File name:

SpoDable.exe

Full analysis: https://app.any.run/tasks/bf07f50f-1126-49c4-88f7-94b4c50c641c
Verdict: Malicious activity
Analysis date: November 10, 2023, 04:52:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EFBA96D0DAEAF96FB70DCDADCD377B68

SHA1:

88B5F974D361E783DB93A0489E61369C6B37B0E0

SHA256:

CC521F0ECF73027979D340EC81CDF6755EF7C233F907B5D25AE0E94240D9DE6A

SSDEEP:

98304:q+cD4dnbPV8UA0exZboAcalKA5YpcCJNDCPJ2MbJaCkel7XKHftYN+XJZSypJVWO:O8EdXONPfXX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SpoDable.exe (PID: 3428)
      • SpoDable.exe (PID: 2424)
      • SpoDable.tmp (PID: 3468)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • SpoDable.tmp (PID: 3468)
    • Reads the Internet Settings

      • AFSpotifyMusicConverter.exe (PID: 3444)
      • SpoDable.tmp (PID: 3468)
    • Checks Windows Trust Settings

      • AFSpotifyMusicConverter.exe (PID: 3444)
    • Reads security settings of Internet Explorer

      • AFSpotifyMusicConverter.exe (PID: 3444)
    • Reads settings of System Certificates

      • AFSpotifyMusicConverter.exe (PID: 3444)
  • INFO

    • Reads the computer name

      • SpoDable.tmp (PID: 3460)
      • SpoDable.tmp (PID: 3468)
      • AFSpotifyMusicConverter.exe (PID: 3444)
      • wmpnscfg.exe (PID: 2624)
    • Checks supported languages

      • SpoDable.tmp (PID: 3460)
      • SpoDable.exe (PID: 3428)
      • SpoDable.exe (PID: 2424)
      • SpoDable.tmp (PID: 3468)
      • AFSpotifyMusicConverter.exe (PID: 3444)
      • wmpnscfg.exe (PID: 2624)
    • Create files in a temporary directory

      • SpoDable.exe (PID: 3428)
      • SpoDable.exe (PID: 2424)
    • Creates files in the program directory

      • SpoDable.tmp (PID: 3468)
    • Reads the machine GUID from the registry

      • AFSpotifyMusicConverter.exe (PID: 3444)
      • wmpnscfg.exe (PID: 2624)
    • Checks proxy server information

      • AFSpotifyMusicConverter.exe (PID: 3444)
    • Creates files or folders in the user directory

      • AFSpotifyMusicConverter.exe (PID: 3444)
    • Application launched itself

      • msedge.exe (PID: 3640)
      • msedge.exe (PID: 4084)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2624)
      • msedge.exe (PID: 4084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 96768
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.9.2.430
ProductVersionNumber: 2.9.2.430
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AudFree Studio.
FileDescription: AudFree Spotify Music Converter Setup
FileVersion: 2.9.2.430
LegalCopyright:
OriginalFileName:
ProductName: AudFree Spotify Music Converter
ProductVersion: 2.9.2.430
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
77
Monitored processes
38
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spodable.exe no specs spodable.tmp no specs spodable.exe spodable.tmp no specs afspotifymusicconverter.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4080 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
276"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3596 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
536"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3856 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1016"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=2536 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4176 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3716 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1668"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=2596 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1808"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1616 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2284 --field-trial-handle=1284,i,4091310124156567051,15818372970524557840,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 448
Read events
8 376
Write events
62
Delete events
10

Modification events

(PID) Process:(3468) SpoDable.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(3444) AFSpotifyMusicConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3444) AFSpotifyMusicConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
688D0BE8984FC1F42AECC1CDD4166FD22026DD0601BD987A3976AB5630347C93
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\AudFree Spotify Music Converter\AFSpotifyMusicConverter.exe
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
213749044A4D9773D074EBEA31E750118E4ACB6FBFCE2E729DF582A28CB6E1C4
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
8C0D0000BED50ACC9113DA01
(PID) Process:(3468) SpoDable.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(3444) AFSpotifyMusicConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
35
Suspicious files
228
Text files
218
Unknown types
0

