File name:

infatica1140.exe

Full analysis: https://app.any.run/tasks/5c9e5bb3-54cb-4cca-bc56-83a1bb9386ae
Verdict: Malicious activity
Analysis date: July 05, 2024, 05:55:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4B9F5C2B4036A8D0A5D131C63D0B49E9

SHA1:

EEA747710E68BF5C02F4BED98E2FFF3D08149F55

SHA256:

BE570DE0DC914402E7DE5F2F8082A5878552D105DEA0E0700812D6769F7424A8

SSDEEP:

98304:ZglZyJZNncDLE0JHarbPHwipHgZx77FtjrxdoZ2tuUGvLLW36kwgzJURazQYyU8L:oE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • infatica1140.exe (PID: 4164)
      • infatica1140.exe (PID: 6224)
      • infatica1140.tmp (PID: 6260)
    • Uses Task Scheduler to run other applications

      • infatica1140.tmp (PID: 6260)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • infatica1140.tmp (PID: 5380)
    • Reads security settings of Internet Explorer

      • infatica1140.tmp (PID: 5380)
    • Executable content was dropped or overwritten

      • infatica1140.exe (PID: 4164)
      • infatica1140.exe (PID: 6224)
      • infatica1140.tmp (PID: 6260)
    • Reads the Windows owner or organization settings

      • infatica1140.tmp (PID: 6260)
    • Checks for external IP

      • infatica1140.tmp (PID: 6260)
  • INFO

    • Checks supported languages

      • infatica1140.exe (PID: 4164)
      • infatica1140.tmp (PID: 5380)
      • infatica1140.exe (PID: 6224)
      • infatica1140.tmp (PID: 6260)
    • Reads the computer name

      • infatica1140.tmp (PID: 5380)
      • infatica1140.tmp (PID: 6260)
    • Process checks computer location settings

      • infatica1140.tmp (PID: 5380)
      • infatica1140.tmp (PID: 6260)
    • Create files in a temporary directory

      • infatica1140.exe (PID: 4164)
      • infatica1140.exe (PID: 6224)
      • infatica1140.tmp (PID: 6260)
    • Creates files in the program directory

      • infatica1140.tmp (PID: 6260)
    • Creates a software uninstall entry

      • infatica1140.tmp (PID: 6260)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 6820)
    • Application launched itself

      • firefox.exe (PID: 6820)
      • firefox.exe (PID: 6752)
    • Manual execution by a user

      • firefox.exe (PID: 6752)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6820)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 6820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 14:39:04+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.1.4.0
ProductVersionNumber: 1.1.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Infatica P2B Network Setup
FileVersion: 1.1.4.0
LegalCopyright:
ProductName: Infatica P2B Network
ProductVersion: 1.1.4.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
16
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start infatica1140.exe infatica1140.tmp no specs infatica1140.exe infatica1140.tmp schtasks.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2960 -childID 1 -isForBrowser -prefsHandle 2904 -prefMapHandle 2900 -prefsLen 30888 -prefMapSize 244343 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ead68b3e-3596-40dd-a8a5-d39ba222bc87} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 143090c0150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1908"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4500 -childID 2 -isForBrowser -prefsHandle 4496 -prefMapHandle 4492 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3454620a-1867-44a5-8ec0-ffe6922bd57e} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 1430b17aa10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2716"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5596 -childID 4 -isForBrowser -prefsHandle 5600 -prefMapHandle 5604 -prefsLen 31108 -prefMapSize 244343 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {99abe3f6-aa74-4a3c-8a8c-ab36fc88170e} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 1430d13af50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3232"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5268 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5260 -prefMapHandle 4824 -prefsLen 36339 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a0004b6c-a43a-4220-bdac-7e648dee9d03} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 1430c820310 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3928"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5852 -childID 5 -isForBrowser -prefsHandle 5772 -prefMapHandle 5776 -prefsLen 31108 -prefMapSize 244343 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ca520e53-6119-42db-9ae6-cc10703781b7} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 1430d13a150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4164"C:\Users\admin\AppData\Local\Temp\infatica1140.exe" C:\Users\admin\AppData\Local\Temp\infatica1140.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Infatica P2B Network Setup
Exit code:
0
Version:
1.1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\infatica1140.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5236"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5292 -childID 3 -isForBrowser -prefsHandle 5440 -prefMapHandle 5436 -prefsLen 31108 -prefMapSize 244343 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {acf7f6c3-2506-42b4-a6c4-64ff1ebb0896} 6820 "\\.\pipe\gecko-crash-server-pipe.6820" 1430ce15f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5380"C:\Users\admin\AppData\Local\Temp\is-S12PH.tmp\infatica1140.tmp" /SL5="$40254,1999037,121344,C:\Users\admin\AppData\Local\Temp\infatica1140.exe" C:\Users\admin\AppData\Local\Temp\is-S12PH.tmp\infatica1140.tmpinfatica1140.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-s12ph.tmp\infatica1140.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6224"C:\Users\admin\AppData\Local\Temp\infatica1140.exe" /SPAWNWND=$802B4 /NOTIFYWND=$40254 C:\Users\admin\AppData\Local\Temp\infatica1140.exe
infatica1140.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Infatica P2B Network Setup
Exit code:
0
Version:
1.1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\infatica1140.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6260"C:\Users\admin\AppData\Local\Temp\is-HEELS.tmp\infatica1140.tmp" /SL5="$40344,1999037,121344,C:\Users\admin\AppData\Local\Temp\infatica1140.exe" /SPAWNWND=$802B4 /NOTIFYWND=$40254 C:\Users\admin\AppData\Local\Temp\is-HEELS.tmp\infatica1140.tmp
infatica1140.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-heels.tmp\infatica1140.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
17 815
Read events
17 764
Write events
50
Delete events
1

