File name:

Pcmflash.exe

Full analysis: https://app.any.run/tasks/9656cbc5-01af-44b0-949e-5946a2c74b43
Verdict: Malicious activity
Analysis date: March 05, 2024, 16:18:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4E3BDB56E5591B122ADFA1754C19DE70

SHA1:

1A7D553F637A1B758FC524CCE4B1E4AC11C7FE40

SHA256:

FCD910520385EC34D09E18DE246B18623A918672BF4FAC7A5EBD2CEF024092E7

SSDEEP:

98304:7r7ayGJ6kHOSN1SCS9dEETwh1pml953kg5vbLJFSjgbQtdV85hFi1RW8VZWr9R1G:PDm3kuORJEFfPgEsRZoqWbT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Pcmflash.exe (PID: 3700)
      • ._cache_Pcmflash.exe (PID: 3536)
      • ._cache_Pcmflash.exe (PID: 4008)
      • ._cache_Pcmflash.tmp (PID: 3956)
      • pcmflash.exe (PID: 696)
    • Connects to the CnC server

      • Synaptics.exe (PID: 2624)
    • Changes the autorun value in the registry

      • Pcmflash.exe (PID: 3700)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Pcmflash.exe (PID: 3700)
      • Synaptics.exe (PID: 2624)
    • Reads security settings of Internet Explorer

      • Pcmflash.exe (PID: 3700)
      • Synaptics.exe (PID: 2624)
    • Executable content was dropped or overwritten

      • ._cache_Pcmflash.exe (PID: 3536)
      • Pcmflash.exe (PID: 3700)
      • ._cache_Pcmflash.exe (PID: 4008)
      • ._cache_Pcmflash.tmp (PID: 3956)
      • pcmflash.exe (PID: 696)
    • Reads the date of Windows installation

      • Pcmflash.exe (PID: 3700)
      • ._cache_Pcmflash.tmp (PID: 3348)
    • Reads the Windows owner or organization settings

      • ._cache_Pcmflash.tmp (PID: 3956)
    • Connects to unusual port

      • Synaptics.exe (PID: 2624)
    • Reads settings of System Certificates

      • Synaptics.exe (PID: 2624)
    • Checks Windows Trust Settings

      • Synaptics.exe (PID: 2624)
  • INFO

    • Checks supported languages

      • Pcmflash.exe (PID: 3700)
      • ._cache_Pcmflash.exe (PID: 3536)
      • Synaptics.exe (PID: 2624)
      • ._cache_Pcmflash.exe (PID: 4008)
      • ._cache_Pcmflash.tmp (PID: 3956)
      • pcmflash.exe (PID: 696)
      • pcmflash.exe (PID: 2072)
      • grddialog-x86.7.0.1.0.exe (PID: 3776)
      • grddialog-x86.7.0.1.0.exe (PID: 1888)
      • ._cache_Pcmflash.tmp (PID: 3348)
    • Reads the computer name

      • Pcmflash.exe (PID: 3700)
      • Synaptics.exe (PID: 2624)
      • ._cache_Pcmflash.tmp (PID: 3956)
      • pcmflash.exe (PID: 2072)
      • pcmflash.exe (PID: 696)
      • ._cache_Pcmflash.tmp (PID: 3348)
    • Create files in a temporary directory

      • ._cache_Pcmflash.exe (PID: 3536)
      • Pcmflash.exe (PID: 3700)
      • ._cache_Pcmflash.exe (PID: 4008)
      • Synaptics.exe (PID: 2624)
      • pcmflash.exe (PID: 696)
    • Creates files in the program directory

      • Pcmflash.exe (PID: 3700)
      • Synaptics.exe (PID: 2624)
      • ._cache_Pcmflash.tmp (PID: 3956)
    • Reads the machine GUID from the registry

      • Synaptics.exe (PID: 2624)
      • ._cache_Pcmflash.tmp (PID: 3348)
      • Pcmflash.exe (PID: 3700)
    • Creates a software uninstall entry

      • ._cache_Pcmflash.tmp (PID: 3956)
    • Checks proxy server information

      • Synaptics.exe (PID: 2624)
    • Reads the software policy settings

      • Synaptics.exe (PID: 2624)
    • Manual execution by a user

      • pcmflash.exe (PID: 2072)
      • taskmgr.exe (PID: 3544)
    • Creates files or folders in the user directory

