File name:

Ninite CutePDF Foxit Reader SumatraPDF Installer.exe

Full analysis: https://app.any.run/tasks/c08fbab8-f6b5-48ad-8293-a4f1767b6f78
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 18, 2025, 07:00:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

21A5721DDAA06536AF0A0B2C7481DEA8

SHA1:

C16DDC3E816E12CFF8BB1C52E0A3996EC8D62047

SHA256:

E7DB1B675A3942DFEEFBFB75EE16B287FFFABAA8D5292A13545CAA974FFC6ABB

SSDEEP:

12288:XLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEn:bVP60BM2pMUN9keo+c+zEn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7224)
      • Ninite.exe (PID: 7420)
    • Executable content was dropped or overwritten

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • target.exe (PID: 7708)
      • gs.exe (PID: 4208)
      • Ninite.exe (PID: 7420)
    • Application launched itself

      • Ninite.exe (PID: 7224)
    • Searches for installed software

      • Ninite.exe (PID: 7420)
    • Potential Corporate Privacy Violation

      • Ninite.exe (PID: 7420)
    • The process creates files with name similar to system file names

      • gs.exe (PID: 4208)
    • Process requests binary or script from the Internet

      • Ninite.exe (PID: 7420)
    • Creates a software uninstall entry

      • target.exe (PID: 7708)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • gs.exe (PID: 4208)
  • INFO

    • Reads the computer name

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7224)
      • Ninite.exe (PID: 7420)
      • gs.exe (PID: 4208)
      • target.exe (PID: 7708)
    • Checks supported languages

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7224)
      • Ninite.exe (PID: 7420)
      • target.exe (PID: 7708)
      • gs.exe (PID: 4208)
    • The sample compiled with english language support

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
      • target.exe (PID: 7708)
    • Reads the machine GUID from the registry

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
    • Creates files or folders in the user directory

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
    • Checks proxy server information

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
    • Create files in a temporary directory

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
      • gs.exe (PID: 4208)
    • Reads the software policy settings

      • Ninite CutePDF Foxit Reader SumatraPDF Installer.exe (PID: 4488)
      • Ninite.exe (PID: 7420)
    • Process checks computer location settings

      • Ninite.exe (PID: 7224)
    • Reads CPU info

      • target.exe (PID: 7708)
    • Creates files in the program directory

      • target.exe (PID: 7708)
      • gs.exe (PID: 4208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ninite cutepdf foxit reader sumatrapdf installer.exe ninite.exe no specs sppextcomobj.exe no specs slui.exe no specs ninite.exe target.exe gs.exe

Process information

PID
CMD
Path
Indicators
Parent process
4208gs.exe /SC:\Users\admin\AppData\Local\Temp\c43616c7-33b5-11f0-b4ed-18f7786f96ee\gs.exe
Ninite.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\c43616c7-33b5-11f0-b4ed-18f7786f96ee\gs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4488"C:\Users\admin\AppData\Local\Temp\Ninite CutePDF Foxit Reader SumatraPDF Installer.exe" C:\Users\admin\AppData\Local\Temp\Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
explorer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Version:
0,1,1,1183
Modules
Images
c:\users\admin\appdata\local\temp\ninite cutepdf foxit reader sumatrapdf installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7224Ninite.exe "fc6b7c3ae957183095ebb46792a4543c10413d8e" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite CutePDF Foxit Reader SumatraPDF Installer.exe"C:\Users\admin\AppData\Local\Temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\Ninite.exeNinite CutePDF Foxit Reader SumatraPDF Installer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Version:
0,1,1,1486
Modules
Images
c:\users\admin\appdata\local\temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7292C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7324"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7420"C:\Users\admin\AppData\Local\Temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\Ninite.exe" "fc6b7c3ae957183095ebb46792a4543c10413d8e" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite CutePDF Foxit Reader SumatraPDF Installer.exe" /relaunchC:\Users\admin\AppData\Local\Temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\Ninite.exe
Ninite.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
HIGH
Description:
Ninite
Version:
0,1,1,1486
Modules
Images
c:\users\admin\appdata\local\temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7708C:\Users\admin\AppData\Local\Temp\C43616~1\target.exe -install -all-users /sC:\Users\admin\AppData\Local\Temp\c43616c5-33b5-11f0-b4ed-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
Krzysztof Kowalczyk
Integrity Level:
HIGH
Description:
SumatraPDF
Exit code:
0
Version:
3.5.2
Modules
Images
c:\users\admin\appdata\local\temp\c43616c5-33b5-11f0-b4ed-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
8 258
Read events
8 055
Write events
152
Delete events
51