Modification events

(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (u)
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Infatica P2B
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Infatica P2B\
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Infatica P2B
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:Inno Setup: Language
Value:
default
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:DisplayName
Value:
Infatica P2B Network
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Infatica P2B\unins000.exe"
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files (x86)\Infatica P2B\unins000.exe" /SILENT
(PID) Process:(6260) infatica1140.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C989163F-E0E5-4DE3-B7F5-46C77F411451}_is1
Operation:writeName:DisplayVersion
Value:
1.1.4.0
Executable files
9
Suspicious files
162
Text files
31
Unknown types
1

Dropped files

PID
Process
Filename
Type
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\is-1ISFV.tmp
MD5:
SHA256:
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\infatica_agent.dat
MD5:
SHA256:
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\infatica_agent.exeexecutable
MD5:9012EE01A6F382CDED63A3184D504BED
SHA256:4F966328F131988979EB1401E9EF512836B35E79502877E00566A261B58409CB
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\unins000.exeexecutable
MD5:0C083266EEC7437BA0DFE44E451AB71F
SHA256:D2DCF7ED0C656532ED25CD496AC237223985BB56CB688F125CBBF940DDB9C6BB
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\is-TO7HO.tmpexecutable
MD5:0C083266EEC7437BA0DFE44E451AB71F
SHA256:D2DCF7ED0C656532ED25CD496AC237223985BB56CB688F125CBBF940DDB9C6BB
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\is-21RMO.tmpexecutable
MD5:9012EE01A6F382CDED63A3184D504BED
SHA256:4F966328F131988979EB1401E9EF512836B35E79502877E00566A261B58409CB
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\unins000.datdat
MD5:E329E891B32A3288C7DC87F4B3DE64B6
SHA256:9ECC087330C90DF7F77213110AB190A980F6F5E3C0BD006A057A74EE3F4C12E3
4164infatica1140.exeC:\Users\admin\AppData\Local\Temp\is-S12PH.tmp\infatica1140.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
6260infatica1140.tmpC:\Program Files (x86)\Infatica P2B\inf_run_task.xmltext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
6224infatica1140.exeC:\Users\admin\AppData\Local\Temp\is-HEELS.tmp\infatica1140.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
33
TCP/UDP connections
135
DNS requests
117
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6260
infatica1140.tmp
GET
200
34.117.186.192:80
http://ipinfo.io/json
unknown
unknown
4780
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
4780
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
6820
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
unknown
6820
firefox.exe
POST
200
184.24.77.54:80
http://r10.o.lencr.org/
unknown
unknown
6820
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
6820
firefox.exe
POST
200
184.24.77.54:80
http://r10.o.lencr.org/
unknown
unknown
6820
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
unknown
unknown
6820
firefox.exe
POST
200
184.24.77.54:80
http://r10.o.lencr.org/
unknown
unknown
6820
firefox.exe
POST
200
184.24.77.54:80
http://r10.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4780
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
3396
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4180
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6260
infatica1140.tmp
34.117.186.192:80
ipinfo.io
GOOGLE-CLOUD-PLATFORM
US
unknown
4780
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4780
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
6820
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
ipinfo.io
  • 34.117.186.192
shared
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared

Threats

PID
Process
Class
Message
6260
infatica1140.tmp
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ipinfo.io
2168
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
No debug info