File name:

StartIsBack.Plus.full.2.8.LTSoft.zip

Full analysis: https://app.any.run/tasks/24ade1df-12ff-4bfa-99d6-2d63b39aeda8
Verdict: Malicious activity
Analysis date: November 28, 2023, 18:48:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

22106C66B755AFD87CDB42B9F744A590

SHA1:

FEA0C880AD4D8153C945E17154B1298D10B96593

SHA256:

DBF0B5EA45F55AE7926D4A9E18C2F6498E59489D4FA1EEAD63670D8BDB133240

SSDEEP:

98304:Sf0qk70i28nNBQ2XQ7QjIKnMxC136VeCb0kRRFaGmoGM21W/UqVXCc0Sy6FJnn0F:AHMTW3nA029

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • StartIsBack AIO 1.0.3.exe (PID: 1728)
      • StartIsBack AIO 1.0.3.exe (PID: 880)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Create files in a temporary directory

      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • StartIsBack AIO 1.0.3.exe (PID: 880)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
      • StartIsBack AIO 1.0.3.exe (PID: 1728)
    • Manual execution by a user

      • cmd.exe (PID: 476)
      • notepad.exe (PID: 2504)
      • StartIsBack AIO 1.0.3.exe (PID: 880)
      • StartIsBack AIO 1.0.3.exe (PID: 1728)
      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • chrome.exe (PID: 3400)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
    • Checks supported languages

      • StartIsBack AIO 1.0.3.exe (PID: 1728)
      • StartIsBack AIO 1.0.3.exe (PID: 880)
      • StartIsBack AIO 1.0.3.tmp (PID: 2984)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • StartIsBack AIO 1.0.3.tmp (PID: 1360)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 888)
    • Reads the computer name

      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
    • Reads the machine GUID from the registry

      • StartIsBackPlusPlus_setup.exe (PID: 240)
      • StartIsBackPlusPlus_setup.exe (PID: 3472)
    • Application launched itself

      • chrome.exe (PID: 3400)
    • The process uses the downloaded file

      • chrome.exe (PID: 1232)
      • chrome.exe (PID: 3452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:12:15 02:50:56
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: StartIsBack.Plus.full.2.8.LTSoft/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
89
Monitored processes
38
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs notepad.exe no specs cmd.exe startisback aio 1.0.3.exe startisback aio 1.0.3.tmp no specs startisbackplusplus_setup.exe no specs startisbackcfg.exe no specs startisback aio 1.0.3.exe startisback aio 1.0.3.tmp no specs startisbackplusplus_setup.exe startisbackcfg.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBackPlusPlus_setup.exe" C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBackPlusPlus_setup.exeexplorer.exe
User:
admin
Company:
www.startisback.com
Integrity Level:
MEDIUM
Description:
StartIsBack++ setup SFX
Exit code:
1
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\startisback.plus.full.2.8.ltsoft\startisbackplusplus_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
476"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\Silent Installation.cmd" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
580"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=2244 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
880"C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe
explorer.exe
User:
admin
Company:
StartIsBack AIO
Integrity Level:
HIGH
Description:
StartIsBack AIO 1.0.3 Setup
Exit code:
1
Version:
1.0.3
Modules
Images
c:\users\admin\desktop\startisback.plus.full.2.8.ltsoft\startisback aio 1.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
888"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3136 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1360"C:\Users\admin\AppData\Local\Temp\is-CDOH6.tmp\StartIsBack AIO 1.0.3.tmp" /SL5="$B0210,2083835,145920,C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" C:\Users\admin\AppData\Local\Temp\is-CDOH6.tmp\StartIsBack AIO 1.0.3.tmpStartIsBack AIO 1.0.3.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-cdoh6.tmp\startisback aio 1.0.3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1728"C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe
explorer.exe
User:
admin
Company:
StartIsBack AIO
Integrity Level:
HIGH
Description:
StartIsBack AIO 1.0.3 Setup
Exit code:
1
Version:
1.0.3
Modules
Images
c:\users\admin\desktop\startisback.plus.full.2.8.ltsoft\startisback aio 1.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2080"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3352 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=3152 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
6 684
Read events
6 597
Write events
87
Delete events
0

