File name:

e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe

Full analysis: https://app.any.run/tasks/9afc11af-ecd2-47a1-881e-a97ed134069c
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: October 03, 2025, 17:03:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
snake
keylogger
evasion
telegram
anti-evasion
stealer
ftp
purecrypter
netreactor
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

1DD3800AFC130F58D1795CD845E120D9

SHA1:

143F1CE5C907AACD9736871F73C2631E00D62498

SHA256:

E45A11DFD7E9B1A6DBD2F2A75C669AE8B7A6912CD0CA5E30E37510D20DD04E2E

SSDEEP:

49152:zG8C+hhUw9Ysu8m+9uF1ao7sm5Hn0v4hSvY2Ng/HNpT:z9C+hOUuv3pNE4hSvY2sT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
    • SNAKEKEYLOGGER has been detected (SURICATA)

      • InstallUtil.exe (PID: 5868)
    • Steals credentials from Web Browsers

      • InstallUtil.exe (PID: 5868)
    • Actions looks like stealing of personal data

      • InstallUtil.exe (PID: 5868)
    • PURECRYPTER has been detected (YARA)

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
    • Checks for external IP

      • svchost.exe (PID: 2428)
      • InstallUtil.exe (PID: 5868)
    • The process checks if it is being run in the virtual environment

      • InstallUtil.exe (PID: 5868)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • InstallUtil.exe (PID: 5868)
    • Loads DLL from Mozilla Firefox

      • InstallUtil.exe (PID: 5868)
    • Connects to unusual port

      • InstallUtil.exe (PID: 5868)
    • Connects to FTP

      • InstallUtil.exe (PID: 5868)
  • INFO

    • Checks supported languages

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • InstallUtil.exe (PID: 5868)
    • Launching a file from the Startup directory

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
    • Creates files or folders in the user directory

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • BackgroundTransferHost.exe (PID: 1288)
    • Reads the machine GUID from the registry

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • InstallUtil.exe (PID: 5868)
    • Reads the computer name

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • InstallUtil.exe (PID: 5868)
    • Manual execution by a user

      • InstallUtil.exe (PID: 5868)
    • Reads Environment values

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • InstallUtil.exe (PID: 5868)
    • Disables trace logs

      • InstallUtil.exe (PID: 5868)
    • Checks proxy server information

      • InstallUtil.exe (PID: 5868)
      • BackgroundTransferHost.exe (PID: 1288)
    • Reads the software policy settings

      • InstallUtil.exe (PID: 5868)
      • BackgroundTransferHost.exe (PID: 1288)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 1288)
      • BackgroundTransferHost.exe (PID: 6416)
      • BackgroundTransferHost.exe (PID: 6156)
      • BackgroundTransferHost.exe (PID: 8056)
      • BackgroundTransferHost.exe (PID: 8056)
    • .NET Reactor protector has been detected

      • e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe (PID: 7084)
      • InstallUtil.exe (PID: 5868)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:10:03 00:47:19+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 1164800
InitializedDataSize: 1536
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.8677.18734
ProductVersionNumber: 1.0.8677.18734
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Idumdepuv
FileVersion: 1.0.8677.18734
InternalName: Idumdepuv.exe
LegalCopyright: Copyright © 2022
LegalTrademarks: -
OriginalFileName: Idumdepuv.exe
ProductName: Idumdepuv
ProductVersion: 1.0.8677.18734
AssemblyVersion: 1.0.7991.8798
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
177
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1288"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
5296C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5868"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
.NET Framework installation utility
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\installutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6156"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
6416"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7084"C:\Users\admin\AppData\Local\Temp\e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe" C:\Users\admin\AppData\Local\Temp\e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Idumdepuv
Exit code:
4294967295
Version:
1.0.8677.18734
Modules
Images
c:\users\admin\appdata\local\temp\e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
8056"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8056"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
3 899
Read events
3 870
Write events
29
Delete events
0

