File name:

MacDrive Pro v11.1.1.12 CE.exe

Full analysis: https://app.any.run/tasks/4e71fc6b-c83a-408d-b35a-bf6f462e2fbf
Verdict: Malicious activity
Analysis date: February 19, 2025, 15:09:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

22C6EC406846BD265419BBCE92A5DA7B

SHA1:

E50FCD89E009AEFF782EE671EFD51F6C15E96624

SHA256:

089EF92BFF723691D5B2A3DD111038F7A4B5FC3D6D2CE40B9BE1FF6F86F05C8F

SSDEEP:

98304:Nikl/tt13Ydp6SF/o1jVpKd4eKSW+FnblRtPSRZMOxIuHLXLc1XPaTIOsSCKjEbV:dQdn/a3gaYnCUKzGznuuXfLR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • wow64sup.exe (PID: 2260)
      • wow64sup.exe (PID: 2424)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6428)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • drvinst.exe (PID: 3564)
      • MacDrive Disk Image.exe (PID: 188)
      • wow64sup.exe (PID: 2424)
      • MacDrive Service.exe (PID: 6868)
      • wow64sup.exe (PID: 2260)
    • Reads security settings of Internet Explorer

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
    • Process drops legitimate windows executable

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • msiexec.exe (PID: 6944)
      • MacDrive Service.exe (PID: 6868)
    • Reads the Windows owner or organization settings

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
    • Drops a system driver (possible attempt to evade defenses)

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • msiexec.exe (PID: 6944)
      • MacDrive Disk Image.exe (PID: 188)
      • wow64sup.exe (PID: 2424)
      • drvinst.exe (PID: 3564)
      • wow64sup.exe (PID: 2260)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7044)
      • MacDrive Service.exe (PID: 6868)
      • vds.exe (PID: 4392)
      • OWCFSEventsService.exe (PID: 648)
    • Image mount has been detect

      • drvinst.exe (PID: 372)
    • Uses REG/REGEDIT.EXE to modify registry

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
  • INFO

    • Process checks computer location settings

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
    • Create files in a temporary directory

      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6428)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
    • Checks supported languages

      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6428)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
      • msiexec.exe (PID: 6984)
      • msiexec.exe (PID: 6944)
    • Reads the computer name

      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
      • msiexec.exe (PID: 6944)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • msiexec.exe (PID: 6984)
    • The sample compiled with english language support

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • drvinst.exe (PID: 3564)
      • MacDrive Disk Image.exe (PID: 188)
      • wow64sup.exe (PID: 2424)
      • wow64sup.exe (PID: 2260)
      • msiexec.exe (PID: 6944)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6908)
      • msiexec.exe (PID: 6944)
    • Application launched itself

      • msiexec.exe (PID: 6944)
    • Detects InnoSetup installer (YARA)

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6428)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
    • Compiled with Borland Delphi (YARA)

      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6488)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6428)
      • MacDrive Pro v11.1.1.12 CE.exe (PID: 6692)
      • MacDrive Pro v11.1.1.12 CE.tmp (PID: 6716)
    • Manages system restore points