Modification events

(PID) Process:(888) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3400) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3400) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
Executable files
26
Suspicious files
80
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
3472StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.D7DAAD90\Orbs\Windows 7.orbexecutable
MD5:85328E698E8A74852B4061A683915DC8
SHA256:E5B74E9E7BD6758A0154B11462AE3328EDD143190865198104D8BD53B9AF7275
888WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa888.34423\StartIsBack.Plus.full.2.8.LTSoft\Silent Installation.cmdtext
MD5:5A8536DC6536988A558CE229AD8BDF30
SHA256:6D542C04BA1D727C19F4F1CBC7EB14E1B0B7FE8ECB02D6ADDC2402CCF5D5DF20
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\UpdateCheck.exeexecutable
MD5:71AF6F38F6813897C75DE6D5FB35185F
SHA256:31C1C4D758C7B4C2081AFC21698C7345696313AE9510B6B633DDB10061F80C01
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Orbs\Shamrock.orbexecutable
MD5:EF55E07E1A2E47BB2BB749046CD150B2
SHA256:1A8DAC51758C66A1BB03FBC227B5EDB52EF7379FA3603B62EB3307005D06C9B5
888WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa888.34423\StartIsBack.Plus.full.2.8.LTSoft\LT SOFT » download your necessary app.websitetext
MD5:14AB02EEE603892A4BDB4FC1F168E6A3
SHA256:9BF607D79765E9B29C5597D560C9DB89337ED1A991ABFB3592CCACFE066F03A1
3472StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.D7DAAD90\Orbs\StartIsBack_Ei8htOrb_v2_by_PainteR.bmpimage
MD5:641328C75E6B117545211DB22DAFCAA0
SHA256:76A72C9AD77843B58223DD588483AC1265A31C15AAEB47EE66D1925DE787644B
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Orbs\StartIsBack_Ei8htOrb_v2_by_PainteR.bmpimage
MD5:641328C75E6B117545211DB22DAFCAA0
SHA256:76A72C9AD77843B58223DD588483AC1265A31C15AAEB47EE66D1925DE787644B
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Orbs\Windows 7.orbexecutable
MD5:85328E698E8A74852B4061A683915DC8
SHA256:E5B74E9E7BD6758A0154B11462AE3328EDD143190865198104D8BD53B9AF7275
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\StartIsBack64.dllexecutable
MD5:7CF3562F9FBBE4B31D848E7C5D02E032
SHA256:06BFE27F7531AA0A25FA441C3BC3030EFCEF6DB005CDAEFBD46EC109EF810D6B
240StartIsBackPlusPlus_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Styles\Windows 7.msstylesexecutable
MD5:D8026912ADA984285D8D5FD35B30D76A
SHA256:076B3BF570EC4AF0A01CBC2C6723F380CD57C71A637BE1A1BB0FE3D6557CE92F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
48
DNS requests
90
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3424
chrome.exe
GET
95.101.148.135:8080
http://95.101.148.135:8080/
unknown
unknown
3424
chrome.exe
GET
400
95.101.148.135:80
http://95.101.148.135/
unknown
html
209 b
unknown
3424
chrome.exe
GET
400
95.101.148.135:80
http://95.101.148.135/
unknown
html
209 b
unknown
3424
chrome.exe
GET
95.101.148.135:443
http://95.101.148.135:443/
unknown
unknown
3424
chrome.exe
GET
400
95.101.148.135:80
http://95.101.148.135/favicon.ico
unknown
html
255 b
unknown
3424
chrome.exe
GET
400
95.101.148.135:80
http://95.101.148.135/favicon.ico
unknown
html
255 b
unknown
3424
chrome.exe
GET
95.101.148.135:443
http://95.101.148.135:443/
unknown
unknown
3424
chrome.exe
GET
95.101.148.135:443
http://95.101.148.135:443/
unknown
unknown
3424
chrome.exe
GET
95.101.148.135:443
http://95.101.148.135:443/
unknown
unknown
868
svchost.exe
HEAD
403
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYWM3QUFZQV9zN2JXZFNHTWhCbGtIMVUwdw/1.0.0.14_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
868
svchost.exe
95.101.148.135:80
Akamai International B.V.
NL
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
2.20.40.170:80
armmf.adobe.com
AKAMAI-AS
NL
unknown
3424
chrome.exe
142.250.187.227:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
3400
chrome.exe
239.255.255.250:1900
whitelisted
3424
chrome.exe
66.102.1.84:443
accounts.google.com
GOOGLE
US
unknown
3424
chrome.exe
172.217.169.4:443
www.google.com
GOOGLE
US
whitelisted
3400
chrome.exe
224.0.0.251:5353
unknown
3424
chrome.exe
142.250.180.3:443
www.gstatic.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 2.20.40.170
whitelisted
clientservices.googleapis.com
  • 142.250.187.227
whitelisted
accounts.google.com
  • 66.102.1.84
shared
www.google.com
  • 172.217.169.4
whitelisted
www.gstatic.com
  • 142.250.180.3
whitelisted
update.googleapis.com
  • 142.250.180.3
whitelisted
optimizationguide-pa.googleapis.com
  • 172.217.169.42
whitelisted
encrypted-tbn0.gstatic.com
  • 142.250.178.14
whitelisted
www.googleapis.com
  • 142.250.179.234
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info