File name:

Ninite WizTree Installer.exe

Full analysis: https://app.any.run/tasks/7b7256f5-fc78-43ea-9cf9-46dafb340966
Verdict: Malicious activity
Analysis date: January 19, 2025, 01:02:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3D8701BB10CD0D54DD76AEE7C24B2054

SHA1:

A0528D488718E14F0CB6809B3EA9373EA52BD4B0

SHA256:

CF7F27BC0172829ED137E7963DA3322DA251B9595FC907EAF25F52FD90F2CA78

SSDEEP:

12288:GLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzE8:YVP60BM2pMUN9keo+c+zE8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
    • Checks Windows Trust Settings

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Executable content was dropped or overwritten

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
    • Application launched itself

      • Ninite.exe (PID: 6464)
    • Searches for installed software

      • Ninite.exe (PID: 6656)
    • Uses TASKKILL.EXE to kill process

      • target.tmp (PID: 6984)
    • Process drops legitimate windows executable

      • target.tmp (PID: 6984)
    • Reads the Windows owner or organization settings

      • target.tmp (PID: 6984)
    • Checks for external IP

      • svchost.exe (PID: 2192)
  • INFO

    • Checks supported languages

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
      • WizTree64.exe (PID: 3524)
    • The sample compiled with english language support

      • Ninite WizTree Installer.exe (PID: 6212)
      • target.tmp (PID: 6984)
    • Checks proxy server information

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Reads the machine GUID from the registry

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Creates files or folders in the user directory

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
      • WizTree64.exe (PID: 3524)
    • Reads the computer name

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
      • WizTree64.exe (PID: 3524)
    • Create files in a temporary directory

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
      • target.exe (PID: 6960)
      • target.tmp (PID: 6984)
    • The process uses the downloaded file

      • Ninite.exe (PID: 6464)
      • Ninite.exe (PID: 6656)
      • target.tmp (PID: 6984)
    • Reads the software policy settings

      • Ninite WizTree Installer.exe (PID: 6212)
      • Ninite.exe (PID: 6656)
    • Process checks computer location settings

      • Ninite.exe (PID: 6464)
      • target.tmp (PID: 6984)
    • Creates files in the program directory

      • target.tmp (PID: 6984)
    • Creates a software uninstall entry

      • target.tmp (PID: 6984)
    • Reads Environment values

      • WizTree64.exe (PID: 3524)
    • Manual execution by a user

      • firefox.exe (PID: 2744)
    • Application launched itself

      • firefox.exe (PID: 2744)
      • firefox.exe (PID: 5536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
24
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
start ninite wiztree installer.exe ninite.exe no specs ninite.exe target.exe target.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs wiztree64.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2548"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4888 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4792 -prefMapHandle 4732 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {76b0de12-dfff-4b90-8002-a0fa2cc26ea6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca650a6d10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2744"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
3524"C:\Program Files\WizTree\WizTree64.exe" -setlanguage enC:\Program Files\WizTree\WizTree64.exetarget.tmp
User:
admin
Company:
Antibody Software Limited
Integrity Level:
HIGH
Description:
WizTree
Exit code:
0
Version:
4.23.0.0
Modules
Images
c:\program files\wiztree\wiztree64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mpr.dll
3560"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6160 -childID 8 -isForBrowser -prefsHandle 6296 -prefMapHandle 6300 -prefsLen 31324 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cfaed4bc-2952-4ab6-bb78-6b165c29baf2} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca69b3c850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2628 -childID 5 -isForBrowser -prefsHandle 5328 -prefMapHandle 5332 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9ad28a41-75dc-4b40-a44b-460c714f6e9a} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
3692"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -childID 3 -isForBrowser -prefsHandle 5136 -prefMapHandle 5132 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3eab185f-90a7-4c3a-ba53-f61cdc0ccee6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
3736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5868 -childID 6 -isForBrowser -prefsHandle 5824 -prefMapHandle 5856 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e3257ca-5904-4e87-9b61-8ab5b939f755} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68d244d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
5536"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5892"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1824 -parentBuildID 20240213221259 -prefsHandle 1852 -prefMapHandle 1840 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4fba9fd9-5294-43c6-ac9f-7c80c39448bb} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca5ddeab10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
Total events
21 206
Read events
21 179
Write events
27
Delete events
0

