File name:

iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe

Full analysis: https://app.any.run/tasks/ec60d38c-e525-45e1-94a6-682b3e8c85f7
Verdict: Malicious activity
Analysis date: December 09, 2023, 02:05:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
covid19
shareaza
ishareaza
gnutella
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D10D03828537829CAE7C312054346648

SHA1:

54DD4A475FC96C75A7D46F1D307B6F5B090A5A66

SHA256:

F06AB830ABB2F0AE9BCC705593D11D6EDB4E5708F13820AD7620E187DC3ADCB6

SSDEEP:

98304:d+cD4dno/J6YqhY1GAVeHpjDJr8KK3cREeMNSN3ztshLXxV2FMEqEiU+5w/Jess6:f/LYy5D4CkAB73wVD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1864)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1328)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • The DLL Hijacking

      • regsvr32.exe (PID: 240)
    • Registers / Runs the DLL via REGSVR32.EXE

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Drops 7-zip archiver for unpacking

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Reads the Windows owner or organization settings

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Write to the desktop.ini file (may be used to cloak folders)

      • Shareaza.exe (PID: 2728)
      • Shareaza.exe (PID: 1004)
    • Reads the Internet Settings

      • Shareaza.exe (PID: 1004)
    • Detected use of alternative data streams (AltDS)

      • Shareaza.exe (PID: 1004)
    • Connects to unusual port

      • Shareaza.exe (PID: 1004)
  • INFO

    • Create files in a temporary directory

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1328)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1864)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Checks supported languages

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1864)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe (PID: 1328)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2920)
      • wmpnscfg.exe (PID: 1360)
      • MediaPlayer.exe (PID: 3092)
      • MediaImageServices.exe (PID: 3528)
      • MediaLibraryBuilder.exe (PID: 2696)
      • Shareaza.exe (PID: 2728)
      • WindowsThumbnail.exe (PID: 4012)
      • WindowsThumbnail.exe (PID: 3632)
      • Skin.exe (PID: 3916)
      • Shareaza.exe (PID: 1004)
      • MediaImageServices.exe (PID: 3644)
      • MediaLibraryBuilder.exe (PID: 1868)
      • MediaPlayer.exe (PID: 4000)
      • WindowsThumbnail.exe (PID: 3944)
    • Reads the computer name

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2920)
      • wmpnscfg.exe (PID: 1360)
      • Shareaza.exe (PID: 2728)
      • WindowsThumbnail.exe (PID: 4012)
      • Shareaza.exe (PID: 1004)
    • Drops a (possible) Coronavirus decoy

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Creates files in the program directory

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1360)
    • Creates files or folders in the user directory

      • iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp (PID: 2544)
      • Shareaza.exe (PID: 1004)
    • Reads the machine GUID from the registry

      • Shareaza.exe (PID: 2728)
      • WindowsThumbnail.exe (PID: 4012)
      • Shareaza.exe (PID: 1004)
    • Checks proxy server information

