File name:

wixtrim-bin.zip

Full analysis: https://app.any.run/tasks/2ec6691c-5fb4-4768-a055-71de127aa62f
Verdict: Malicious activity
Analysis date: May 16, 2025, 09:10:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

5D673E5BC60F7436529AC16A5993BD74

SHA1:

8B8D50E80C22BC89E66C84A03CD65420305C40CD

SHA256:

066261B31C150C307C0F2AEAE6180735C988E8B52123C3BB9B1356FCF8667E80

SSDEEP:

98304:B6FFQE3Or+xTaAP35KO1hNsB8e0l2VBmceVmzyH9uJupHLyrPMMj7Q8SZFFAqK8h:Itqmus9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 7416)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 7416)
    • Starts a Microsoft application from unusual location

      • WixTrim.vshost.exe (PID: 8108)
    • Reads the date of Windows installation

      • dw20.exe (PID: 8140)
    • Reads security settings of Internet Explorer

      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Reads Microsoft Outlook installation path

      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 2432)
      • csc.exe (PID: 4272)
      • csc.exe (PID: 5260)
    • Reads Internet Explorer settings

      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • There is functionality for taking screenshot (YARA)

      • WixTrim.exe (PID: 7232)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7416)
    • Creates files in the program directory

      • dw20.exe (PID: 8140)
    • Manual execution by a user

      • WixTrim.vshost.exe (PID: 8108)
      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • rundll32.exe (PID: 5736)
      • WixTrim.exe (PID: 2772)
    • Reads the computer name

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 2772)
    • Checks supported languages

      • dw20.exe (PID: 8140)
      • WixTrim.vshost.exe (PID: 8108)
      • WixTrim.exe (PID: 7232)
      • csc.exe (PID: 2432)
      • cvtres.exe (PID: 6436)
      • WixTrim.exe (PID: 1628)
      • dfsvc.exe (PID: 7260)
      • csc.exe (PID: 4272)
      • WixTrim.exe (PID: 2772)
      • cvtres.exe (PID: 5608)
      • csc.exe (PID: 5260)
      • cvtres.exe (PID: 2040)
    • Reads the machine GUID from the registry

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • csc.exe (PID: 2432)
      • cvtres.exe (PID: 6436)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • csc.exe (PID: 4272)
      • cvtres.exe (PID: 5608)
      • WixTrim.exe (PID: 2772)
      • csc.exe (PID: 5260)
      • cvtres.exe (PID: 2040)
    • Reads Environment values

      • dw20.exe (PID: 8140)
      • dfsvc.exe (PID: 7260)
    • Reads product name

      • dw20.exe (PID: 8140)
    • Process checks computer location settings

      • dw20.exe (PID: 8140)
    • Checks proxy server information

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
      • slui.exe (PID: 2564)
    • Creates files or folders in the user directory

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Reads the software policy settings

      • dw20.exe (PID: 8140)
      • slui.exe (PID: 7596)
      • slui.exe (PID: 2564)
    • Reads CPU info

      • dw20.exe (PID: 8140)
    • Create files in a temporary directory

      • WixTrim.exe (PID: 7232)
      • cvtres.exe (PID: 6436)
      • csc.exe (PID: 2432)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • cvtres.exe (PID: 5608)
      • csc.exe (PID: 4272)
      • WixTrim.exe (PID: 2772)
      • csc.exe (PID: 5260)
      • cvtres.exe (PID: 2040)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 7296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2006:10:02 12:08:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Funnel/Funnel/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
22
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs wixtrim.vshost.exe no specs dw20.exe wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs openwith.exe no specs slui.exe rundll32.exe no specs dfsvc.exe no specs wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1628"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Exit code:
0
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2040C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES57BE.tmp" "c:\Users\admin\AppData\Local\Temp\CSC57BD.tmp"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.9672 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
2432"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\rfrgwmi3.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
c:\windows\system32\msvcrt.dll
2564C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2772"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3180\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4272"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\fy5thdnu.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
5260"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\bdk3dlfk.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
5608C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES1C7A.tmp" "c:\Users\admin\AppData\Local\Temp\CSC1C79.tmp"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.9672 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
c:\windows\system32\bcrypt.dll
5736"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbApplication C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.applicationC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
10 331
Read events
10 274
Write events
40
Delete events
17

Modification events

(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\wixtrim-bin.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
17
Suspicious files
16
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.dllexecutable
MD5:78AAB7651A7D5F31DEE4B6A9960C337B
SHA256:5A8CCC0082048A147ADC9C95796D9DFF3FC3F17AB29609BCD8D06C30FA6ECC25
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.pdbbinary
MD5:B88EF8C821EB5884E2A26E5F379946F4
SHA256:F49E73084F9C1136BA72CD4496ADA2725D156AE663E3BBB7E1EC1AD759A5F74D
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixDesigner.dllexecutable
MD5:4116A785F7BD460A01C8C88458F93C82
SHA256:E2D99C5C43BB0AFE4C14772CC636609A948B6B74B3F78BE40D3D7B6220490FBE
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.exe.manifestxml
MD5:8D4772324CD1A1E92CC9DDD99CB09E10
SHA256:9B286E698EE7FD2198D5B5B75FB846CC1F5AAB39D34D907698A2AD9AEDBBF411
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.applicationxml
MD5:7BD0652AA6E8E92B1B7D73647185B723
SHA256:133717D8327990301C2F90E9A6FC212D5991D48143A5FE8F9BC5E3F4B5C5CA37
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.exeexecutable
MD5:9CE9B24722A620804E6A8BEC9C30FE56
SHA256:E122EC296743DB15BBB0ED0CDBBCD8737DCAFA68C9A22A9533E8B1E1755EFA66
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.pdbbinary
MD5:EE90E96608B00A1C289F4009E19A88B6
SHA256:91291D699A5E20243BAF2125F3AEB616BC7B01D61AFD895781D8817C58FE749B
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\SandDock.xmlxml
MD5:46C3F8DC7DFF0ED21A1AD919AA6A65A4
SHA256:68A1D6BFCA97EFF28D6AF60E4AF91436CBB3099494B06759901546ED0AA98FB3
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\Interop.MsmMergeTypeLib.dllexecutable
MD5:6951F0FFA143B7F5781832AF0F1BE6C1
SHA256:2AD15AC0393C9FF0C57BE34B886FE901A5BD72D88EADA42C9E2D3F104D101D53
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WindowsInstaller.pdbbinary
MD5:DE1296AFE3266D924706D79C8616E604
SHA256:E0474B375432C1D2D1C0864FC6C66BBBAB26164F60014666AB4B33BCE818DCF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
25
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7888
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7888
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8140
dw20.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8140
dw20.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6652
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.65
  • 20.190.160.130
  • 20.190.160.67
  • 40.126.32.68
  • 20.190.160.17
  • 20.190.160.4
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted

Threats

No threats detected
No debug info