File name:

_Getintopc.com_Fix(1).zip

Full analysis: https://app.any.run/tasks/8d16e2f4-f338-45fd-a617-927d352f9b64
Verdict: Malicious activity
Analysis date: February 15, 2025, 01:25:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

927ACDDA720F56C8A7D7A82B94788009

SHA1:

16670F9BB2F66A243ED97136DC4562BAAA653EF9

SHA256:

F2532FA4978FF0D007836FA46CC11DA72DEA438DD25AEB9E60581D7EC74EEF3D

SSDEEP:

98304:DL8vDOcXN233M9355g6c4BRXhyI9OI8QmMYH0VoiPsola7URoQirCcgVtyaaMiUy:di6l74p1m++L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • AdskNLM.exe (PID: 6420)
      • WinRAR.exe (PID: 6484)
      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 5916)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 6440)
      • AdskNLM.exe (PID: 6160)
      • AdskNLM.exe (PID: 4388)
      • AdskNLM.exe (PID: 396)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 2624)
      • AdskNLM.exe (PID: 4520)
      • AdskNLM.exe (PID: 6676)
    • Application launched itself

      • AdskNLM.exe (PID: 6420)
      • AdskNLM.exe (PID: 6160)
      • cmd.exe (PID: 3688)
    • Executable content was dropped or overwritten

      • AdskNLM.exe (PID: 6160)
      • xcopy.exe (PID: 2324)
    • Reads the date of Windows installation

      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 6420)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 6676)
      • AdskNLM.exe (PID: 5916)
      • AdskNLM.exe (PID: 6160)
      • AdskNLM.exe (PID: 6440)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 396)
      • AdskNLM.exe (PID: 4388)
      • AdskNLM.exe (PID: 4520)
      • AdskNLM.exe (PID: 2624)
    • Stops a currently running service

      • sc.exe (PID: 2676)
      • sc.exe (PID: 4544)
    • Starts SC.EXE for service management

      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 4388)
    • Uses TASKKILL.EXE to kill process

      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 6676)
      • AdskNLM.exe (PID: 6440)
      • AdskNLM.exe (PID: 5916)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3688)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 2624)
      • AdskNLM.exe (PID: 4520)
      • AdskNLM.exe (PID: 396)
    • Process copies executable file

      • cmd.exe (PID: 3688)
    • Windows service management via SC.EXE

      • sc.exe (PID: 3792)
      • sc.exe (PID: 3692)
    • Uses REG/REGEDIT.EXE to modify registry

      • AdskNLM.exe (PID: 6160)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 5556)
  • INFO

    • Checks supported languages

      • AdskNLM.exe (PID: 6420)
      • AdskNLM.exe (PID: 6160)
      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 5916)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 6676)
      • AdskNLM.exe (PID: 6440)
      • AdskNLM.exe (PID: 4388)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 396)
      • AdskNLM.exe (PID: 4520)
      • msiexec.exe (PID: 6808)
      • AdskNLM.exe (PID: 2624)
    • Reads the computer name

      • AdskNLM.exe (PID: 6420)
      • AdskNLM.exe (PID: 6160)
      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 6676)
      • AdskNLM.exe (PID: 5916)
      • AdskNLM.exe (PID: 4388)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 396)
      • AdskNLM.exe (PID: 4520)
      • msiexec.exe (PID: 6808)
      • AdskNLM.exe (PID: 2624)
      • AdskNLM.exe (PID: 6440)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6484)
    • Process checks computer location settings

      • AdskNLM.exe (PID: 6420)
      • AdskNLM.exe (PID: 5448)
      • AdskNLM.exe (PID: 4052)
      • AdskNLM.exe (PID: 3620)
      • AdskNLM.exe (PID: 3820)
      • AdskNLM.exe (PID: 6868)
      • AdskNLM.exe (PID: 6948)
      • AdskNLM.exe (PID: 6208)
      • AdskNLM.exe (PID: 1356)
      • AdskNLM.exe (PID: 5392)
      • AdskNLM.exe (PID: 1296)
      • AdskNLM.exe (PID: 6900)
      • AdskNLM.exe (PID: 5592)
      • AdskNLM.exe (PID: 5788)
      • AdskNLM.exe (PID: 4076)
      • AdskNLM.exe (PID: 3608)
      • AdskNLM.exe (PID: 2072)
      • AdskNLM.exe (PID: 6692)
      • AdskNLM.exe (PID: 5916)
      • AdskNLM.exe (PID: 6676)
      • AdskNLM.exe (PID: 6440)
      • AdskNLM.exe (PID: 6160)
      • AdskNLM.exe (PID: 4388)
      • AdskNLM.exe (PID: 3540)
      • AdskNLM.exe (PID: 396)
      • AdskNLM.exe (PID: 4520)
      • AdskNLM.exe (PID: 2624)
    • The sample compiled with english language support

      • AdskNLM.exe (PID: 6160)
    • Create files in a temporary directory

      • AdskNLM.exe (PID: 6160)
    • Creates files in the program directory

      • xcopy.exe (PID: 2324)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 3608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:11:04 14:38:24
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Fix/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
208
Monitored processes
84
Malicious processes
3
Suspicious processes
6