      • Shareaza.exe (PID: 1004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 56320
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.7.10.5
ProductVersionNumber: 2.7.10.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shareaza Development Team
FileDescription: Shareaza Ultimate File Sharing
FileVersion: 2.7.10.5
LegalCopyright: Copyright � Shareaza Development Team. All rights reserved.
OriginalFileName:
ProductName: Shareaza
ProductVersion: 2.7.10.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
77
Monitored processes
34
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ishareaza_2.7.10.5_win32_release_2023-09-23.exe no specs ishareaza_2.7.10.5_win32_release_2023-09-23.tmp no specs ishareaza_2.7.10.5_win32_release_2023-09-23.exe ishareaza_2.7.10.5_win32_release_2023-09-23.tmp no specs wmpnscfg.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs shareaza.exe no specs mediaimageservices.exe no specs medialibrarybuilder.exe no specs mediaplayer.exe no specs windowsthumbnail.exe no specs skin.exe no specs shareaza.exe GFL Image Services no specs mediaimageservices.exe no specs medialibrarybuilder.exe no specs mediaplayer.exe no specs windowsthumbnail.exe no specs GFL Library Builder no specs windowsthumbnail.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\ImageViewer.dll"C:\Windows\System32\regsvr32.exeiShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
644"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RazaWebHook64.dll"C:\Windows\System32\regsvr32.exeiShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1004"C:\Program Files\Shareaza\Shareaza.exe"C:\Program Files\Shareaza\Shareaza.exe
iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Shareaza Development Team
Integrity Level:
MEDIUM
Description:
Shareaza Ultimate File Sharing
Exit code:
0
Version:
2.7.10.5
Modules
Images
c:\program files\shareaza\shareaza.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1276"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RARBuilder.dll"C:\Windows\System32\regsvr32.exeiShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1328"C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe" /SPAWNWND=$1B0142 /NOTIFYWND=$1301B8 C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe
iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Shareaza Development Team
Integrity Level:
HIGH
Description:
Shareaza Ultimate File Sharing
Exit code:
0
Version:
2.7.10.5
Modules
Images
c:\users\admin\downloads\ishareaza_2.7.10.5_win32_release_2023-09-23.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1360"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1696"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RatDVDReader.dll"C:\Windows\System32\regsvr32.exeiShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1844"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\GFLImageServices.dll"C:\Windows\System32\regsvr32.exeiShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1864"C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe" C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exeexplorer.exe
User:
admin
Company:
Shareaza Development Team
Integrity Level:
MEDIUM
Description:
Shareaza Ultimate File Sharing
Exit code:
0
Version:
2.7.10.5
Modules
Images
c:\users\admin\downloads\ishareaza_2.7.10.5_win32_release_2023-09-23.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1868"C:\Program Files\Shareaza\MediaLibraryBuilder.exe" /RegServerPerUserC:\Program Files\Shareaza\MediaLibraryBuilder.exeShareaza.exe
User:
admin
Company:
Shareaza Development Team
Integrity Level:
MEDIUM
Description:
Media Library Builder Plugin
Exit code:
0
Version:
1.1.0.1
Modules
Images
c:\program files\shareaza\medialibrarybuilder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
5 672
Read events
3 959
Write events
1 685
Delete events
28

Modification events

(PID) Process:(1844) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\ImageService
Operation:writeName:.sti
Value:
{E9F51B1E-DB0F-4EEE-9B36-46151994C715}
(PID) Process:(2996) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder
Operation:writeName:.sti
Value:
{E9F51B1E-DB0F-4EEE-9B36-46151994C715}
(PID) Process:(2728) Shareaza.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Shareaza.exe
Operation:writeName:FriendlyAppName
Value:
Shareaza
(PID) Process:(2728) Shareaza.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Shareaza.exe\shell\open\ddeexec
Operation:writeName:WindowClassName
Value:
ShareazaMainWnd
(PID) Process:(2728) Shareaza.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection\shell\open\ddeexec
Operation:writeName:WindowClassName
Value:
ShareazaMainWnd
(PID) Process:(2728) Shareaza.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection
Operation:writeName:EditFlags
Value:
65536
(PID) Process:(2728) Shareaza.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection
Operation:writeName:AppUserModelID
Value:
Shareaza
(PID) Process:(2544) iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(1004) Shareaza.exeKey:HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder
Operation:writeName:.7z
Value:
{B69F80CD-FB15-45E8-B359-92A41CC571A7}
(PID) Process:(1004) Shareaza.exeKey:HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder
Operation:writeName:.cb7
Value:
{B69F80CD-FB15-45E8-B359-92A41CC571A7}
Executable files
77
Suspicious files
42
Text files
698
Unknown types
0

