download:

/rzc0d3r/ESET-KeyGen/releases/download/v1.0.9.3-221123-0959/ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe

Full analysis: https://app.any.run/tasks/2aa4c082-8efe-4017-8837-e9a00483f440
Verdict: Malicious activity
Analysis date: November 24, 2023, 11:51:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

115793D4BA57A57B7F21BF3AB3406A8B

SHA1:

3AB08D67AB0CC773D93B3DECB8234FFBD7D23F0E

SHA256:

CA3C9ED6A3EA19B1FC3F88C629CA922D07AE0DD6CB7CD8B380D526D8B7CC1F44

SSDEEP:

196608:Nza9aQpeOZY/ZOAkuxgyHgAYNhbtief0:laAQAdZku+yAAshpF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
    • Loads Python modules

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
    • The process drops C-runtime libraries

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
    • Application launched itself

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
    • Reads the Internet Settings

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
  • INFO

    • Reads the computer name

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
      • wmpnscfg.exe (PID: 2496)
    • Checks supported languages

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
      • wmpnscfg.exe (PID: 2496)
    • Reads the machine GUID from the registry

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
      • wmpnscfg.exe (PID: 2496)
    • Checks proxy server information

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2748)
    • Create files in a temporary directory

      • ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe (PID: 2876)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2496)
      • chrome.exe (PID: 2684)
    • The process uses the downloaded file

      • chrome.exe (PID: 4020)
      • chrome.exe (PID: 3408)
      • chrome.exe (PID: 2248)
    • Application launched itself

      • chrome.exe (PID: 2684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (50.1)
.exe | Win64 Executable (generic) (32.2)
.dll | Win32 Dynamic Link Library (generic) (7.6)
.exe | Win32 Executable (generic) (5.2)
.exe | Generic Win/DOS Executable (2.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:22 10:09:04+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 156160
InitializedDataSize: 128512
UninitializedDataSize: -
EntryPoint: 0xaa50
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
25
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start eset-keygen_v1.0.9.3-221123-0959_win32.exe no specs eset-keygen_v1.0.9.3-221123-0959_win32.exe wmpnscfg.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
476"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1584 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
600"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1036 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
888"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=988 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1272"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=1568 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1360"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2220 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1988"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6b738b38,0x6b738b48,0x6b738b54C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1992"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3640 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2248"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2008 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2400"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1104 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2412"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1188,i,16814674247309793980,17716981989316834175,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
4 648
Read events
4 563
Write events
81
Delete events
4

Modification events

(PID) Process:(2496) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{14E3BFEE-1D34-4E43-B8FF-1E687AB3897E}\{D5DBCD18-AD21-48E7-9F02-6405E21E870F}
Operation:delete keyName:(default)
Value:
(PID) Process:(2496) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{14E3BFEE-1D34-4E43-B8FF-1E687AB3897E}
Operation:delete keyName:(default)
Value:
(PID) Process:(2496) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{8ADF1FEF-E055-42E5-BB58-AD2C3754D4E7}
Operation:delete keyName:(default)
Value:
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
(PID) Process:(2684) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
Executable files
18
Suspicious files
95
Text files
57
Unknown types
0