Behavior graph

Click at the process to see the details
start winrar.exe adsknlm.exe no specs adsknlm.exe adsknlm.exe no specs sc.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs xcopy.exe adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs sc.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs adsknlm.exe no specs taskkill.exe no specs conhost.exe no specs reg.exe no specs adsknlm.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs adsknlm.exe no specs sc.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs adsknlm.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396"C:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exe" -sfxwaitall:0 "cmd" /c "C:\Program Files\Autodesk\AdskIdentityManager\uninstall.exe" --mode unattendedC:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exeAdskNLM.exe
User:
admin
Company:
MAGNiTUDE & m0nkrus
Integrity Level:
HIGH
Description:
Autodesk 2020-2024 Cracked NLM Installer
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6484.6215\fix\autodesk autocad 2025 x64 new crack\adsknlm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
444\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
624"C:\Windows\System32\taskkill.exe" /im AdskLicensingAgent.exe /fC:\Windows\System32\taskkill.exeAdskNLM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
628"C:\Windows\System32\taskkill.exe" /f /im AdAppMgrSvc.exeC:\Windows\System32\taskkill.exeAdskNLM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
772\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
904\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1296"C:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exe" -sfxwaitall:0 "cmd" /c if exist "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\12.0.0.6529\AdskLicensingAgent\AdskLicensingAgent.exe" ( echo F | xcopy /hkry "C:\Users\admin\AppData\Local\Temp\Adsk-NLM\version_old.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\12.0.0.6529\AdskLicensingAgent\version.dll" )C:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exeAdskNLM.exe
User:
admin
Company:
MAGNiTUDE & m0nkrus
Integrity Level:
HIGH
Description:
Autodesk 2020-2024 Cracked NLM Installer
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6484.6215\fix\autodesk autocad 2025 x64 new crack\adsknlm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1356"C:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exe" -sfxwaitall:0 "cmd" /c if exist "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\11.1.0.5629\AdskLicensingAgent\AdskLicensingAgent.exe" ( echo F | xcopy /hkry "C:\Users\admin\AppData\Local\Temp\Adsk-NLM\version_old.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\11.1.0.5629\AdskLicensingAgent\version.dll" )C:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exeAdskNLM.exe
User:
admin
Company:
MAGNiTUDE & m0nkrus
Integrity Level:
HIGH
Description:
Autodesk 2020-2024 Cracked NLM Installer
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6484.6215\fix\autodesk autocad 2025 x64 new crack\adsknlm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1400\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
17 525
Read events
17 515
Write events
9
Delete events
1

Modification events

(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_Getintopc.com_Fix(1).zip
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3632) reg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Autodesk Access
Value:
Executable files
6
Suspicious files
2
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\nlm11-19-4-1-ipv4-ipv6-win64.msi
MD5:
SHA256:
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\delnowmic.ps1text
MD5:67924FF023F149E8B467A8905FF1B4FC
SHA256:4B5EF379990A4663A3341913B0BD4FEDF906B9F6AF8D8FA0CB8BEE4A09FF92F9
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\licenses.lictext
MD5:CB60AEE5E7AD52188A791FB885AFCA68
SHA256:A86DFB9F3B3A6D0EDECC504FA9FBD5D9246765386C5F6621CA32750CD82C4D27
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\version.dllexecutable
MD5:44774FAFD716FA45C7A0CCB3B14D59A6
SHA256:4739ABFF4DA13A27F2421452007C9D2340BF4F9E9A601EF0EC9F1B9D64D1D365
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\adskflex.exeexecutable
MD5:E974687B0135A662623056078A8E58E1
SHA256:82BE4EC8BA546EBF1E3448976D06E163E9C4E258301CFCEB9CE8A2D76ECBD6AE
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\nlm.mstbinary
MD5:29810BAB1EF69A3D26872093EF09372B
SHA256:90E413CD675EE085C441DF6327F6661A3459F4E109E0684B1A361C050D672BDB
2324xcopy.exeC:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingAgent\version.dllexecutable
MD5:44774FAFD716FA45C7A0CCB3B14D59A6
SHA256:4739ABFF4DA13A27F2421452007C9D2340BF4F9E9A601EF0EC9F1B9D64D1D365
6484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\Readme.txttext
MD5:B23A762137352DE899637C59C80107D1
SHA256:55CE1D1CEDDD18791AA65D397537E14A75D3856E61C325E0B0EF2702529374CC
6484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6484.6215\Fix\Autodesk AutoCAD 2025 x64 new Crack\AdskNLM.exeexecutable
MD5:7C43835AAC7F366CE2075A0D8DB8C334
SHA256:982EC5CDEA22801121C7FA31D23FB69CCA07167928DB33540594F6ACBCD79883
6160AdskNLM.exeC:\Users\admin\AppData\Local\Temp\Adsk-NLM\UnNamed.jsonbinary
MD5:BA3088F87EDFCCEB1E084C971DB40601
SHA256:E0371582686D18B48EDB9E956057B52AA97DE8C034EE79AAB10FFB5331711651
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1296
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6684
WmiPrvSE.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6684
WmiPrvSE.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
6756
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1296
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
104.126.37.178:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5064
SearchApp.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1076
svchost.exe
184.30.18.9:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 104.126.37.178
  • 104.126.37.136
  • 104.126.37.129
  • 104.126.37.131
  • 104.126.37.163
  • 104.126.37.130
  • 104.126.37.123
  • 104.126.37.145
  • 104.126.37.139
whitelisted
login.live.com
  • 20.190.160.20
  • 20.190.160.132
  • 20.190.160.3
  • 40.126.32.138
  • 40.126.32.68
  • 20.190.160.17
  • 20.190.160.14
  • 20.190.160.131
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info