| File name: | fl_studio_produc_edition_20_8_3_id898832ids1s.exe |
| Full analysis: | https://app.any.run/tasks/b1ec2c7c-88c8-4437-b1ab-645228a55bfe |
| Verdict: | Malicious activity |
| Analysis date: | June 08, 2021, 10:41:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F861D8212A77EC9F21FF8803C63E4245 |
| SHA1: | 3100990CD72C6D16FDC3067B9C81155039351490 |
| SHA256: | E04A22D06A0AC6EA4D16A69D74AF36C15F2BB85619A28FF7778C6B348D84EA85 |
| SSDEEP: | 49152:zgSCSkKipF0lTrdF+kqUEgdIkdpM7j+e/JoN64qR+JkgBHvKVu6YLqpDtIJxQ0oZ:zgXKiXuTREFUEYI7j+e/JoNVY+JkgBPi |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:03 10:41:11+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 1480192 |
| InitializedDataSize: | 1462272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x160025 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | - |
| FileVersion: | 1 |
| InternalName: | - |
| LegalCopyright: | - |
| OriginalFileName: | - |
| ProductName: | - |
| ProductVersion: | 1 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 03-Jun-2021 08:41:11 |
| Detected languages: |
|
| Comments: | - |
| CompanyName: | - |
| FileDescription: | - |
| FileVersion: | 1.0 |
| InternalName: | - |
| LegalCopyright: | - |
| OriginalFilename: | - |
| ProductName: | - |
| ProductVersion: | 1.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000120 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 03-Jun-2021 08:41:11 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x001694B4 | 0x00169600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62321 |
.rdata | 0x0016B000 | 0x00074240 | 0x00074400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.16162 |
.data | 0x001E0000 | 0x0000F500 | 0x00009600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.15037 |
.rsrc | 0x001F0000 | 0x000D1484 | 0x000D1600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.82695 |
.reloc | 0x002C2000 | 0x00015E56 | 0x00016000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.05543 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.22706 | 820 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.18073 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 5.05232 | 2440 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.75162 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
128 | 2.62308 | 62 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
129 | 1.67172 | 170 | Latin 1 / Western European | English - United States | UNKNOWN |
HTML | 7.9997 | 570669 | Latin 1 / Western European | Russian - Russia | ARCHIVE_7Z |
PRELOADER | 7.98607 | 15254 | Latin 1 / Western European | Russian - Russia | ARCHIVE_7Z |
CABUNDLE | 6.0253 | 227153 | Latin 1 / Western European | Russian - Russia | CRT |
YACLIDS | 3.22226 | 22061 | Latin 1 / Western European | Russian - Russia | TXT |
ADVAPI32.dll |
COMCTL32.dll |
CRYPT32.dll |
GDI32.dll |
KERNEL32.dll |
MSVCR90.dll |
OLEAUT32.dll |
OPENGL32.dll |
PSAPI.DLL |
SHELL32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 256 | "C:\Users\admin\AppData\Local\Temp\is-08KNV.tmp\lum_inst.tmp" /SL5="$30150,2205721,121344,C:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exe" /verysilent | C:\Users\admin\AppData\Local\Temp\is-08KNV.tmp\lum_inst.tmp | lum_inst.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 101 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 580 | "C:\Users\admin\MediaGet2\QtWebEngineProcess.exe" --type=renderer --disable-speech-api --enable-threaded-compositing --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --disable-gpu-compositing --lang=en-US --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2512 /prefetch:1 | C:\Users\admin\MediaGet2\QtWebEngineProcess.exe | — | mediaget.exe | |||||||||||
