File name:

OfficeSetup.exe

Full analysis: https://app.any.run/tasks/24424ebf-cf5b-4c9f-9991-7117d94049cf
Verdict: Malicious activity
Analysis date: May 10, 2025, 13:50:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

571A8BAB0BD60B69C9488867BAE20912

SHA1:

F98B31F3201D0279434C548A6B75DBCD043BC332

SHA256:

087C5D720ACE3AA78EC0BF5BB5257C62A89589DA626663B3C6E738AF7C29B17D

SSDEEP:

98304:CeYDn+P++j8xOxtxUBacyWOOXCigTc0Rd847TucE2725rKbkK9hFPU5EKe5EF1ML:4/m/D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • OfficeSetup.exe (PID: 4120)
      • OfficeSetup.exe (PID: 672)
    • GENERIC has been found (auto)

      • OfficeClickToRun.exe (PID: 7376)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • OfficeSetup.exe (PID: 4892)
      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
    • Process drops legitimate windows executable

      • OfficeSetup.exe (PID: 4892)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
    • Application launched itself

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4892)
    • Reads security settings of Internet Explorer

      • OfficeSetup.exe (PID: 4120)
      • OfficeSetup.exe (PID: 672)
    • Searches for installed software

      • OfficeSetup.exe (PID: 4120)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 7376)
  • INFO

    • Reads the computer name

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
      • OfficeClickToRun.exe (PID: 7472)
    • Reads the machine GUID from the registry

      • OfficeSetup.exe (PID: 672)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 4988)
      • OfficeClickToRun.exe (PID: 7472)
    • Checks supported languages

      • OfficeSetup.exe (PID: 4892)
      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
      • OfficeClickToRun.exe (PID: 7472)
    • Reads Microsoft Office registry keys

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 7472)
      • OfficeClickToRun.exe (PID: 4988)
    • Process checks computer location settings

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
    • Process checks whether UAC notifications are on

      • OfficeSetup.exe (PID: 672)
    • Checks proxy server information

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
      • OfficeClickToRun.exe (PID: 7472)
    • Create files in a temporary directory

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 7472)
    • Reads CPU info

      • OfficeSetup.exe (PID: 4120)
      • OfficeSetup.exe (PID: 672)
    • Reads Environment values

      • OfficeSetup.exe (PID: 4120)
      • OfficeSetup.exe (PID: 672)
    • Reads the software policy settings

      • OfficeSetup.exe (PID: 672)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7472)
      • OfficeClickToRun.exe (PID: 4988)
      • slui.exe (PID: 5936)
    • Creates files or folders in the user directory

      • OfficeSetup.exe (PID: 672)
      • OfficeSetup.exe (PID: 4120)
      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 7472)
    • Creates files in the program directory

      • OfficeClickToRun.exe (PID: 7376)
      • OfficeClickToRun.exe (PID: 4988)
    • The sample compiled with arabic language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with spanish language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with czech language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with german language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with french language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with korean language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with Indonesian language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with Italian language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with chinese language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with japanese language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with portuguese language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with polish language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with russian language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with slovak language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with turkish language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with swedish language support

      • OfficeClickToRun.exe (PID: 7376)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 4988)
    • Manual execution by a user

      • OfficeC2RClient.exe (PID: 4756)
    • The sample compiled with bulgarian language support

      • OfficeClickToRun.exe (PID: 7376)
    • The sample compiled with english language support

      • OfficeClickToRun.exe (PID: 7376)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:02 22:57:08+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.4
CodeSize: 4682240
InitializedDataSize: 2945536
UninitializedDataSize: -
EntryPoint: 0x3fbdc5
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.18730.20142
ProductVersionNumber: 16.0.18730.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.18730.20142
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.18730.20142
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start officesetup.exe no specs officesetup.exe officesetup.exe sppextcomobj.exe no specs slui.exe #GENERIC officeclicktorun.exe Delivery Optimization User no specs officeclicktorun.exe officeclicktorun.exe slui.exe officec2rclient.exe