Modification events

(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\PersistentHandler
Operation:delete keyName:(default)
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers
Operation:delete valueName:{3D3B1846-CC43-42AE-BFF9-D914083C2BA3}
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Operation:delete keyName:(default)
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers
Operation:delete valueName:{C29D3E2B-8FF6-4033-A4E8-54221D859D74}
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers
Operation:delete valueName:{CB1D63A6-FE5E-4DED-BEA5-3F6AF1A70D08}
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers
Operation:delete valueName:{6689D0D4-1E9C-400A-8BCA-FA6C56B2C3B5}
Value:
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDF
Operation:writeName:DisplayIcon
Value:
C:\Program Files\SumatraPDF\SumatraPDF.exe
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDF
Operation:writeName:DisplayName
Value:
SumatraPDF
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDF
Operation:writeName:DisplayVersion
Value:
3.5.2
(PID) Process:(7708) target.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDF
Operation:writeName:EstimatedSize
Value:
22886
Executable files
11
Suspicious files
335
Text files
340
Unknown types
0

Dropped files

PID
Process
Filename
Type
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:6EABDEAE700B6D4D3AF6B5EB923761A7
SHA256:ED369BCF6466E4380DB9AC33B8F31456C832BDF6AE651A910CE657A01C47A8CD
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\Local\Temp\c246360f-33b5-11f0-b4ed-18f7786f96ee\Ninite.exeexecutable
MD5:8C2C71081C6AFB8884501914E81FA20D
SHA256:AE60E4F6ED4EC4AA15E5A957A3A659AD06BB051A1C5BAF536B2D452CCF3D5494
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:3EC1FD62066E4A4CF2674C9953DA56A4
SHA256:50170190AC2CA0C7AFA46807AB6C154B1B44CD611E164735E723E1B917AE65C3
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:8F2B58FEABAF533FDD05C5FF5CC794B8
SHA256:2DA5EED36683079838D6E2CCFF0DCB6AFCACAFC429AEC55706BC2342F464DFF6
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:A8CE3579A859A959CF25C1475B4C5BE0
SHA256:A96402357612A3D64599E952E6BC6BDA98301110C6ADD5144C53C055D96DD3E2
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_6C354C532D063DF5607A63BA827F5164binary
MD5:EDD5E410935877BDC554A9F139195DA4
SHA256:F3D54F3E70BDAF8E17882555CF206DA30B8898EDE25AF0E4DE5D16027CAFB499
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:C944CEEAB285C65A8E8351F13ADBAF28
SHA256:B25F88DD6BB7B7CD2083EDDC1DEBD698113CB71C2E667E43CE9E5A93D02DBEEA
7420Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:E192462F281446B5D1500D474FBACC4B
SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60
7420Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
4488Ninite CutePDF Foxit Reader SumatraPDF Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_6C354C532D063DF5607A63BA827F5164binary
MD5:54AB39EF3BED4C35DD75CA267BE18836
SHA256:33599814A62509BD0FD4854013CB0E1304743464191B68914315C6FDF306DCA1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
47
DNS requests
28
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgOhtwj4VKsGchDZBEc%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7420
Ninite.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
7420
Ninite.exe
GET
200
142.250.185.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
7420
Ninite.exe
GET
200
142.250.185.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
65.9.66.107:443
ninite.com
AMAZON-02
US
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
4488
Ninite CutePDF Foxit Reader SumatraPDF Installer.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.206
whitelisted
ninite.com
  • 65.9.66.107
  • 65.9.66.56
  • 65.9.66.60
  • 65.9.66.14
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.66
  • 20.190.160.3
  • 20.190.160.130
  • 40.126.32.134
  • 40.126.32.68
  • 20.190.160.20
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
www.sumatrapdfreader.org
  • 138.201.51.123
whitelisted

Threats

PID
Process
Class
Message
7420
Ninite.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info