      • SrTasks.exe (PID: 5652)
    • The sample compiled with czech language support

      • msiexec.exe (PID: 6944)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 6944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:10 21:24:32+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 782848
InitializedDataSize: 143872
UninitializedDataSize: -
EntryPoint: 0xc0004
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 11.1.1.12
ProductVersionNumber: 11.1.1.12
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Other World Computing
FileDescription: MacDrive Pro 11.1.1.12
FileVersion: 11.1.1.12
LegalCopyright: © 1996-2022 MediaFour; 2017-2024 Other World Computing, Inc.
OriginalFileName:
ProductName: MacDrive Pro 11.1.1.12
ProductVersion: 11.1.1.12
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
38
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start macdrive pro v11.1.1.12 ce.exe macdrive pro v11.1.1.12 ce.tmp no specs macdrive pro v11.1.1.12 ce.exe macdrive pro v11.1.1.12 ce.tmp msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiea5b.tmp no specs msieaf9.tmp no specs msief6e.tmp no specs msief9e.tmp no specs msiexec.exe no specs drvinst.exe drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs macdrive disk image.exe wow64sup.exe conhost.exe no specs wow64sup.exe conhost.exe no specs macdrive service.exe vdsldr.exe no specs vds.exe no specs owcfseventsservice.exe activate macdrive.exe no specs msi2b83.tmp no specs owc product updates helper.exe no specs msi2d79.tmp no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Program Files\OWC\MacDrive 11\MacDrive Disk Image.exe" /installdriverC:\Program Files\OWC\MacDrive 11\MacDrive Disk Image.exe
msiexec.exe
User:
admin
Company:
OWC
Integrity Level:
HIGH
Description:
MacDrive Disk Image
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\owc\macdrive 11\macdrive disk image.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
372DrvInst.exe "2" "211" "ROOT\SCSIADAPTER\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:57de7b8f3742476c:OWCVirtualDisk_Device:12.59.17.498:root\owcvirtualdisk2," "4ab4d401f" "00000000000000EC"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewow64sup.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
648"C:\Program Files\Common Files\OWC\FSEvents\OWCFSEventsService.exe"C:\Program Files\Common Files\OWC\FSEvents\OWCFSEventsService.exe
services.exe
User:
SYSTEM
Company:
OWC
Integrity Level:
SYSTEM
Description:
FSEventsApp
Version:
11.1.1.9
Modules
Images
c:\program files\common files\owc\fsevents\owcfseventsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
900"C:\WINDOWS\Installer\MSI2D79.tmp"C:\Windows\Installer\MSI2D79.tmpmsiexec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2147942403
Modules
Images
c:\windows\installer\msi2d79.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
1544"C:\Windows\System32\MsiExec.exe" /Y "C:\Program Files\OWC\MacDrive 11\MDOptions.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1988C:\Windows\System32\MsiExec.exe -Embedding A0E347AD3AE930910F3E29F0C9C51AB4C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2260"C:\Users\admin\AppData\Local\Temp\cbd5AC.tmp\x64\wow64sup.exe"C:\Users\admin\AppData\Local\Temp\cbd5AC.tmp\x64\wow64sup.exe
MacDrive Disk Image.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cbd5ac.tmp\x64\wow64sup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2424"C:\Users\admin\AppData\Local\Temp\cbdFE78.tmp\x64\wow64sup.exe"C:\Users\admin\AppData\Local\Temp\cbdFE78.tmp\x64\wow64sup.exe
MacDrive Disk Image.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cbdfe78.tmp\x64\wow64sup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
15 297
Read events
14 051
Write events
1 212
Delete events
34