Process information

PID
CMD
Path
Indicators
Parent process
672OfficeSetup.exe RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.18730.20142
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4120"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Version:
16.0.18730.20142
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4756"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /progressandlaunch AppTargets="root\office16\excel.exe|root\office16\onenote.exe|root\office16\powerpnt.exe|root\office16\winword.exe" ManualUpgrade=False ScenarioToTrack="Scenario:{477E0208-58BD-4F33-978A-09BCC9AA9EB1}@INSTALL"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office Click-to-Run Client
Version:
16.0.18730.20142
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\common files\microsoft shared\clicktorun\apiclient.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140.dll
c:\program files\common files\microsoft shared\clicktorun\msvcp140.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
4892"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" C:\Users\admin\AppData\Local\Temp\OfficeSetup.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.18730.20142
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4988"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18730.20142
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
c:\program files\common files\microsoft shared\clicktorun\msvcp140.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140.dll
c:\program files\common files\microsoft shared\clicktorun\apiclient.dll
c:\windows\system32\advapi32.dll
5056C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5936"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7376OfficeClickToRun.exe platform=x64 culture=fr-fr productstoadd=O365AppsBasicRetail.16_fr-fr_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.18730.20142 mediatype=CDN sourcetype=CDN O365AppsBasicRetail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7472OfficeClickToRun.exe platform=x64 culture=fr-fr productstoadd=O365AppsBasicRetail.16_fr-fr_x-none cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.18730.20142 mediatype.16=CDN sourcetype.16=CDN O365AppsBasicRetail.excludedapps.16=groove updatesenabled.16=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown uninstallcentennial=TrueC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18730.20142
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140.dll
c:\program files\common files\microsoft shared\clicktorun\msvcp140.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
c:\program files\common files\microsoft shared\clicktorun\apiclient.dll
7588C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
Total events
78 403
Read events
77 848
Write events
334
Delete events
221

Modification events

(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3
Operation:writeName:Last
Value:
0
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3\0
Operation:writeName:FilePath
Value:
officeclient.microsoft.com\E93DE6EC-5FA5-4C3C-9A28-76B85EAD6089
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3\0
Operation:writeName:StartDate
Value:
D07D5D8FB2C1DB01
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3\0
Operation:writeName:EndDate
Value:
D03DC7B97BC2DB01
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3\0
Operation:writeName:Properties
Value:
1
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.18730&crev=3\0
Operation:writeName:Url
Value:
https://officeclient.microsoft.com/config16/?syslcid=1033&build=16.0.18730&crev=3
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache
Operation:writeName:LastClean
Value:
D07D5D8FB2C1DB01
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe\ULSMonitor
Operation:delete keyName:(default)
Value:
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(672) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe\ULSMonitor
Operation:writeName:ULSTagIds0
Value:
41816131,577889346,5804129,17102418,39389248,7202269,41484365,24262478,595174594,3700754,593359442,17110988,17962391,17962392,17110992,20502174,3702920,3462423,3965062,24262474,4297094,7153421,24262473,18716193,7153487,7153435,7202265,24262477,6308191,18407617,51475283,9179410,3462365,6104718,9179409,9179411,41185282,39125643,539756558,539756557,528570079
Executable files
403
Suspicious files
434
Text files
519
Unknown types
2