Modification events

(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5868) InstallUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\InstallUtil_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
1
Suspicious files
5
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\12c3796d-6cd1-46d0-b519-3e2cf25160d0.down_data
MD5:
SHA256:
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f80ccf3f-43b6-46e4-9565-b3e9794b263e.up_meta_securebinary
MD5:043CA4067469A3EE19624215731C7951
SHA256:705378EED210AC35E0BD5635AEBEFCCAB5B0C8F170CA494519529793F0571FB9
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
7084e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IsSpecialName.vbstext
MD5:66A3DF1974DB8ABAA9DD306D24478686
SHA256:1324E0EA97814D72EE358E1A2229D62E0E10AF95F396E1D725EC0B206D92E0CB
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f80ccf3f-43b6-46e4-9565-b3e9794b263e.c1d6ffd7-9e14-40f3-ad2c-1768f0ead201.down_metabinary
MD5:DB57EC9D0507238ECF89981AE2C49F39
SHA256:3A1876873C48FF05CA0A1AECD7A6FFF4B440410A367E51C36DB8A87A41A2AA9B
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:31D267402E3879DCA268523D34ECDA51
SHA256:CA88D621CDE95E091D606F9F17BC2C43C75E206227FEACCFEAF6C96FBE43E7D8
1288BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\12c3796d-6cd1-46d0-b519-3e2cf25160d0.c1d6ffd7-9e14-40f3-ad2c-1768f0ead201.down_metabinary
MD5:DB57EC9D0507238ECF89981AE2C49F39
SHA256:3A1876873C48FF05CA0A1AECD7A6FFF4B440410A367E51C36DB8A87A41A2AA9B
7084e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e.exeC:\Users\admin\AppData\Roaming\IsSpecialName.exeexecutable
MD5:1DD3800AFC130F58D1795CD845E120D9
SHA256:E45A11DFD7E9B1A6DBD2F2A75C669AE8B7A6912CD0CA5E30E37510D20DD04E2E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
39
DNS requests
21
Threats
22

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
5868
InstallUtil.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
JP
html
106 b
whitelisted
4776
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3628
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5868
InstallUtil.exe
132.226.8.169:80
checkip.dyndns.org
ORACLE-BMC-31898
JP
whitelisted
4
System
192.168.100.255:138
whitelisted
5868
InstallUtil.exe
188.114.96.3:443
reallyfreegeoip.org
CLOUDFLARENET
NL
malicious
5868
InstallUtil.exe
149.154.167.220:443
api.telegram.org
Telegram Messenger Inc
GB
whitelisted
5868
InstallUtil.exe
188.127.239.250:21
backup.smartape.ru
LLC Smart Ape
EE
malicious
5868
InstallUtil.exe
188.127.239.250:35757
backup.smartape.ru
LLC Smart Ape
EE
malicious
5224
SearchApp.exe
95.101.136.201:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.238
whitelisted
checkip.dyndns.org
  • 132.226.8.169
  • 193.122.130.0
  • 158.101.44.242
  • 193.122.6.168
  • 132.226.247.73
whitelisted
reallyfreegeoip.org
  • 188.114.96.3
  • 188.114.97.3
malicious
api.telegram.org
  • 149.154.167.220
whitelisted
backup.smartape.ru
  • 188.127.239.250
malicious
www.bing.com
  • 95.101.136.201
  • 95.101.136.194
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.207
whitelisted
login.live.com
  • 40.126.31.131
  • 40.126.31.0
  • 20.190.159.0
  • 40.126.31.130
  • 20.190.159.128
  • 20.190.159.73
  • 40.126.31.128
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Device Retrieving External IP Address Detected
ET DYN_DNS External IP Lookup Domain in DNS Query (checkip .dyndns .org)
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO 404/Snake/Matiex Keylogger Style External IP Check
2428
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Address Lookup Domain (reallyfreegeoip .org)
5868
InstallUtil.exe
Misc activity
ET INFO External IP Lookup Service Domain (reallyfreegeoip .org) in TLS SNI
2428
svchost.exe
Misc activity
ET INFO External IP Address Lookup Domain in DNS Lookup (reallyfreegeoip .org)
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
5868
InstallUtil.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
No debug info