Dropped files

PID
Process
Filename
Type
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\selenium\webdriver\common\linux\selenium-manager
MD5:
SHA256:
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\selenium\webdriver\common\macos\selenium-manager
MD5:
SHA256:
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\_hashlib.pydexecutable
MD5:9AA769EFAC1446DB1D2E4E1C39500A20
SHA256:DE7C71C90C7F58DCDC3DA159D08DDA7DC297E39C5F309849290238BAED7E230F
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\_ctypes.pydexecutable
MD5:36BF6FFD59C04075D50F245EF5DE2AB9
SHA256:7C11A5B8CBAEB0CD34544A7E4949C1B2A61CC78392C0155C0156306E6FF602E0
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\VCRUNTIME140.dllexecutable
MD5:AE96651CFBD18991D186A029CBECB30C
SHA256:1B372F064EACB455A0351863706E6326CA31B08E779A70DE5DE986B5BE8069A1
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\_bz2.pydexecutable
MD5:852CAC1AC7232C5788CBA284C3122347
SHA256:94D02CBCFAC3141CA0107253050D7B9D809FEA04B42964142BED3F090783A26A
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\_queue.pydexecutable
MD5:BCF5440A884EF33DF02CE124557D0C2C
SHA256:2F2F30A6B697B7BA7C09DB16EC04517C85CDFAB13F142B9C810FDF9983522129
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\_lzma.pydexecutable
MD5:52E990DA9F33D0EF2B83A0B52D42DCD6
SHA256:17FD3A2750E61FB164F3A9E8E021A0A3B5DE107A3CC4C798E127618034E09D6F
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\libssl-1_1.dllexecutable
MD5:9417E0D677E0F8B08398FCD57DCCBAFD
SHA256:DB16853DBC64F045AE2A972F7605A6F192D09B79CAE86FD93B8434FA7D9E031F
2876ESET-KeyGen_v1.0.9.3-221123-0959_win32.exeC:\Users\admin\AppData\Local\Temp\_MEI28762\selenium\webdriver\common\mutation-listener.jstext
MD5:81F59E36BDE07E051C3CB92A4986B327
SHA256:2C2083C9A49F65C510D68D3620A57D4DFEDC8DC0FCC32524C1CCB11C6329EA07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
30
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
868
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/k4ldha5kevpu7qn7k4s3mznvgu_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win32_ad2kbvs6jks3au5dsxn7cqflsiiq.crx3
unknown
unknown
868
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/k4ldha5kevpu7qn7k4s3mznvgu_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win32_ad2kbvs6jks3au5dsxn7cqflsiiq.crx3
unknown
binary
9.06 Kb
unknown
868
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/k4ldha5kevpu7qn7k4s3mznvgu_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win32_ad2kbvs6jks3au5dsxn7cqflsiiq.crx3
unknown
binary
6.25 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2748
ESET-KeyGen_v1.0.9.3-221123-0959_win32.exe
142.250.186.59:443
chromedriver.storage.googleapis.com
GOOGLE
US
unknown
2684
chrome.exe
239.255.255.250:1900
whitelisted
2412
chrome.exe
142.250.181.227:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
2412
chrome.exe
142.250.186.173:443
accounts.google.com
GOOGLE
US
unknown
2412
chrome.exe
142.250.184.228:443
www.google.com
GOOGLE
US
whitelisted
2412
chrome.exe
142.250.185.195:443
update.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
chromedriver.storage.googleapis.com
  • 142.250.186.59
  • 172.217.18.27
  • 172.217.16.219
  • 216.58.206.59
  • 142.250.74.219
  • 172.217.18.123
  • 172.217.23.123
  • 216.58.212.155
  • 142.250.185.91
  • 142.250.185.123
  • 142.250.185.155
  • 142.250.185.187
  • 142.250.185.219
  • 142.250.185.251
  • 142.250.186.91
  • 142.250.186.123
whitelisted
clientservices.googleapis.com
  • 142.250.181.227
whitelisted
accounts.google.com
  • 142.250.186.173
shared
www.google.com
  • 142.250.184.228
whitelisted
update.googleapis.com
  • 142.250.185.195
  • 142.250.181.227
whitelisted
optimizationguide-pa.googleapis.com
  • 142.250.74.202
  • 172.217.18.106
  • 216.58.212.170
  • 172.217.23.106
  • 216.58.212.138
  • 142.250.185.74
  • 142.250.185.106
  • 142.250.185.138
  • 142.250.185.170
  • 142.250.185.202
  • 142.250.185.234
  • 142.250.186.74
  • 142.250.186.106
  • 142.250.181.234
  • 142.250.184.202
  • 142.250.184.234
whitelisted
encrypted-tbn0.gstatic.com
  • 142.250.186.110
whitelisted
lh5.googleusercontent.com
  • 142.250.186.97
whitelisted
www.gstatic.com
  • 142.250.185.163
whitelisted
content-autofill.googleapis.com
  • 142.250.185.202
  • 142.250.185.234
  • 142.250.186.74
  • 142.250.186.106
  • 142.250.181.234
  • 142.250.184.202
  • 142.250.184.234
  • 142.250.186.138
  • 142.250.186.170
  • 142.250.186.42
  • 172.217.18.10
  • 172.217.16.202
  • 216.58.206.42
  • 172.217.18.106
  • 216.58.212.170
  • 172.217.23.106
whitelisted

Threats

No threats detected
No debug info