Modification events

(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.8 (u)
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\WizTree
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\WizTree\
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Icon Group
Value:
WizTree
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon,quicklaunchicon
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:Inno Setup: Language
Value:
en
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:DisplayName
Value:
WizTree v4.23
(PID) Process:(6984) target.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\WizTree\WizTree.exe
Executable files
12
Suspicious files
220
Text files
73
Unknown types
0

Dropped files

PID
Process
Filename
Type
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:AE1B20C7DC0EA874884868943D24F276
SHA256:1E697D5CD6D4BFC02489B29AA2F35D1BACA86E1498B1F496948EE1997279C84F
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:AFA6A8DDB88654619A8BEF685FC89BE5
SHA256:F779A4937720CEE5AA89F526A3F43ACD4BBF520D7007EC3512ABCE43B1003E90
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:2B44D1584874F492B6406BFCED95A748
SHA256:B9065996A719949883B09F18E0BBFB8D2F691AC1C1581F850F27764306910CDE
6960target.exeC:\Users\admin\AppData\Local\Temp\is-S74G3.tmp\target.tmpexecutable
MD5:E92523CCBE8DB70FFB5D575BC6AD5393
SHA256:1E23CBBD9135490044F608163C867BB5101E70F6C0022EA14FDF7342480F9A31
6984target.tmpC:\Users\admin\AppData\Local\Temp\is-C838Q.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6656Ninite.exeC:\Users\admin\AppData\Local\Temp\16e4151a-d601-11ef-b4ea-18f7786f96ee\target.exeexecutable
MD5:DEAE8661F3643AB1FA58774589459880
SHA256:EDE889913A2B3819B2AA642A1BC46185A91202D854FA3EEC141C6E8E64EDD5C5
6984target.tmpC:\Program Files\WizTree\is-RVB5F.tmpexecutable
MD5:E92523CCBE8DB70FFB5D575BC6AD5393
SHA256:1E23CBBD9135490044F608163C867BB5101E70F6C0022EA14FDF7342480F9A31
6984target.tmpC:\Users\admin\AppData\Local\Temp\is-C838Q.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6984target.tmpC:\Program Files\WizTree\unins000.exeexecutable
MD5:E92523CCBE8DB70FFB5D575BC6AD5393
SHA256:1E23CBBD9135490044F608163C867BB5101E70F6C0022EA14FDF7342480F9A31
6212Ninite WizTree Installer.exeC:\Users\admin\AppData\Local\Temp\150b2203-d601-11ef-b4ea-18f7786f96ee\Ninite.exeexecutable
MD5:AECEA03AB75EA848DC8BB0511A3DFD83
SHA256:168C0280421EC2CEA8ADCF34A22056839F32DF0AC3575B08F98001A10AD587C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
53
TCP/UDP connections
194
DNS requests
235
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5536
firefox.exe
POST
200
184.24.77.53:80
http://r10.o.lencr.org/
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11
unknown
whitelisted
6212
Ninite WizTree Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6656
Ninite.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6212
Ninite WizTree Installer.exe
65.9.66.107:443
ninite.com
AMAZON-02
US
whitelisted
6212
Ninite WizTree Installer.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
5064
SearchApp.exe
104.126.37.170:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6212
Ninite WizTree Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.142
whitelisted
ninite.com
  • 65.9.66.107
  • 65.9.66.56
  • 65.9.66.14
  • 65.9.66.60
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
www.bing.com
  • 104.126.37.170
  • 104.126.37.176
  • 104.126.37.139
  • 104.126.37.185
  • 104.126.37.178
  • 104.126.37.131
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
diskanalyzer.com
  • 23.111.178.178
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.75
whitelisted

Threats

PID
Process
Class
Message
5536
firefox.exe
Device Retrieving External IP Address Detected
ET INFO Possible External IP Lookup Domain Observed in SNI (ipinfo. io)
5536
firefox.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ipinfo.io
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
No debug info