File name:

AME Wizard Beta.zip

Full analysis: https://app.any.run/tasks/478858f6-0487-42a6-bf72-2501128ee6e0
Verdict: Malicious activity
Analysis date: September 25, 2024, 03:13:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
mimikatz
tools
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

2BE41DB4186F769FF9108231E75C1DA5

SHA1:

935B4A8EC709220A43228AEBB32C3EEFC1A777D4

SHA256:

C982B80CFFB5CF6958CC145D4524E3D434D4047280E21EEF6EE5770C3A50E435

SSDEEP:

98304:c4/cb3SAdO3U8Cv5ykY/btM3THiYETbKscNQzTHO+rw1K+EMxNgNl9jFA5YXZ1n5:btZh+S3guCfyS03PT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • MIMIKATZ has been detected (YARA)

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • AME Wizard Beta.exe (PID: 2892)
    • Process drops legitimate windows executable

      • AME Wizard Beta.exe (PID: 2892)
    • Executable content was dropped or overwritten

      • AME Wizard Beta.exe (PID: 2892)
    • Reads security settings of Internet Explorer

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Application launched itself

      • AME Wizard Beta.exe (PID: 2892)
    • Reads the date of Windows installation

      • AME Wizard Beta.exe (PID: 2892)
    • The process creates files with name similar to system file names

      • AME Wizard Beta.exe (PID: 2892)
    • The process drops C-runtime libraries

      • AME Wizard Beta.exe (PID: 2892)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 5512)
      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Manual execution by a user

      • AME Wizard Beta.exe (PID: 2892)
      • firefox.exe (PID: 644)
    • Checks supported languages

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Reads the computer name

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Create files in a temporary directory

      • AME Wizard Beta.exe (PID: 2892)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5512)
    • Creates files in the program directory

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Reads the machine GUID from the registry

      • AME Wizard Beta.exe (PID: 2892)
      • AME Wizard Beta.exe (PID: 6284)
    • Reads Environment values

      • AME Wizard Beta.exe (PID: 2892)
    • Process checks computer location settings

      • AME Wizard Beta.exe (PID: 2892)
    • Application launched itself

      • firefox.exe (PID: 1644)
      • firefox.exe (PID: 644)
    • Checks proxy server information

      • AME Wizard Beta.exe (PID: 2892)
    • Reads the software policy settings

      • AME Wizard Beta.exe (PID: 2892)
    • Disables trace logs

      • AME Wizard Beta.exe (PID: 2892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:09:09 19:25:42
ZipCRC: 0xffa81c28
ZipCompressedSize: 10741019
ZipUncompressedSize: 18487808
ZipFileName: AME Wizard Beta.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
19
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe #MIMIKATZ ame wizard beta.exe #MIMIKATZ ame wizard beta.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
644"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
1644"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2892"C:\Users\admin\Desktop\AME Wizard Beta.exe" C:\Users\admin\Desktop\AME Wizard Beta.exe
explorer.exe
User:
admin
Company:
Ameliorated LLC
Integrity Level:
MEDIUM
Description:
AME Wizard
Version:
0.7.6
Modules
Images
c:\users\admin\desktop\ame wizard beta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2936"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2288 -parentBuildID 20240213221259 -prefsHandle 2280 -prefMapHandle 2276 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1a828a1d-137c-45d0-8292-cde4c0052a51} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac08d80b10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3880"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4500 -childID 2 -isForBrowser -prefsHandle 4496 -prefMapHandle 4492 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {384eb45f-a645-42df-9ba7-9710840719a3} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac1c629bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4688"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6052 -childID 5 -isForBrowser -prefsHandle 6060 -prefMapHandle 6064 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2055bfb0-a2a9-4a86-a460-84298b8f6ba3} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073ba10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5268"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5696 -childID 3 -isForBrowser -prefsHandle 5456 -prefMapHandle 5608 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a8272d73-feed-4ab2-9a1d-b3686181a7f1} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073bd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5512"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\AME Wizard Beta.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5888"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5904 -childID 4 -isForBrowser -prefsHandle 5816 -prefMapHandle 5820 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3a1a2e2b-0310-43ce-85ab-93e78e8a5f67} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073b850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
18 346
Read events
18 315
Write events
31
Delete events
0

Modification events

(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AME Wizard Beta.zip
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF1E01000033000000DE0400001C020000
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
52
Suspicious files
185
Text files
37
Unknown types
5

Dropped files

PID
Process
Filename
Type
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\Ben.Demystifier.dllexecutable
MD5:965D07F46CD56AE2A4F310921230C206
SHA256:F49EC56E6D8DD1029F990C08DBFC8CA7C5E8EDD353D8D7BA35FAE2C6ADCAA1C9
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\DiscUtils.Iso9660.dllexecutable
MD5:C7340CDF1E4AF72C007FE68694B7ECB5
SHA256:4AA30F253343F3E130F4FF8DF0E955232134F339FFCB279CB8FE22A05ACC727D
5512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5512.33300\AME Wizard Beta.exeexecutable
MD5:3725BE198E6BC6B8AEC46060F3CFC2E4
SHA256:AC2C0A54AC444CD2B093CC74BCDE2EAE1C9B154F1D1393C312165C8BECEB8347
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\7za.dllexecutable
MD5:58FDBF10D3DCE4D2E270C03E8311D9DB
SHA256:0BBCC7BFC688A512911FBE679BBD279928F1B463431139685EBE39A98798134E
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\client-helper.dllexecutable
MD5:37FAF38D69284BDA23E383C000D946A3
SHA256:0C84C4F52A981B57DA3C639D7F96DE0BD3E366C241B14972BA8A5F6D396DBD54
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\msvcp140.dllexecutable
MD5:1BA6D1CF0508775096F9E121A24E5863
SHA256:74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\7zxa.dllexecutable
MD5:BC3754B7C77DFB6AED1722EF7F53B414
SHA256:B54CAC90E649EBBF7C27CF1772F5C1644F4600DB88F0D51419A3529A5A5F95FC
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\Microsoft.Bcl.TimeProvider.dllexecutable
MD5:37E25D107CE1385DF1474780CBFA4636
SHA256:693242B67DA91AF78DDA4B91D6020E0B8CDA08D4C9102177A12522009EF9B940
2892AME Wizard Beta.exeC:\Users\admin\AppData\Local\Temp\AME\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:A844AC745A4005FBD3F51D79FF88583C
SHA256:74FE1A6A1E36BE7D893E31BBB4D4BD83BF4B927E715276CD5607982139818EBD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
124
DNS requests
148
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6660
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5104
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1644
firefox.exe
POST
200
2.16.168.6:80
http://r11.o.lencr.org/
unknown
unknown
1644
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
unknown
1644
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
unknown
1644
firefox.exe
POST
200
142.250.186.131:80
http://o.pki.goog/wr2
unknown
unknown
1644
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
unknown
1644
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
unknown
1644
firefox.exe
POST
200
142.250.186.131:80
http://o.pki.goog/wr2
unknown
unknown
7200
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
5104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4652
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2892
AME Wizard Beta.exe
140.82.121.6:443
api.github.com
GITHUB
US
whitelisted
6660
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.110
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info