Dropped files

PID
Process
Filename
Type
1864iShareaza_2.7.10.5_Win32_Release_2023-09-23.exeC:\Users\admin\AppData\Local\Temp\is-UQENE.tmp\iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpexecutable
MD5:36D3386F631A5A36CC2563E2C6A6F817
SHA256:B9EA74EC1862F532A3C8231895D85549A1FD94FB1DB55E85519A96446B9E57F6
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\is-OEHBE.tmpexecutable
MD5:AEE75271856C9C42F75D950FD8455C33
SHA256:A66DAB2D51C4952024B7C2974ACBF3367D3BCEA0489EB1AE8EB41923157AFD5A
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\Uninstall\is-QA39D.tmpexecutable
MD5:584D9F48138F97A44495AC31B46F92DA
SHA256:A3F66D8F9C2AFD5233E376C20DF0C809FDD469078125525E5E775F82004D52B9
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Users\admin\AppData\Local\Temp\is-P9QMR.tmp\idp.dllexecutable
MD5:55C310C0319260D798757557AB3BF636
SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\Skin.exeexecutable
MD5:2331633B8BB4196B7C8054E6E27C47C6
SHA256:21D16A63A59B20B679673FB14A500D9961217A051174F2637F085D0E2E07498F
1328iShareaza_2.7.10.5_Win32_Release_2023-09-23.exeC:\Users\admin\AppData\Local\Temp\is-V49QD.tmp\iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpexecutable
MD5:36D3386F631A5A36CC2563E2C6A6F817
SHA256:B9EA74EC1862F532A3C8231895D85549A1FD94FB1DB55E85519A96446B9E57F6
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\is-C76IR.tmpexecutable
MD5:DBA1404EC119616A4995C197C1244C3F
SHA256:6D43B3CF0AFE3A9D98FFFE05B71F5971B762896D797C59196A7E4D25C744C478
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\Uninstall\unins000.exeexecutable
MD5:584D9F48138F97A44495AC31B46F92DA
SHA256:A3F66D8F9C2AFD5233E376C20DF0C809FDD469078125525E5E775F82004D52B9
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\TorrentWizard.exeexecutable
MD5:7B2E65D91AA5E9B5855C3C2C3284B093
SHA256:0DC3640D0F29507A512F21579267E08CB2B795CB712DD2B29D0DCF8A406CF3E8
2544iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmpC:\Program Files\Shareaza\Shareaza.exeexecutable
MD5:AEE75271856C9C42F75D950FD8455C33
SHA256:A66DAB2D51C4952024B7C2974ACBF3367D3BCEA0489EB1AE8EB41923157AFD5A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
80
DNS requests
17
Threats
75

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1004
Shareaza.exe
GET
200
172.67.130.169:80
http://upd.emule-security.org/server.met
unknown
binary
2.19 Kb
unknown
1004
Shareaza.exe
GET
410
3.64.163.50:80
http://gwc.centrump2p.com/skulls.php?get=1&hostfile=1&net=gnutella&client=RAZI&version=2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1
unknown
html
140 b
unknown
1004
Shareaza.exe
GET
200
149.28.163.175:3558
http://au.gnutella.dyslexicfish.net:3558/?get=1&hostfile=1&net=gnutella&client=RAZI&version=2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1
unknown
text
433 b
unknown
1004
Shareaza.exe
GET
200
69.163.178.11:80
http://dkac.trillinux.org/dkac/dkac.php?get=1&hostfile=1&net=gnutella2&ping=1&pv=4&client=RAZI2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1
unknown
text
1.35 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1004
Shareaza.exe
239.255.255.250:1900
whitelisted
1004
Shareaza.exe
172.67.130.169:80
upd.emule-security.org
CLOUDFLARENET
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
1004
Shareaza.exe
67.215.246.10:6881
router.bittorrent.com
unknown
1004
Shareaza.exe
116.14.134.29:8691
unknown
1004
Shareaza.exe
34.229.89.117:6881
dht.aelitis.com
unknown
1004
Shareaza.exe
154.199.0.61:6881
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.35.228.137
whitelisted
uk.gnutella.dyslexicfish.net
unknown
upd.emule-security.org
  • 172.67.130.169
  • 104.21.3.116
unknown
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
dht.transmissionbt.com
  • 87.98.162.88
  • 212.129.33.59
unknown
dht.aelitis.com
  • 34.229.89.117
malicious
ping.pongwar.com
unknown
cache.ce3c.be
unknown
dkac.trillinux.org
  • 69.163.178.11
unknown

Threats

PID
Process
Class
Message
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P eDonkey Server Status Request
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P eDonkey Server Status Request
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P Gnutella Connect
1004
Shareaza.exe
Potential Corporate Privacy Violation
GPL P2P GNUTella client request
1004
Shareaza.exe
Potential Corporate Privacy Violation
GPL P2P GNUTella client request
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P Gnutella Connect
1004
Shareaza.exe
Potential Corporate Privacy Violation
GPL P2P GNUTella client request
1004
Shareaza.exe
Potential Corporate Privacy Violation
ET P2P Gnutella Connect
1004
Shareaza.exe
Potential Corporate Privacy Violation
GPL P2P GNUTella client request
No debug info