File name:

Ninite WizTree Installer.exe

Full analysis: https://app.any.run/tasks/7b7256f5-fc78-43ea-9cf9-46dafb340966
Verdict: Malicious activity
Analysis date: January 19, 2025, 01:02:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3D8701BB10CD0D54DD76AEE7C24B2054

SHA1:

A0528D488718E14F0CB6809B3EA9373EA52BD4B0

SHA256:

CF7F27BC0172829ED137E7963DA3322DA251B9595FC907EAF25F52FD90F2CA78

SSDEEP:

12288:GLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzE8:YVP60BM2pMUN9keo+c+zE8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite.exe (PID: 6464)
      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
    • Application launched itself

      • Ninite.exe (PID: 6464)
    • Checks Windows Trust Settings

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Executable content was dropped or overwritten

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
    • Process drops legitimate windows executable

      • target.tmp (PID: 6984)
    • Searches for installed software

      • Ninite.exe (PID: 6656)
    • Reads the Windows owner or organization settings

      • target.tmp (PID: 6984)
    • Uses TASKKILL.EXE to kill process

      • target.tmp (PID: 6984)
    • Checks for external IP

      • svchost.exe (PID: 2192)
  • INFO

    • The sample compiled with english language support

      • Ninite WizTree Installer.exe (PID: 6212)
      • target.tmp (PID: 6984)
    • Checks supported languages

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • Ninite.exe (PID: 6464)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
      • WizTree64.exe (PID: 3524)
    • The process uses the downloaded file

      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
    • Reads the machine GUID from the registry

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Create files in a temporary directory

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
    • Reads the computer name

      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • Ninite WizTree Installer.exe (PID: 6212)
      • target.tmp (PID: 6984)
      • WizTree64.exe (PID: 3524)
    • Reads the software policy settings

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Process checks computer location settings

      • Ninite.exe (PID: 6464)
      • target.tmp (PID: 6984)
    • Checks proxy server information

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Creates files or folders in the user directory

      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
      • Ninite WizTree Installer.exe (PID: 6212)
      • WizTree64.exe (PID: 3524)
    • Creates files in the program directory

      • target.tmp (PID: 6984)
    • Creates a software uninstall entry

      • target.tmp (PID: 6984)
    • Reads Environment values

      • WizTree64.exe (PID: 3524)
    • Application launched itself

      • firefox.exe (PID: 2744)
      • firefox.exe (PID: 5536)
    • Manual execution by a user

      • firefox.exe (PID: 2744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
24
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
start ninite wiztree installer.exe ninite.exe no specs ninite.exe target.exe target.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs wiztree64.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2548"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4888 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4792 -prefMapHandle 4732 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {76b0de12-dfff-4b90-8002-a0fa2cc26ea6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca650a6d10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2744"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
3524"C:\Program Files\WizTree\WizTree64.exe" -setlanguage enC:\Program Files\WizTree\WizTree64.exetarget.tmp
User:
admin
Company:
Antibody Software Limited
Integrity Level:
HIGH
Description:
WizTree
Exit code:
0
Version:
4.23.0.0
Modules
Images
c:\program files\wiztree\wiztree64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mpr.dll
3560"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6160 -childID 8 -isForBrowser -prefsHandle 6296 -prefMapHandle 6300 -prefsLen 31324 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cfaed4bc-2952-4ab6-bb78-6b165c29baf2} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca69b3c850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2628 -childID 5 -isForBrowser -prefsHandle 5328 -prefMapHandle 5332 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9ad28a41-75dc-4b40-a44b-460c714f6e9a} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
3692"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -childID 3 -isForBrowser -prefsHandle 5136 -prefMapHandle 5132 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3eab185f-90a7-4c3a-ba53-f61cdc0ccee6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
3736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5868 -childID 6 -isForBrowser -prefsHandle 5824 -prefMapHandle 5856 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e3257ca-5904-4e87-9b61-8ab5b939f755} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68d244d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
5536"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5892"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1824 -parentBuildID 20240213221259 -prefsHandle 1852 -prefMapHandle 1840 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4fba9fd9-5294-43c6-ac9f-7c80c39448bb} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca5ddeab10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
Total events
21 206
Read events
21 179
Write events
27
Delete events
0