      • Synaptics.exe (PID: 2624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Borland Delphi 7 (83.1)
.exe | Inno Setup installer (13.7)
.exe | Win32 Executable Delphi generic (1.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Win16/32 Executable Delphi generic (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 629760
InitializedDataSize: 12195840
UninitializedDataSize: -
EntryPoint: 0x9ab80
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.4
ProductVersionNumber: 1.0.0.4
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Turkish
CharacterSet: Windows, Turkish
CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName: -
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: -
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pcmflash.exe ._cache_pcmflash.exe ._cache_pcmflash.tmp no specs synaptics.exe ._cache_pcmflash.exe ._cache_pcmflash.tmp pcmflash.exe pcmflash.exe no specs grddialog-x86.7.0.1.0.exe no specs grddialog-x86.7.0.1.0.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Program Files\PCMflash\pcmflash.exe"C:\Program Files\PCMflash\pcmflash.exe
._cache_Pcmflash.tmp
User:
admin
Company:
quickie@yandex.ru
Integrity Level:
MEDIUM
Description:
PCMflash
Exit code:
2000
Version:
1.2.0.0
Modules
Images
c:\program files\pcmflash\pcmflash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1888C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)"C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)" MB_RETRYCANCELC:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exepcmflash.exe
User:
admin
Company:
Activ Co.
Integrity Level:
MEDIUM
Description:
Command-line utility protection
Exit code:
2
Version:
7, 0, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\grddialog-x86.7.0.1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2072"C:\Program Files\PCMflash\pcmflash.exe" C:\Program Files\PCMflash\pcmflash.exeexplorer.exe
User:
admin
Company:
quickie@yandex.ru
Integrity Level:
MEDIUM
Description:
PCMflash
Exit code:
2000
Version:
1.2.0.0
Modules
Images
c:\program files\pcmflash\pcmflash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2624"C:\ProgramData\Synaptics\Synaptics.exe" InjUpdateC:\ProgramData\Synaptics\Synaptics.exe
Pcmflash.exe
User:
admin
Company:
Synaptics
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3348"C:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmp" /SL5="$16013E,11790810,54272,C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" C:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmp._cache_Pcmflash.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9fdvt.tmp\._cache_pcmflash.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3536"C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe
Pcmflash.exe
User:
admin
Company:
PCMflash
Integrity Level:
MEDIUM
Description:
PCMflash Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\._cache_pcmflash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3544"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3700"C:\Users\admin\AppData\Local\Temp\Pcmflash.exe" C:\Users\admin\AppData\Local\Temp\Pcmflash.exe
explorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
MEDIUM
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\users\admin\appdata\local\temp\pcmflash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3776C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)"C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)" MB_RETRYCANCELC:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exepcmflash.exe
User:
admin
Company:
Activ Co.
Integrity Level:
MEDIUM
Description:
Command-line utility protection
Exit code:
2
Version:
7, 0, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\grddialog-x86.7.0.1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3956"C:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmp" /SL5="$8020A,11790810,54272,C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" /SPAWNWND=$120176 /NOTIFYWND=$16013E C:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmp
._cache_Pcmflash.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ah38a.tmp\._cache_pcmflash.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
18 257
Read events
18 041
Write events
200
Delete events
16

Modification events

(PID) Process:(3700) Pcmflash.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3700) Pcmflash.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3700) Pcmflash.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3700) Pcmflash.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3700) Pcmflash.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Synaptics Pointing Device Driver
Value:
C:\ProgramData\Synaptics\Synaptics.exe
(PID) Process:(3700) Pcmflash.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3348) ._cache_Pcmflash.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3956) ._cache_Pcmflash.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
740F000036AC68DD186FDA01
(PID) Process:(3956) ._cache_Pcmflash.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9A3EBB85D6923CF9599F74CF0A4E120709D2493F15A4FB05C32AE566B18C2978
(PID) Process:(3956) ._cache_Pcmflash.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
Executable files
13
Suspicious files
8
Text files
2
Unknown types
6

Dropped files

PID
Process
Filename
Type
3536._cache_Pcmflash.exeC:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmpexecutable
MD5:6B99893EE22CD8775D55979D3F537030
SHA256:9E8C3247701E0E7DAC13B473B3A187B365C966085F891FD744A941DA4A08C5F2
3956._cache_Pcmflash.tmpC:\Program Files\PCMflash\is-7EM7T.tmpexecutable
MD5:56A41D58C5495981B2FB5D885504D8B1
SHA256:768C4830501CDC77F19FAF6BEBF4B1DBB2AC04C13B7635C434E937C9881D55CA
3700Pcmflash.exeC:\ProgramData\Synaptics\RCX4ED.tmpexecutable
MD5:C725925C04C052EAAAAAE21B1040BC80
SHA256:65C5B363B3FEC9A7E2FBFC10D4D0E4949A21B6673FD5D950C9D9566C755ADA10
3700Pcmflash.exeC:\ProgramData\Synaptics\Synaptics.exeexecutable
MD5:4E3BDB56E5591B122ADFA1754C19DE70
SHA256:FCD910520385EC34D09E18DE246B18623A918672BF4FAC7A5EBD2CEF024092E7
3956._cache_Pcmflash.tmpC:\Program Files\PCMflash\unins000.exeexecutable
MD5:F17DFB89F41AE7C3155D5871C0B13A3D
SHA256:2A9BB84BF61D74116EEA76B02D6D5ED26DD750FEB64DF9E01C33D659FB24FC56
3700Pcmflash.exeC:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exeexecutable
MD5:12324387789529A933FF92CEEFF2E66F
SHA256:2A598B4B2BE13129CB8B3642838E4D7623DA2D38FD6C93BDC0CB238835375795
4008._cache_Pcmflash.exeC:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmpexecutable
MD5:6B99893EE22CD8775D55979D3F537030
SHA256:9E8C3247701E0E7DAC13B473B3A187B365C966085F891FD744A941DA4A08C5F2
3956._cache_Pcmflash.tmpC:\Users\Public\Desktop\PCMflash.lnklnk
MD5:2BA3B07618F68C8164B02233EA218B96
SHA256:F92756D08D817FE8608AB112F825631D383AF6C6E1B68386DCD5A832D4D658D4
3956._cache_Pcmflash.tmpC:\Program Files\PCMflash\is-UMNDM.tmpexecutable
MD5:F17DFB89F41AE7C3155D5871C0B13A3D
SHA256:2A9BB84BF61D74116EEA76B02D6D5ED26DD750FEB64DF9E01C33D659FB24FC56
696pcmflash.exeC:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exeexecutable
MD5:3A00867414E479B7FEC10B6D23230EB0
SHA256:4A8A557CA6D5667B64017F5B7B8BD51556F321CE88F780DFC0A74CF372743449
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
14
DNS requests
9
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2624
Synaptics.exe
GET
304
2.16.100.179:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c1adc6ce095ff73c
DE
unknown
2624
Synaptics.exe
GET
200
69.42.215.252:80
http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
US
text
31 b
unknown
2624
Synaptics.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
unknown
2624
Synaptics.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCECzpBwEAqmZNCdn%2B9lFcFjc%3D
US
binary
471 b
unknown
2624
Synaptics.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCRd4hKrA6aBAnnS3UYBsso
US
binary
472 b
unknown
2624
Synaptics.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
binary
724 b
unknown
1080
svchost.exe
GET
200
88.221.110.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e
DE
compressed
67.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2624
Synaptics.exe
49.13.77.253:1199
xred.mooo.com
Hetzner Online GmbH
DE
unknown
2624
Synaptics.exe
69.42.215.252:80
freedns.afraid.org
AWKNET
US
unknown
2624
Synaptics.exe
142.250.186.174:443
docs.google.com
GOOGLE
US
whitelisted
2624
Synaptics.exe
2.16.100.179:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
2624
Synaptics.exe
142.250.184.227:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2624
Synaptics.exe
142.250.184.193:443
drive.usercontent.google.com
GOOGLE
US
whitelisted
1080
svchost.exe
88.221.110.120:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
xred.mooo.com
  • 49.13.77.253
unknown
freedns.afraid.org
  • 69.42.215.252
whitelisted
docs.google.com
  • 142.250.186.174
shared
ctldl.windowsupdate.com
  • 2.16.100.179
  • 88.221.110.121
  • 2.16.100.161
  • 2.16.100.138
  • 2.16.100.171
  • 2.16.100.152
  • 2.16.100.155
  • 2.16.100.163
  • 88.221.110.120
  • 88.221.110.122
  • 88.221.110.75
  • 88.221.110.65
  • 88.221.110.66
  • 88.221.110.96
  • 88.221.110.112
  • 88.221.110.104
whitelisted
ocsp.pki.goog
  • 142.250.184.227
whitelisted
drive.usercontent.google.com
  • 142.250.184.193
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
3 ETPRO signatures available at the full report
No debug info