Dropped files

PID
Process
Filename
Type
4120OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A583E2A51BFBDC1E492A57B7C8325850binary
MD5:E25E1240FEB32DE14377ADDD66925A40
SHA256:E2DF7A6F1149985095D8785F11A13ADF364440A69584A0AEC6C748825CDB1CAC
672OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E93DE6EC-5FA5-4C3C-9A28-76B85EAD6089xml
MD5:583A28BB3621239DE0F83CAB98459ED0
SHA256:A9B315913E0B463B759AA7B1870B71DED74C1A1620137EF9F3416A2F56706E3B
4120OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\36AC0BE60E1243344AE145F746D881FEbinary
MD5:A44EBB6F613F0180BADDE624492A9FBE
SHA256:E57C0D92D6A92E4AFC9669DAB1B387F54E779A408EAB75D2E04402A47890F9D0
4120OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\36AC0BE60E1243344AE145F746D881FEbinary
MD5:411D4C6D9068F0593E05D0F67B46BF77
SHA256:743747DD59C21B0ECD5328A93F31A5D89A9765AFC6740C4963EBA797AA383043
4120OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:48CE0711D3D5BB6DFB5636B8D1E300D9
SHA256:DDB27469D387E919C1331552DFBA9E54341561FB42E50D2190F61A39CB2C6377
4120OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:CB0BF7779501DB0D4AB56C44DD13CEFF
SHA256:F3C27A5F606A7FDBA1104AF40D3E34F71E7E0C3255E88DFA8784D1992C5D7B2E
672OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-walbinary
MD5:71FBCABE1C73880846B5208231A62E70
SHA256:FDA3288A894B7548A31A255A1249E8809DA1FB0C8A044B00968D0546F860486A
4120OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R5A2A595F-D52D-4A25-A5F3-1D7D15CDBAB3\v64.hashtext
MD5:546CD976A9BE62D7A3985E675DC5F66E
SHA256:E5085F50422B67CE0BF4159F1389995DC64B885E3F919AC7E26FDA7DF47470BE
4120OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R5A2A595F-D52D-4A25-A5F3-1D7D15CDBAB3OfficeC2RFEC511C4-B282-46DF-BB7C-89B32B8AFA69\v64.hashtext
MD5:546CD976A9BE62D7A3985E675DC5F66E
SHA256:E5085F50422B67CE0BF4159F1389995DC64B885E3F919AC7E26FDA7DF47470BE
4120OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R5A2A595F-D52D-4A25-A5F3-1D7D15CDBAB3OfficeC2RFEC511C4-B282-46DF-BB7C-89B32B8AFA69\VersionDescriptor.xmlxml
MD5:3A5E916A6B94B0C146230E8F637D7D14
SHA256:179BB37A090088DECE6644751A9C6CC0D1CA1918F9502DA61DA59502D9D7283A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
261
TCP/UDP connections
251
DNS requests
167
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4120
OfficeSetup.exe
HEAD
200
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
HEAD
200
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
GET
200
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
4120
OfficeSetup.exe
HEAD
200
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
GET
206
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
4120
OfficeSetup.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
HEAD
200
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18730.20142.cab
unknown
whitelisted
7504
svchost.exe
GET
200
2.22.242.89:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.18730.20142/i640.cab.phf
unknown
whitelisted
4120
OfficeSetup.exe
GET
200
23.48.23.161:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
4120
OfficeSetup.exe
GET
200
23.48.23.161:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.161:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
672
OfficeSetup.exe
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
672
OfficeSetup.exe
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4120
OfficeSetup.exe
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4120
OfficeSetup.exe
52.110.17.67:443
mrodevicemgr.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4120
OfficeSetup.exe
199.232.210.172:80
f.c2r.ts.cdn.office.net
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.161
  • 23.48.23.150
  • 23.48.23.156
  • 23.48.23.164
  • 23.48.23.180
  • 23.48.23.176
  • 23.48.23.177
  • 23.48.23.173
  • 23.48.23.147
  • 2.16.168.114
  • 2.16.168.124
  • 2.16.164.51
  • 2.16.164.106
  • 2.16.164.34
  • 2.16.164.114
  • 2.16.164.9
  • 2.16.164.24
  • 23.48.23.162
  • 23.48.23.166
  • 23.48.23.159
  • 23.48.23.158
  • 23.48.23.183
  • 23.48.23.143
  • 23.48.23.193
  • 23.48.23.169
  • 23.48.23.194
  • 23.48.23.185
  • 23.48.23.190
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
  • 95.101.149.131
  • 23.219.150.101
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
  • 52.109.28.46
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.110.17.67
  • 52.110.17.3
  • 52.110.17.18
  • 52.110.17.74
  • 52.110.17.45
  • 52.110.17.46
  • 52.110.17.40
  • 52.110.17.26
whitelisted
f.c2r.ts.cdn.office.net
  • 199.232.210.172
  • 199.232.214.172
  • 2.22.242.89
  • 2.22.242.130
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.131
  • 20.190.160.130
  • 40.126.32.138
  • 20.190.160.132
  • 40.126.31.129
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.130
  • 20.190.159.2
  • 20.190.159.73
  • 20.190.159.128
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info