Modification events

(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.8 (u)
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\WizTree
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\WizTree\
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Icon Group
Value:
WizTree
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon,quicklaunchicon
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Language
Value:
en
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:DisplayName
Value:
WizTree v4.23
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\WizTree\WizTree.exe
Executable files
12
Suspicious files
220
Text files
73
Unknown types
0

Dropped files

PID
Process
Filename
Type
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:2B44D1584874F492B6406BFCED95A748
SHA256:B9065996A719949883B09F18E0BBFB8D2F691AC1C1581F850F27764306910CDE
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:9F86BE1CD0CB7E200442CED32BD3BB3B
SHA256:9956928C14211725B9FE12AB3349D36F95A2C949D34E18B4A11384B1D7101763
6656Ninite.exeC:\Users\admin\AppData\Local\Temp\16e4151a-d601-11ef-b4ea-18f7786f96ee\target.exe_16e4151b-d601-11ef-b4ea-18f7786f96eeexecutable
MD5:DEAE8661F3643AB1FA58774589459880
SHA256:EDE889913A2B3819B2AA642A1BC46185A91202D854FA3EEC141C6E8E64EDD5C5
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:2BB9EBF580E7F882CC30F32EB1481741
SHA256:47765859EB79927B1B1A2647F406F58680F2646C29F1D62503BBE2692281A255
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\Local\Temp\150b2203-d601-11ef-b4ea-18f7786f96ee\Ninite.exeexecutable
MD5:AECEA03AB75EA848DC8BB0511A3DFD83
SHA256:168C0280421EC2CEA8ADCF34A22056839F32DF0AC3575B08F98001A10AD587C9
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:AFA6A8DDB88654619A8BEF685FC89BE5
SHA256:F779A4937720CEE5AA89F526A3F43ACD4BBF520D7007EC3512ABCE43B1003E90
6960target.exeC:\Users\admin\AppData\Local\Temp\is-S74G3.tmp\target.tmpexecutable
MD5:E92523CCBE8DB70FFB5D575BC6AD5393
SHA256:1E23CBBD9135490044F608163C867BB5101E70F6C0022EA14FDF7342480F9A31
6656Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_427CDB1C9AAC2BAE6B426DB11F126FA2binary
MD5:5F7D7C58A619CF10BAFDD602FBB94FE8
SHA256:8B12B5E66235AA77EC36FC9C0593CC47A980C380B737A5B04112C902C3CF85B1
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:248C4A2BC827A486C8C486017AE6074C
SHA256:E70033CEC911EABD2CAD100CCB00D14E377BD8D5C6DF0CF951121CAB2A4AEB48
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3Dbinary
MD5:2A590CDD20C46F046A8FF795E6BE4F5F
SHA256:BDDE4AAA47FC2C90AEDBBC8CBDCD50CAE6D3BDCD55668854B42F204071C73FEF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
53
TCP/UDP connections
194
DNS requests
235
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11
unknown
whitelisted
6656
Ninite.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAkO6MXeW%2Fpi0q4v9wl8SFc%3D
unknown
whitelisted
6656
Ninite.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
5536
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6212
Ninite WizTree Installer.exe
65.9.66.107:443
ninite.com
AMAZON-02
US
whitelisted
6212
Ninite WizTree Installer.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
5064
SearchApp.exe
104.126.37.170:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6212
Ninite WizTree Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.142
whitelisted
ninite.com
  • 65.9.66.107
  • 65.9.66.56
  • 65.9.66.14
  • 65.9.66.60
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
www.bing.com
  • 104.126.37.170
  • 104.126.37.176
  • 104.126.37.139
  • 104.126.37.185
  • 104.126.37.178
  • 104.126.37.131
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
diskanalyzer.com
  • 23.111.178.178
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.75
whitelisted

Threats

PID
Process
Class
Message
5536
firefox.exe
Device Retrieving External IP Address Detected
ET INFO Possible External IP Lookup Domain Observed in SNI (ipinfo. io)
5536
firefox.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ipinfo.io
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
No debug info