User: admin Company: The Qt Company Ltd. Integrity Level: LOW Description: C++ Application Development Framework Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 1148 | C:\Users\admin\MediaGet2\mediaget_crashpad_handler.exe --no-rate-limit "--database=C:\Users\admin\AppData\Local\Media Get LLC\MediaGet2\crashdumps" "--metrics-dir=C:\Users\admin\AppData\Local\Media Get LLC\MediaGet2\crashdumps" --url=https://o612922.ingest.sentry.io:443/api/5751793/minidump/?sentry_client=sentry.native/0.4.6&sentry_key=b129893601654617990d7dd2cb86abed "--attachment=C:/Users/admin/AppData/Local/Media Get LLC/MediaGet2/crashdumps/logs/log" "--attachment=C:\Users\admin\AppData\Local\Media Get LLC\MediaGet2\crashdumps\59a3b023-3f8b-453f-5ee3-e5bae6a7b693.run\__sentry-event" "--attachment=C:\Users\admin\AppData\Local\Media Get LLC\MediaGet2\crashdumps\59a3b023-3f8b-453f-5ee3-e5bae6a7b693.run\__sentry-breadcrumb1" "--attachment=C:\Users\admin\AppData\Local\Media Get LLC\MediaGet2\crashdumps\59a3b023-3f8b-453f-5ee3-e5bae6a7b693.run\__sentry-breadcrumb2" --initial-client-data=0x3cc,0x3d0,0x3d4,0x3a0,0x3d8,0x6a9b7b7c,0x6a9b7b90,0x6a9b7ba0 | C:\Users\admin\MediaGet2\mediaget_crashpad_handler.exe | — | mediaget.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1936 | "C:\Users\admin\MediaGet2\QtWebEngineProcess.exe" --type=renderer --disable-speech-api --enable-threaded-compositing --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --disable-gpu-compositing --lang=en-US --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3272 /prefetch:1 | C:\Users\admin\MediaGet2\QtWebEngineProcess.exe | — | mediaget.exe | |||||||||||
User: admin Company: The Qt Company Ltd. Integrity Level: LOW Description: C++ Application Development Framework Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 1944 | "C:\Users\admin\AppData\Local\Temp\fl_studio_produc_edition_20_8_3_id898832ids1s.exe" | C:\Users\admin\AppData\Local\Temp\fl_studio_produc_edition_20_8_3_id898832ids1s.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.0 Modules
| |||||||||||||||
| 2504 | C:\Users\admin\MediaGet2\Luminati-m\test_wpf.exe | C:\Users\admin\MediaGet2\Luminati-m\test_wpf.exe | — | net_updater32.exe | |||||||||||
User: SYSTEM Company: Luminati Networks Ltd. Integrity Level: SYSTEM Description: test_wpf Exit code: 0 Version: 1.237.241 Modules
| |||||||||||||||
| 2520 | C:\Users\admin\MediaGet2\Luminati-m\luminati-m-controller.exe is_switch_on | C:\Users\admin\MediaGet2\Luminati-m\luminati-m-controller.exe | mediaget.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 101 Modules
| |||||||||||||||
| 2596 | "C:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exe" /verysilent | C:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exe | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | ||||||||||||
User: admin Company: luminati Integrity Level: HIGH Description: luminati Setup Exit code: 101 Version: Modules
| |||||||||||||||
| 2624 | "C:\Users\admin\MediaGet2\Luminati-m\net_updater32.exe" --install-ui win_mediaget.com --dlg-app-name MediaGet --dlg-tos-link "https://mediaget.com/license" --dlg-benefit-txt "MediaGet (Ad free)" --dlg-logo-link "https://mediaget.com/installer/binaries/mg-icon-400.png" --dlg-not-peer-txt ads --dlg-peer-txt remove_ads | C:\Users\admin\MediaGet2\Luminati-m\net_updater32.exe | lum_inst.tmp | ||||||||||||
User: admin Company: Luminati Networks Ltd. Integrity Level: HIGH Description: Luminati SDK Updater Exit code: 1 Version: 1.237.241 Modules
| |||||||||||||||
| 2668 | "C:\Users\admin\AppData\Local\Temp\fl_studio_produc_edition_20_8_3_id898832ids1s.exe" | C:\Users\admin\AppData\Local\Temp\fl_studio_produc_edition_20_8_3_id898832ids1s.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.0 Modules
| |||||||||||||||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Media Get LLC\MediaGet2-systemScope\mediaget_info |
| Operation: | write | Name: | hasDownloadedUpdate |
Value: false | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Width |
Value: 318 | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Height |
Value: 288 | |||
| (PID) Process: | (2668) fl_studio_produc_edition_20_8_3_id898832ids1s.exe | Key: | HKEY_CURRENT_USER\Software\MediaGet |
| Operation: | write | Name: | (default) |
Value: C:\Users\admin\MediaGet2\mediaget.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\Documents\write_file_test | — | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\opera\opera-back678-2.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\infatica1.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\opera\opera-back678-1.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\infatica2.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\rucola1.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\accept-green-en.png | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\img\rucola2.jpg | image | |
