pki.goog/s/gts1d4/tPVfSrt3g1k/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDASJ2qLaCI5xAFjJiGxx93
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2408
FFlag Pack_37247527.exe
35.190.60.70:443
www.dlsft.com
GOOGLE
US
whitelisted
2408
FFlag Pack_37247527.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2408
FFlag Pack_37247527.exe
172.217.23.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1264
setup37247527.exe
104.17.8.52:443
flow.lavasoft.com
CLOUDFLARENET
shared
1264
setup37247527.exe
104.18.68.73:443
sos.adaware.com
CLOUDFLARENET
unknown
1264
setup37247527.exe
143.204.98.4:443
download.enigmasoftware.com
AMAZON-02
US
unknown
1264
setup37247527.exe
169.150.247.39:443
spyhunter-download-v2.b-cdn.net
GB
unknown

DNS requests

Domain
IP
Reputation
www.dlsft.com
  • 35.190.60.70
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 172.217.23.99
whitelisted
www.google.com
  • 142.250.186.164
whitelisted
flow.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
sos.adaware.com
  • 104.18.68.73
  • 104.18.67.73
whitelisted
dlsft.com
  • 35.190.60.70
unknown
download.enigmasoftware.com
  • 143.204.98.4
  • 143.204.98.125
  • 143.204.98.83
  • 143.204.98.91
shared
spyhunter-download-v2.b-cdn.net
  • 169.150.247.39
unknown
anypdf.com
  • 18.245.86.11
  • 18.245.86.41
  • 18.245.86.56
  • 18.245.86.61
unknown

Threats

Found threats are available for the paid subscriptions
6 ETPRO signatures available at the full report
Process
Message
setup37247527.exe
Error: File not found - sciterwrapper:console.tis
setup37247527.exe
setup37247527.exe
setup37247527.exe
at sciter:init-script.tis
setup37247527.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
setup37247527.exe
at sciter:init-script.tis
setup37247527.exe
Error: File not found - sciterwrapper:console.tis
setup37247527.exe
setup37247527.exe
setup37247527.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'