URL:

https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe

Full analysis: https://app.any.run/tasks/acc3e902-9dad-4584-80c4-d9a2c44f912d
Verdict: Malicious activity
Analysis date: November 13, 2024, 11:37:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

BE27889697699E5A153485700F962C69

SHA1:

5C266FF0C0723FA71DE0979374BAF37A240EB657

SHA256:

E89E1A4C58F19523A4265A76D765D36B5E52A9986A10C603B9DCC8A5943AFB87

SSDEEP:

3:N8UxXYL2SKIfohDNSlTXK2aA:2UxoL2SKMo6XGA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • firefox.exe (PID: 6624)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 2784)
      • pnputil.exe (PID: 1048)
      • drvinst.exe (PID: 7600)
      • pnputil.exe (PID: 5912)
      • drvinst.exe (PID: 2684)
      • drvinst.exe (PID: 5652)
      • IndiDriverInstallUtilx64.exe (PID: 7092)
      • drvinst.exe (PID: 7528)
      • pnputil.exe (PID: 7592)
    • The process creates files with name similar to system file names

      • Setup.exe (PID: 2784)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Setup.exe (PID: 2784)
    • Drops a system driver (possible attempt to evade defenses)

      • pnputil.exe (PID: 1048)
      • Setup.exe (PID: 2784)
      • drvinst.exe (PID: 7600)
      • pnputil.exe (PID: 5912)
      • IndiDriverInstallUtilx64.exe (PID: 7092)
      • drvinst.exe (PID: 2684)
      • drvinst.exe (PID: 7528)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7600)
      • drvinst.exe (PID: 2684)
    • The process drops C-runtime libraries

      • Setup.exe (PID: 2784)
    • Process drops legitimate windows executable

      • Setup.exe (PID: 2784)
    • Executes as Windows Service

      • DPMService.exe (PID: 6856)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 6624)
      • firefox.exe (PID: 1576)
    • Reads the software policy settings

      • slui.exe (PID: 6168)
      • drvinst.exe (PID: 7600)
    • Checks supported languages

      • Setup.exe (PID: 2784)
      • drvinst.exe (PID: 7600)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6624)
    • Reads the computer name

      • Setup.exe (PID: 2784)
    • The process uses the downloaded file

      • firefox.exe (PID: 6624)
    • Creates files in the program directory

      • Setup.exe (PID: 2784)
    • Create files in a temporary directory

      • Setup.exe (PID: 2784)
      • pnputil.exe (PID: 1048)
      • pnputil.exe (PID: 7592)
      • pnputil.exe (PID: 5912)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7600)
    • Sends debugging messages

      • DPM.exe (PID: 6472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
186
Monitored processes
45
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe slui.exe setup.exe no specs setup.exe pnputil.exe conhost.exe no specs drvinst.exe pnputil.exe conhost.exe no specs drvinst.exe pnputil.exe conhost.exe no specs drvinst.exe indidriverinstallutilx64.exe no specs conhost.exe no specs indidriverinstallutilx64.exe conhost.exe no specs drvinst.exe drvinst.exe no specs dpmservice.exe no specs conhost.exe no specs dpmservice.exe no specs conhost.exe no specs installerhelper.exe no specs conhost.exe no specs dpmservice.exe no specs conhost.exe no specs dpmcrashhandler.exe no specs dpmservice.exe dpmcrashhandler.exe no specs dpm.exe dpmcrashhandler.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2832 -childID 1 -isForBrowser -prefsHandle 2824 -prefMapHandle 2820 -prefsLen 26798 -prefMapSize 244343 -jsInitHandle 1316 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {503e4128-b736-4fe4-8c9f-c6aa80a2231b} 6624 "\\.\pipe\gecko-crash-server-pipe.6624" 207a6585150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
848\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDPMService.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1048"C:\WINDOWS\system32\PnPutil.exe" /add-driver "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents\WacHIDRouterISDU.inf" /installC:\Windows\System32\pnputil.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pnputil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\devobj.dll
c:\windows\system32\advapi32.dll
1172"C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\database" "--metrics-dir=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x648,0x678,0x67c,0x674,0x684,0x7ff6edbcb658,0x7ff6edbcb670,0x7ff6edbcb688C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exeDPM.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\dell\dell peripheral manager\dpmcrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1200"C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\database" "--metrics-dir=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x504,0x52c,0x530,0x528,0x538,0x7ff7a07f1958,0x7ff7a07f1970,0x7ff7a07f1988C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exeDPMService.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\dell\dell peripheral manager\dpmcrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1576"C:\Program Files\Mozilla Firefox\firefox.exe" "https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
2684DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d49fcc1f-1195-5041-b4f4-14bdcbc806ec}\WacHIDRouterISDF.inf" "9" "423699577" "00000000000001EC" "WinSta0\Default" "00000000000001FC" "208" "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2784"C:\Users\admin\Downloads\Setup.exe" C:\Users\admin\Downloads\Setup.exe
firefox.exe
User:
admin
Company:
Dell
Integrity Level:
HIGH
Description:
Dell Peripheral Manager Installer
Exit code:
0
Version:
${FILE_VERSION}
Modules
Images
c:\users\admin\downloads\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3024"C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe" -regserverC:\Program Files\Dell\Dell Peripheral Manager\DPMService.exeSetup.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Peripheral Manager Service
Exit code:
0
Version:
1.7.7
Modules
Images
c:\program files\dell\dell peripheral manager\dpmservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wintrust.dll
c:\program files\dell\dell peripheral manager\qt5network.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
3620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepnputil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
47 654
Read events
47 530
Write events
116
Delete events
8