MD5:— | SHA256:— | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\preloader.html | html | |
MD5:3E2A88C55776A6118C91B8B11D5211A3 | SHA256:57B689D69089B3DE9BE51928FE6C9A08664F986BC68EBABBB886BF3C26B1EC03 | |||
| 2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | C:\Users\admin\AppData\Local\Temp\mediaget-installer-tmp\mediaget-logo.png | image | |
MD5:A27C51E0821FF975C33C70578BBE1D97 | SHA256:29EBD96D14DEE8E335A674BF093AF7ABFD1CBD931B3277516FBCD037366D1344 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4000 | mediaget.exe | GET | — | 193.34.49.213:6969 | http://tracker.dler.org:6969/announce?info_hash=%fa%f8%8f%dd%40XH%e8%b4%10%fez%ca%e4%e4%807%fa%89(&peer_id=-KN31%f80-em(KO8h-S).J&port=30189&uploaded=0&downloaded=0&left=26079978&corrupt=0&key=B223CC3D&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0 | DE | — | — | suspicious |
3388 | QtWebEngineProcess.exe | GET | 200 | 23.197.4.103:80 | http://x1.c.lencr.org/ | NL | der | 717 b | whitelisted |
4000 | mediaget.exe | GET | 200 | 195.82.146.120:80 | http://bt.t-ru.org/ann?info_hash=%fa%f8%8f%dd%40XH%e8%b4%10%fez%ca%e4%e4%807%fa%89(&peer_id=-KN31%f80-em(KO8h-S).J&port=30189&uploaded=0&downloaded=0&left=26079978&corrupt=0&key=B223CC3D&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0 | RU | text | 96 b | malicious |
3388 | QtWebEngineProcess.exe | GET | 200 | 92.122.214.152:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMzVp8L8MUjyiOjKl0QCvci3g%3D%3D | unknown | der | 503 b | shared |
3388 | QtWebEngineProcess.exe | GET | 200 | 92.122.214.144:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | unknown | der | 1.16 Kb | whitelisted |
3388 | QtWebEngineProcess.exe | GET | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | US | der | 724 b | whitelisted |
4000 | mediaget.exe | GET | 200 | 109.120.150.23:80 | http://prime-oblako.ru/file/fl_studio_prod_edition_20_8_3.zip | RU | compressed | 679 b | unknown |
3388 | QtWebEngineProcess.exe | GET | 200 | 104.18.21.226:80 | http://crl.globalsign.net/root-r2.crl | US | der | 950 b | whitelisted |
3388 | QtWebEngineProcess.exe | GET | 200 | 92.122.214.152:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOytzRAz0in7IAZhIardH7O%2Fg%3D%3D | unknown | der | 503 b | shared |
3388 | QtWebEngineProcess.exe | GET | 200 | 5.45.205.244:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEDbEISBuJVGq0KdX46enAhA%3D | RU | der | 1.48 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2624 | net_updater32.exe | 162.125.66.15:443 | ucdc82573acef5aa44a625a1d8e8.dl.dropboxusercontent.com | Dropbox, Inc. | DE | malicious |
2624 | net_updater32.exe | 104.248.48.136:443 | perr.l-err.biz | — | US | suspicious |
2624 | net_updater32.exe | 128.199.170.164:80 | 128-199-170-164.l-cdn.com | Digital Ocean, Inc. | SG | unknown |
2624 | net_updater32.exe | 104.131.116.66:80 | 104-131-116-66.l-cdn.com | Digital Ocean, Inc. | US | unknown |
2624 | net_updater32.exe | 3.228.177.90:443 | clientsdk.lum-sdk.io | — | US | suspicious |
2668 | fl_studio_produc_edition_20_8_3_id898832ids1s.exe | 23.111.31.137:443 | mediaget.com | Servers.com, Inc. | NL | unknown |
2624 | net_updater32.exe | 3.228.36.186:443 | clientsdk.lum-sdk.io | — | US | suspicious |
— | — | 3.228.36.186:443 | clientsdk.lum-sdk.io | — | US | suspicious |
2624 | net_updater32.exe | 142.93.243.99:443 | perr.l-err.biz | — | CA | suspicious |
2924 | net_updater32.exe | 142.93.243.99:443 | perr.l-err.biz | — | CA | suspicious |
Domain | IP | Reputation |
|---|---|---|
mediaget.com |
| suspicious |
www.dropbox.com |
| shared |
ucdc82573acef5aa44a625a1d8e8.dl.dropboxusercontent.com |
| malicious |
perr.l-err.biz |
| suspicious |
perr.l-agent.me |
| suspicious |
perr.lum-sdk.io |
| suspicious |
128-199-170-164.l-cdn.com |
| unknown |
104-131-116-66.l-cdn.com |
| unknown |
clientsdk.lum-sdk.io |
| suspicious |
clientsdk.luminatinet.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
2624 | net_updater32.exe | Potential Corporate Privacy Violation | ET POLICY Dropbox.com Offsite File Backup in Use |
1064 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2624 | net_updater32.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |