File name:

AceSetup.exe

Full analysis: https://app.any.run/tasks/fec88614-5160-4605-84c9-af44512b9e3b
Verdict: Malicious activity
Analysis date: April 04, 2026, 21:49:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 11 sections
MD5:

B219A75B950338E67E9248FD5AB69619

SHA1:

93922CFB4C222E5C8E596B5130E2A47794C81044

SHA256:

005930DAFC3191268EAAC65DB75B81DD44671FADD1AA9E12CAF44A6EAF8C2E0D

SSDEEP:

98304:J16zOwJ2TtI/0ymWxU+lvtn2cRfOBYFgByUrSA4ouht+I1bPESAmep3XAhIeX178:Rp3X6YZVcE8mBzogP9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • AceSetup.exe (PID: 2432)
      • AceSetup.exe (PID: 4308)
      • updater.exe (PID: 5224)
      • updater.exe (PID: 1180)
      • updater.exe (PID: 5548)
      • updater.exe (PID: 5008)
      • updater.exe (PID: 3156)
      • updater.exe (PID: 2792)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • AceSetup.exe (PID: 2432)
    • Application launched itself

      • AceSetup.exe (PID: 2432)
      • updater.exe (PID: 1180)
      • updater.exe (PID: 5548)
      • updater.exe (PID: 3156)
    • Executes as Windows Service

      • updater.exe (PID: 3156)
      • updater.exe (PID: 5548)
  • INFO

    • Reads security settings of Internet Explorer

      • AceSetup.exe (PID: 2432)
      • updater.exe (PID: 1180)
    • Reads the computer name

      • AceSetup.exe (PID: 2432)
      • AceSetup.exe (PID: 4308)
      • updater.exe (PID: 1180)
      • updater.exe (PID: 5548)
      • updater.exe (PID: 3156)
    • Checks supported languages

      • AceSetup.exe (PID: 4308)
      • AceSetup.exe (PID: 2432)
      • updater.exe (PID: 1180)
      • updater.exe (PID: 5224)
      • updater.exe (PID: 5008)
      • updater.exe (PID: 3156)
      • updater.exe (PID: 5548)
      • updater.exe (PID: 2792)
    • The sample compiled with english language support

      • AceSetup.exe (PID: 2432)
    • Reads the machine GUID from the registry

      • AceSetup.exe (PID: 4308)
      • updater.exe (PID: 3156)
      • updater.exe (PID: 1180)
    • Create files in a temporary directory

      • AceSetup.exe (PID: 4308)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 1180)
      • updater.exe (PID: 3156)
      • updater.exe (PID: 5548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 3869696
InitializedDataSize: 8240128
UninitializedDataSize: -
EntryPoint: 0x371d50
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 143.0.7514.0
ProductVersionNumber: 143.0.7514.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BrowseAI LLC
FileDescription: Ace Installer (x64)
FileVersion: 143.0.7514.0
InternalName: Ace Installer (x64)
LegalCopyright: Copyright 1970 The BrowseAI LLC Authors. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Ace Installer (x64)
ProductVersion: 143.0.7514.0
CompanyShortName: BrowseAI LLC
ProductShortName: AceUpdater
LastChange: 0000000000000000000000000000000000000000
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
9
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
start acesetup.exe no specs slui.exe acesetup.exe updater.exe updater.exe no specs updater.exe no specs updater.exe no specs updater.exe updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1180"C:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\updater.exe" --install=appguid={908AAF3D-6DAA-4F36-A9B0-538D90BEC8C1}&appname=Chromium&needsadmin=prefers&iid=fb5bf2ba-306e-11f1-a669-5659c2b1882a@fb5be9fa-306e-11f1-a669-5659c2b1882a@gs_23566648955_196381223707_802980954933@image --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\updater.exe
AceSetup.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
HIGH
Description:
Ace Updater (x64)
Version:
143.0.7514.0
Modules
Images
c:\users\admin\appdata\local\temp\ace4308_1969508865\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2432"C:\Users\admin\Desktop\AceSetup.exe" C:\Users\admin\Desktop\AceSetup.exeexplorer.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
MEDIUM
Description:
Ace Installer (x64)
Version:
143.0.7514.0
Modules
Images
c:\users\admin\desktop\acesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2524C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2792"C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\Crashpad" --url=https://clients2.google.com/cr/staging_report --annotation=prod=AceUpdater --annotation=ver=143.0.7514.0 "--attachment=C:\Program Files (x86)\Ace\AceUpdater\updater.log" --initial-client-data=0x260,0x264,0x268,0x23c,0x26c,0x7ff6c3e282ac,0x7ff6c3e282b8,0x7ff6c3e282c8C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exeupdater.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Updater (x64)
Version:
143.0.7514.0
Modules
Images
c:\program files (x86)\ace\aceupdater\143.0.7514.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
3156"C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exe" --system --windows-service --service=updateC:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exe
services.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Updater (x64)
Version:
143.0.7514.0
Modules
Images
c:\program files (x86)\ace\aceupdater\143.0.7514.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
4308"C:\Users\admin\Desktop\AceSetup.exe" --install=appguid={908AAF3D-6DAA-4F36-A9B0-538D90BEC8C1}&appname=Chromium&needsadmin=prefers&iid=fb5bf2ba-306e-11f1-a669-5659c2b1882a@fb5be9fa-306e-11f1-a669-5659c2b1882a@gs_23566648955_196381223707_802980954933@image --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\Desktop\AceSetup.exe
AceSetup.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
HIGH
Description:
Ace Installer (x64)
Version:
143.0.7514.0
Modules
Images
c:\users\admin\desktop\acesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5008"C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\Crashpad" --url=https://clients2.google.com/cr/staging_report --annotation=prod=AceUpdater --annotation=ver=143.0.7514.0 "--attachment=C:\Program Files (x86)\Ace\AceUpdater\updater.log" --initial-client-data=0x258,0x25c,0x260,0x234,0x264,0x7ff6c3e282ac,0x7ff6c3e282b8,0x7ff6c3e282c8C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exeupdater.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Updater (x64)
Exit code:
0
Version:
143.0.7514.0
Modules
Images
c:\program files (x86)\ace\aceupdater\143.0.7514.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
5224C:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\Crashpad" --url=https://clients2.google.com/cr/staging_report --annotation=prod=AceUpdater --annotation=ver=143.0.7514.0 "--attachment=C:\Program Files (x86)\Ace\AceUpdater\updater.log" --initial-client-data=0x268,0x26c,0x270,0x250,0x274,0x7ff7025282ac,0x7ff7025282b8,0x7ff7025282c8C:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\updater.exeupdater.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
HIGH
Description:
Ace Updater (x64)
Version:
143.0.7514.0
Modules
Images
c:\users\admin\appdata\local\temp\ace4308_1969508865\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5548"C:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exeservices.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Updater (x64)
Exit code:
0
Version:
143.0.7514.0
Modules
Images
c:\program files (x86)\ace\aceupdater\143.0.7514.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
Total events
14 177
Read events
14 071
Write events
104
Delete events
2

Modification events

(PID) Process:(2524) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F62A668-F2CD-5EE5-AF96-D5E810082767}
Operation:writeName:AppID
Value:
{4F62A668-F2CD-5EE5-AF96-D5E810082767}
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4F62A668-F2CD-5EE5-AF96-D5E810082767}
Operation:writeName:LocalService
Value:
AceUpdaterService143.0.7514.0
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4F62A668-F2CD-5EE5-AF96-D5E810082767}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{283209B7-C761-41CA-BE8D-B5321CD78FD6}
Operation:writeName:AppID
Value:
{283209B7-C761-41CA-BE8D-B5321CD78FD6}
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{E0425C1F-4263-4BA5-9328-423470344FC0}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E0425C1F-4263-4BA5-9328-423470344FC0}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B7DA4837-09FF-4355-BFE1-30598E40F41A}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7DA4837-09FF-4355-BFE1-30598E40F41A}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5548) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D45CFCE3-5297-4D0B-925E-1924A32A7452}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
0
Suspicious files
0
Text files
0
Unknown types
21

Dropped files

PID
Process
Filename
Type
4308AceSetup.exeC:\Users\admin\AppData\Local\Temp\Ace4308_1259004321\UPDATER.PACKED.7Z
MD5:
SHA256:
4308AceSetup.exeC:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\updater.7z
MD5:
SHA256:
5548updater.exeC:\Program Files (x86)\Ace\AceUpdater\prefs.jsonbinary
MD5:078F49F3BE050B7642142E6BF0B50B1B
SHA256:C49632AF4674FE9D9CE718228D2B74AA8519CE1E0C2F74D9ED8798B26BDF0B50
4308AceSetup.exeC:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\uninstall.cmdbinary
MD5:37B06E59CF1AB59705A9B621A76E0BF1
SHA256:4C7FB6EDC3BDC0F12B11B3669F27DC7274EE0642EE0E00FE5B1A04D96A009DBD
1180updater.exeC:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\updater.exebinary
MD5:DCB9128E17C6E9E25F5D69B6F84E35EC
SHA256:ACED4EF02FA4E8B6040F6FD3BE126CB68C8686778A7E2FDC6274E3F06C7742F4
1180updater.exeC:\Program Files (x86)\Ace\AceUpdater\updater.logbinary
MD5:08A47A588A718CDD2F51759FC42A9404
SHA256:3E8DBC32D23E06D45DF15768FF5D5A4B7B986466F38E2EC1021EC16A98AF4EB3
4308AceSetup.exeC:\Users\admin\AppData\Local\Temp\Ace4308_1969508865\bin\updater.exebinary
MD5:DCB9128E17C6E9E25F5D69B6F84E35EC
SHA256:ACED4EF02FA4E8B6040F6FD3BE126CB68C8686778A7E2FDC6274E3F06C7742F4
1180updater.exeC:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\uninstall.cmdbinary
MD5:37B06E59CF1AB59705A9B621A76E0BF1
SHA256:4C7FB6EDC3BDC0F12B11B3669F27DC7274EE0642EE0E00FE5B1A04D96A009DBD
5548updater.exeC:\Program Files (x86)\Ace\AceUpdater\143.0.7514.0\2eb28e5c-8d7f-49ad-b03c-b1b25bd1eb4e.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
1180updater.exeC:\Program Files (x86)\Ace\AceUpdater\prefs.jsonbinary
MD5:1E53B935C07311B38DDA51900A35555F
SHA256:C60A6B88BCA5DA2484854E7265BB82642FD1B929156BAFE8C11E5E721B7A8D28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
26
DNS requests
14
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3156
updater.exe
GET
104.20.31.107:443
https://media.ace.ai/media/versions/ace/mini_installer___ACE-update-143-0-7514-0___x64___20260331130005.crx3
US
unknown
7784
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
7784
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
POST
200
172.66.160.227:443
https://browser.ace.ai/analytics
US
binary
2 b
unknown
2524
slui.exe
POST
500
48.192.1.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
whitelisted
3156
updater.exe
POST
200
34.8.74.205:443
https://update.ace.ai/ace/service/update2/json/fb5bf2ba-306e-11f1-a669-5659c2b1882a@fb5be9fa-306e-11f1-a669-5659c2b1882a@gs_23566648955_196381223707_802980954933@image
US
binary
117 b
unknown
4308
AceSetup.exe
POST
200
104.20.31.107:443
https://browser.ace.ai/analytics
US
2 b
unknown
2524
slui.exe
POST
500
48.192.1.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
512 b
whitelisted
3156
updater.exe
POST
200
34.8.74.205:443
https://update.ace.ai/ace/service/update2/json/fb5bf2ba-306e-11f1-a669-5659c2b1882a@fb5be9fa-306e-11f1-a669-5659c2b1882a@gs_23566648955_196381223707_802980954933@image
US
117 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.218:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7784
svchost.exe
23.48.23.143:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
7784
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.201
whitelisted
google.com
  • 142.251.110.113
  • 142.251.110.100
  • 142.251.110.139
  • 142.251.110.138
  • 142.251.110.101
  • 142.251.110.102
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
  • 2.16.164.120
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.59.18.102
whitelisted
browser.ace.ai
  • 104.20.31.107
  • 172.66.160.227
unknown
update.ace.ai
  • 34.8.74.205
whitelisted
dl.google.com
  • 192.178.183.190
  • 192.178.183.91
  • 192.178.183.136
  • 192.178.183.93
whitelisted
media.ace.ai
  • 104.20.31.107
  • 172.66.160.227
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Observed UA-CPU Header
1180
updater.exe
Misc activity
ET INFO Observed UA-CPU Header
No debug info