Modification events

(PID) Process:(6716) MacDrive Pro v11.1.1.12 CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mediafour\Common\Logging\M4LIC2.DLL
Operation:writeName:EnabledLevels
Value:
0
(PID) Process:(6716) MacDrive Pro v11.1.1.12 CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mediafour\Common\Logging\MacDrive.exe
Operation:writeName:EnabledLevels
Value:
0
(PID) Process:(6716) MacDrive Pro v11.1.1.12 CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mediafour\Common\Logging\License.x64.dll
Operation:writeName:EnabledLevels
Value:
0
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000007CB73654E082DB01201B00006C1B0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000DEDC3954E082DB01201B00006C1B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000006A2F9D54E082DB01201B00006C1B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000006A2F9D54E082DB01201B00006C1B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000281DA954E082DB01201B00006C1B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000009656A454E082DB01201B00006C1B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6944) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
Executable files
361
Suspicious files
107
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\CFiles64\OWC\Drivers\OWCVirtualDisk2\OWCVirtualDisk.catbinary
MD5:0D0D406CD3A3A0F79F4E973052AE0A26
SHA256:80B7E18CAC98AC9CBCBE9B5335139FE41039DA2E9455921E9DBCFCE933FAF1C3
6692MacDrive Pro v11.1.1.12 CE.exeC:\Users\admin\AppData\Local\Temp\is-JQIN4.tmp\MacDrive Pro v11.1.1.12 CE.tmpexecutable
MD5:62C23FD36356E79C4FC299E2FE3C18A7
SHA256:11D53C40CD0E588E481BE56B0F2B35D2510BF2B38E5EA6FF3A642A0F36C80017
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\is-FAN6Q.tmpxml
MD5:4F2113B75A5F0955A32C2D4CAA746AE0
SHA256:6B34BB4064B3D2FB6D87D1816152E6385120C4DBA3F3B710A725EED8FC171838
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\MacDrive Helper.exe.configxml
MD5:4F2113B75A5F0955A32C2D4CAA746AE0
SHA256:6B34BB4064B3D2FB6D87D1816152E6385120C4DBA3F3B710A725EED8FC171838
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\CommApp\OWC\MacDrive 11\Licenses\macdrive-11binary
MD5:695A72754CFC073332545044232C6195
SHA256:6FBD18F5D5C6D8D8D54A767D40C05374E88517DB3923BA2BC6C192C3EDCFBC36
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\CommApp\OWC\MacDrive 11\Licenses\is-GBNGD.tmpbinary
MD5:695A72754CFC073332545044232C6195
SHA256:6FBD18F5D5C6D8D8D54A767D40C05374E88517DB3923BA2BC6C192C3EDCFBC36
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\callback.CBFSDisk.dllexecutable
MD5:E8552411F46756ACB3BAD80EA102ECF6
SHA256:0ABF7A2290E736E4FEAA6E0EA42FF45BAD53204FFA829345FC9696A3635D47A7
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\is-7D2AS.tmpexecutable
MD5:24EC1BFB69CC48411BE0303AD895196D
SHA256:CE1209E1A08F40F4F88C7A31A9F7FD08CE41182E95563C2B77727D366B080BC2
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\Caliburn.Micro.Platform.Core.dllexecutable
MD5:24EC1BFB69CC48411BE0303AD895196D
SHA256:CE1209E1A08F40F4F88C7A31A9F7FD08CE41182E95563C2B77727D366B080BC2
6716MacDrive Pro v11.1.1.12 CE.tmpC:\Users\admin\AppData\Local\Temp\is-CBGAE.tmp\PFiles64\OWC\MacDrive 11\is-QQPL1.tmpexecutable
MD5:B6DD8323B8C000C8BBCD4459B48BC7A2
SHA256:CFBB50C7103A982A471E4E65E26774CDCE9412ADAB6203A981A60C76934C3DBA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
37
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
3140
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5696
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
ID
binary
419 b
whitelisted
5696
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
ID
binary
408 b
whitelisted
6868
MacDrive Service.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEA9iL28hwv9dUh9yOh1H1i0%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
23.48.23.139:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2160
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
crl.microsoft.com
  • 23.48.23.139
  • 23.48.23.188
  • 23.48.23.140
  • 23.48.23.137
  • 23.48.23.192
  • 23.48.23.191
  • 23.48.23.176
  • 23.48.23.183
  • 23.48.23.190
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.209.214.100
whitelisted
google.com
  • 216.58.206.46
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.0
  • 20.190.159.71
  • 40.126.31.3
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.130
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
Process
Message
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#000000001F500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#000000001F500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000003FCB800000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000003FAAF00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000003FAAF00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
MacDrive Service.exe
Mount detected: \\?\STORAGE#Volume#{90cf3dd6-0af7-11ec-b480-806e6f6e6963}#0000003FCB800000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
OWCFSEventsService.exe
Service Started
OWCFSEventsService.exe
OWCFSEventsService.exe Information: 0 :