Dropped files

PID
Process
Filename
Type
3428SpoDable.exeC:\Users\admin\AppData\Local\Temp\is-SGPRL.tmp\SpoDable.tmpexecutable
MD5:5DFDBBCAA4AA02766E331B1902811340
SHA256:C66904C4A953EC0906399AB52524B531CA8BAEBF9E74B7099D16898189BA10DD
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-SUAIR.tmpexecutable
MD5:E222316B9E872D2057FD2FFCB4A35D72
SHA256:F8394D88A2EF2C1DB25D242B9D0552CC8C44A9FF6D2ADE037F69B85ECAE15C0E
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-ORLEP.tmpexecutable
MD5:E2DA017F8AE50BD729B2A664026FDB06
SHA256:A5F415554729B8961539C57DA054F6BBB48FB8EB0B1D4A82EAA75160FC9AF886
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-3ODFJ.tmpexecutable
MD5:FA26C10F3E595FF79090E4580153EF73
SHA256:B04E24F6C81B0511FAA76057F2F88622AA3D4267125632CBF8398B8E680CB858
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\AFSpotifyMusicConverter.exeexecutable
MD5:FA26C10F3E595FF79090E4580153EF73
SHA256:B04E24F6C81B0511FAA76057F2F88622AA3D4267125632CBF8398B8E680CB858
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-G65BM.tmpexecutable
MD5:B9682CA9B24C543FD2D2DDEE83710681
SHA256:14891CDCCB314BF93FFA95CC6885B7A0FC31B63051284B8A92869D0AAC1386E7
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\ConvertLibrary.dllexecutable
MD5:E222316B9E872D2057FD2FFCB4A35D72
SHA256:F8394D88A2EF2C1DB25D242B9D0552CC8C44A9FF6D2ADE037F69B85ECAE15C0E
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-0HSVE.tmpexecutable
MD5:25EB71F37B224B9045EC66B26647098D
SHA256:0F79CC2ADED65385475D61C6C7B0FC2D1349C3191C50503715848A73E3E68A60
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\HelperLibrary.dllexecutable
MD5:25EB71F37B224B9045EC66B26647098D
SHA256:0F79CC2ADED65385475D61C6C7B0FC2D1349C3191C50503715848A73E3E68A60
3468SpoDable.tmpC:\Program Files\AudFree Spotify Music Converter\is-VSLB5.tmpexecutable
MD5:E724CC676423569F1F262A4610DE8AC2
SHA256:225CEA77CECB2D4673B7DCD04C64B916861605E2794CBD0FD19C4854894695C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
74
DNS requests
157
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3444
AFSpotifyMusicConverter.exe
GET
200
8.248.131.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8c9c38131579114d
unknown
compressed
4.66 Kb
unknown
3444
AFSpotifyMusicConverter.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3444
AFSpotifyMusicConverter.exe
172.67.176.90:443
api.audfree.com
CLOUDFLARENET
US
unknown
3444
AFSpotifyMusicConverter.exe
8.248.131.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3444
AFSpotifyMusicConverter.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2376
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4084
msedge.exe
239.255.255.250:1900
whitelisted
2376
msedge.exe
104.21.64.50:443
api.audfree.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
api.audfree.com
  • 172.67.176.90
  • 104.21.64.50
unknown
ctldl.windowsupdate.com
  • 8.248.131.254
  • 8.241.11.254
  • 8.241.122.254
  • 8.241.123.254
  • 67.26.137.254
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 51.104.176.40
whitelisted
www.audfree.com
  • 172.67.176.90
  • 104.21.64.50
unknown
ajax.googleapis.com
  • 142.250.186.106
whitelisted
www.google-analytics.com
  • 142.250.185.174
  • 142.250.186.46
whitelisted

Threats

PID
Process
Class
Message
2376
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
No debug info