Modification events

(PID) Process:(6624) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6624) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(1048) pnputil.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver
Operation:writeName:Owners
Value:
oem8.inf
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver\Parameters\Wdf
Operation:writeName:KmdfLibraryVersion
Value:
1.15
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemRoot%/System32/drivers/DPMDriver.sys
Operation:writeName:Owners
Value:
oem8.inf
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Configuration
Value:
DPMDriver_Device.NT
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Manufacturer
Value:
%manufacturername%
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Description
Value:
%dpmdriver.devicedesc%
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Configurations\DPMDriver_Device.NT
Operation:writeName:Service
Value:
DPMDriver
Executable files
279
Suspicious files
800
Text files
103
Unknown types
23

Dropped files

PID
Process
Filename
Type
6624firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:C09FF302D57C404B61E6A89B0B9F36E7
SHA256:6A5B4F82595799346D0E501FE6CC8629E0FD6ED27B74D0E6CB5073DDB2E3C40B
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.dbbinary
MD5:FF680518BF4ABD23AE2D25C24B050864
SHA256:2A743CABB6714DF481CC77B8B0DDB6B3B87A1D2DD006ACE99410BC256FAC5F50
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:8BD997F90ECBED0083C0F3B144B2F721
SHA256:25EC68792A8D0944AEC3A5C97A589369B3CEF2F6F5F2721E09A1570C270E8255
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
106
DNS requests
123
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6624
firefox.exe
POST
200
2.16.202.121:80
http://r10.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
944
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6624
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6624
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6624
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
whitelisted
5332
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2660
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5488
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2.23.209.173:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6944
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
6624
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6624
firefox.exe
2.19.126.160:443
clientperipherals.dell.com
Akamai International B.V.
DE
whitelisted
6624
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.173
  • 2.23.209.168
  • 2.23.209.177
  • 2.23.209.174
  • 2.23.209.182
  • 2.23.209.175
  • 2.23.209.176
  • 2.23.209.166
  • 2.23.209.179
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.142
  • 2.23.209.137
  • 2.23.209.193
  • 2.23.209.189
  • 2.23.209.192
  • 2.23.209.136
  • 2.23.209.141
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.46
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
clientperipherals.dell.com
  • 2.19.126.160
  • 2.19.126.141
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
a664.dscd.akamai.net
  • 2.19.126.160
  • 2.19.126.141
  • 2a02:26f0:480:33::212:40d9
  • 2a02:26f0:480:33::212:40db
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted

Threats

No threats detected
Process
Message
DPM.exe
C:\Users\Public\Desktop\Adobe Acrobat.lnk
DPM.exe
C:\Users\Public\Desktop\Skype.lnk
DPM.exe
C:\Users\Public\Desktop\Microsoft Edge.lnk
DPM.exe
C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
DPM.exe
C:\Users\Public\Desktop\VLC media player.lnk
DPM.exe
real path
DPM.exe
real path
DPM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
DPM.exe
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
DPM.exe
C:\Users\Public\Desktop\CCleaner.lnk