File name:

wixtrim-bin.zip

Full analysis: https://app.any.run/tasks/2ec6691c-5fb4-4768-a055-71de127aa62f
Verdict: Malicious activity
Analysis date: May 16, 2025, 09:10:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

5D673E5BC60F7436529AC16A5993BD74

SHA1:

8B8D50E80C22BC89E66C84A03CD65420305C40CD

SHA256:

066261B31C150C307C0F2AEAE6180735C988E8B52123C3BB9B1356FCF8667E80

SSDEEP:

98304:B6FFQE3Or+xTaAP35KO1hNsB8e0l2VBmceVmzyH9uJupHLyrPMMj7Q8SZFFAqK8h:Itqmus9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 7416)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 7416)
    • Starts a Microsoft application from unusual location

      • WixTrim.vshost.exe (PID: 8108)
    • Reads the date of Windows installation

      • dw20.exe (PID: 8140)
    • Reads security settings of Internet Explorer

      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Reads Microsoft Outlook installation path

      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 2432)
      • csc.exe (PID: 4272)
      • csc.exe (PID: 5260)
    • Reads Internet Explorer settings

      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • There is functionality for taking screenshot (YARA)

      • WixTrim.exe (PID: 7232)
  • INFO

    • Manual execution by a user

      • WixTrim.vshost.exe (PID: 8108)
      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • rundll32.exe (PID: 5736)
      • WixTrim.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7416)
    • Checks supported languages

      • WixTrim.vshost.exe (PID: 8108)
      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • csc.exe (PID: 2432)
      • cvtres.exe (PID: 6436)
      • WixTrim.exe (PID: 1628)
      • dfsvc.exe (PID: 7260)
      • cvtres.exe (PID: 5608)
      • WixTrim.exe (PID: 2772)
      • csc.exe (PID: 4272)
      • cvtres.exe (PID: 2040)
      • csc.exe (PID: 5260)
    • Reads the computer name

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Reads the machine GUID from the registry

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • cvtres.exe (PID: 6436)
      • csc.exe (PID: 2432)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • cvtres.exe (PID: 5608)
      • WixTrim.exe (PID: 2772)
      • csc.exe (PID: 4272)
      • cvtres.exe (PID: 2040)
      • csc.exe (PID: 5260)
    • Creates files in the program directory

      • dw20.exe (PID: 8140)
    • Reads Environment values

      • dw20.exe (PID: 8140)
      • dfsvc.exe (PID: 7260)
    • Reads product name

      • dw20.exe (PID: 8140)
    • Reads CPU info

      • dw20.exe (PID: 8140)
    • Process checks computer location settings

      • dw20.exe (PID: 8140)
    • Checks proxy server information

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
      • slui.exe (PID: 2564)
    • Creates files or folders in the user directory

      • dw20.exe (PID: 8140)
      • WixTrim.exe (PID: 7232)
      • dfsvc.exe (PID: 7260)
      • WixTrim.exe (PID: 1628)
      • WixTrim.exe (PID: 2772)
    • Reads the software policy settings

      • dw20.exe (PID: 8140)
      • slui.exe (PID: 7596)
      • slui.exe (PID: 2564)
    • Create files in a temporary directory

      • WixTrim.exe (PID: 7232)
      • cvtres.exe (PID: 6436)
      • csc.exe (PID: 2432)
      • dfsvc.exe (PID: 7260)
      • csc.exe (PID: 4272)
      • cvtres.exe (PID: 5608)
      • WixTrim.exe (PID: 1628)
      • csc.exe (PID: 5260)
      • WixTrim.exe (PID: 2772)
      • cvtres.exe (PID: 2040)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 7296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2006:10:02 12:08:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Funnel/Funnel/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
22
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs wixtrim.vshost.exe no specs dw20.exe wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs openwith.exe no specs slui.exe rundll32.exe no specs dfsvc.exe no specs wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs wixtrim.exe no specs csc.exe conhost.exe no specs cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1628"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Exit code:
0
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2040C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES57BE.tmp" "c:\Users\admin\AppData\Local\Temp\CSC57BD.tmp"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.9672 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
2432"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\rfrgwmi3.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
c:\windows\system32\msvcrt.dll
2564C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2772"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3180\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4272"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\fy5thdnu.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
5260"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\bdk3dlfk.cmdline"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
5608C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES1C7A.tmp" "c:\Users\admin\AppData\Local\Temp\CSC1C79.tmp"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.9672 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
c:\windows\system32\bcrypt.dll
5736"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbApplication C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.applicationC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
10 331
Read events
10 274
Write events
40
Delete events
17

Modification events

(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\wixtrim-bin.zip
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
17
Suspicious files
16
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.dllexecutable
MD5:78AAB7651A7D5F31DEE4B6A9960C337B
SHA256:5A8CCC0082048A147ADC9C95796D9DFF3FC3F17AB29609BCD8D06C30FA6ECC25
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\Window Layout.xmlxml
MD5:45D1040989520AF543B1F8F20D02A5A3
SHA256:221AB7AB77313D0AE189266B1B42A618C830132A3F4D4A6A1A439E9A877B6456
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WindowsInstaller.dllexecutable
MD5:859287D1D935C40C981F9B49039E6F5C
SHA256:EE866160B08AF12A18441C310808CCC6DF430C345549DF61D9A210A1C16698E2
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\SandDock.xmlxml
MD5:46C3F8DC7DFF0ED21A1AD919AA6A65A4
SHA256:68A1D6BFCA97EFF28D6AF60E4AF91436CBB3099494B06759901546ED0AA98FB3
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\SandDock.dllexecutable
MD5:B35E0BA22F9D6E99243526A21F8C5352
SHA256:53A8A91FD51535A73C9E473222EC65DE60B1CBBBC50104A51E9EF86BEA5560E4
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixDesigner.pdbbinary
MD5:A4C6E4545A0DE0515DBB18F353B3D198
SHA256:5758A52FD84FDFAE85DE5542CC367261BF31BFC818D8C93A2FE32FF37FF9D9B4
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixDesigner.dllexecutable
MD5:4116A785F7BD460A01C8C88458F93C82
SHA256:E2D99C5C43BB0AFE4C14772CC636609A948B6B74B3F78BE40D3D7B6220490FBE
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.pdbbinary
MD5:B88EF8C821EB5884E2A26E5F379946F4
SHA256:F49E73084F9C1136BA72CD4496ADA2725D156AE663E3BBB7E1EC1AD759A5F74D
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.pdbbinary
MD5:EE90E96608B00A1C289F4009E19A88B6
SHA256:91291D699A5E20243BAF2125F3AEB616BC7B01D61AFD895781D8817C58FE749B
7416WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixTrim.vshost.applicationxml
MD5:7BD0652AA6E8E92B1B7D73647185B723
SHA256:133717D8327990301C2F90E9A6FC212D5991D48143A5FE8F9BC5E3F4B5C5CA37
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
25
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7888
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7888
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8140
dw20.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8140
dw20.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6652
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.65
  • 20.190.160.130
  • 20.190.160.67
  • 40.126.32.68
  • 20.190.160.17
  • 20.190.160.4
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted

Threats

No threats detected
No debug info