File name:

Antivirus.exe

Full analysis: https://app.any.run/tasks/43434fd9-e1ea-480f-91ec-d1ef538d2eb6
Verdict: Malicious activity
Analysis date: January 13, 2025, 09:14:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
arch-exec
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

43CD42FE47AF2256E4414264F49AF1A8

SHA1:

3CCBBFFFD0DA76F72DD99AC39AFCFDFACD5F16E2

SHA256:

0918FA4B22D3E212A13FA449A5A7B5C3EC97759DD87DB6D281F387B1570E13C9

SSDEEP:

3072:fVGnJGXX4ftqRjLnohZR2NyDxHUSUIUyAUw5TmpAREl7j3:fVG4XX4ftqBLohjD9UXyAUtiO3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 3812)
      • SecHealthUI.exe (PID: 3884)
      • VirusTotalUploader2.2.exe (PID: 2672)
    • Executable content was dropped or overwritten

      • Antivirus.exe (PID: 6500)
    • Creates a software uninstall entry

      • Antivirus.exe (PID: 6500)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 5036)
    • Starts CMD.EXE for commands execution

      • salinewin.exe (PID: 4036)
  • INFO

    • Checks supported languages

      • Antivirus.exe (PID: 6500)
      • ShellExperienceHost.exe (PID: 3812)
      • SecHealthUI.exe (PID: 3884)
      • VirusTotalUploader2.2.exe (PID: 7480)
      • salinewin.exe (PID: 4036)
    • Reads the computer name

      • ShellExperienceHost.exe (PID: 3812)
      • Antivirus.exe (PID: 6500)
      • SecHealthUI.exe (PID: 3884)
      • VirusTotalUploader2.2.exe (PID: 7480)
    • Sends debugging messages

      • SecHealthUI.exe (PID: 3884)
      • ShellExperienceHost.exe (PID: 3812)
    • Creates files in the program directory

      • Antivirus.exe (PID: 6500)
    • Manual execution by a user

      • VirusTotalUploader2.2.exe (PID: 7480)
      • VirusTotalUploader2.2.exe (PID: 2672)
      • chrome.exe (PID: 7552)
    • Creates files or folders in the user directory

      • Antivirus.exe (PID: 6500)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6880)
      • chrome.exe (PID: 6704)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6880)
    • Application launched itself

      • chrome.exe (PID: 7552)
    • Checks proxy server information

      • VirusTotalUploader2.2.exe (PID: 2672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:07:14 20:09:51+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x310b
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
182
Monitored processes
40
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start antivirus.exe shellexperiencehost.exe no specs systemsettingsbroker.exe no specs sechealthui.exe no specs securityhealthhost.exe no specs securityhealthhost.exe no specs securityhealthhost.exe no specs virustotaluploader2.2.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs winrar.exe salinewin.exe no specs salinewin.exe cmd.exe no specs conhost.exe no specs reg.exe no specs virustotaluploader2.2.exe antivirus.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
736"C:\Users\admin\AppData\Local\Temp\Rar$EXa6880.21347\salinewin.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6880.21347\salinewin.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6880.21347\salinewin.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1016"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3336 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2008"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=5340 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2144C:\Windows\System32\SecurityHealthHost.exe {E041C90B-68BA-42C9-991E-477B73A75C90} -EmbeddingC:\Windows\System32\SecurityHealthHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Security Health Host
Exit code:
0
Version:
4.18.1907.16384 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\securityhealthhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
2420"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --mojo-platform-channel-handle=5896 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2672"C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe" C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1073807364
Modules
Images
c:\program files (x86)\virustotaluploader2\virustotaluploader2.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\psapi.dll
c:\windows\syswow64\user32.dll
3656"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5692 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3700"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3420 --field-trial-handle=1936,i,3664736542057246324,6046982101547591865,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3732C:\Windows\System32\SystemSettingsBroker.exe -EmbeddingC:\Windows\System32\SystemSettingsBroker.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Settings Broker
Exit code:
1073807364
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\systemsettingsbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
3812"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
Total events
13 779
Read events
13 707
Write events
64
Delete events
8

Modification events

(PID) Process:(3812) ShellExperienceHost.exeKey:\REGISTRY\A\{ec6344ba-7740-e13f-8dcc-37462428f73a}\LocalState
Operation:writeName:placeholderLayout
Value:
7B0022004900730052006500730069007A00610062006C00650022003A0074007200750065002C002200470072006F0075007000730022003A005B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0031002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022002C0022005400690074006C00650022003A0022004E006500740077006F0072006B0022002C002200490063006F006E0022003A00220077EE22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022002C0022005400690074006C00650022003A00220041006C006C002000730065007400740069006E006700730022002C002200490063006F006E0022003A00220013E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022002C0022005400690074006C00650022003A0022004C006F0063006100740069006F006E0022002C002200490063006F006E0022003A00220007E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022002C0022005400690074006C00650022003A00220046006F00630075007300200061007300730069007300740022002C002200490063006F006E0022003A00220008E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022002C0022005400690074006C00650022003A0022004E00690067006800740020006C00690067006800740022002C002200490063006F006E0022003A0022008CF022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022002C0022005400690074006C00650022003A002200560050004E0022002C002200490063006F006E0022003A00220005E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022002C0022005400690074006C00650022003A002200500072006F006A0065006300740022002C002200490063006F006E0022003A002200C6EB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022002C0022005400690074006C00650022003A00220043006F006E006E0065006300740022002C002200490063006F006E0022003A002200DEEB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022002C0022005400690074006C00650022003A002200530063007200650065006E00200073006E006900700022002C002200490063006F006E0022003A00220006F422002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220053006C006900640065007200470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0031002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D005D007D00000014CCCDA39B65DB01
(PID) Process:(3812) ShellExperienceHost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.controlcenter.uistate\windows.data.controlcenter.uistate
Operation:writeName:Data
Value:
434201000A0201002A069DB393BC062A2B0EFD2A43420100D20AD4085B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006100740074006500720079005300610076006500720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C007500650074006F006F007400680022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005400610062006C00650074004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0052006F0074006100740069006F006E004C006F0063006B0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006C006F007200500072006F00660069006C00650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00430065006C006C0075006C006100720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004D006F00620069006C00650048006F007400730070006F00740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006900720070006C0061006E0065004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004E006500610072005300680061007200650022007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004200720069006700680074006E0065007300730022007D005D007D005D00D214E40C7B0022004900730052006500730069007A00610062006C00650022003A0074007200750065002C002200470072006F0075007000730022003A005B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0031002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022002C0022005400690074006C00650022003A0022004E006500740077006F0072006B0022002C002200490063006F006E0022003A00220077EE22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022002C0022005400690074006C00650022003A00220041006C006C002000730065007400740069006E006700730022002C002200490063006F006E0022003A00220013E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022002C0022005400690074006C00650022003A0022004C006F0063006100740069006F006E0022002C002200490063006F006E0022003A00220007E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022002C0022005400690074006C00650022003A00220046006F00630075007300200061007300730069007300740022002C002200490063006F006E0022003A00220008E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022002C0022005400690074006C00650022003A0022004E00690067006800740020006C00690067006800740022002C002200490063006F006E0022003A0022008CF022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0030007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022002C0022005400690074006C00650022003A002200560050004E0022002C002200490063006F006E0022003A00220005E722002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022002C0022005400690074006C00650022003A002200500072006F006A0065006300740022002C002200490063006F006E0022003A002200C6EB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022002C0022005400690074006C00650022003A00220043006F006E006E0065006300740022002C002200490063006F006E0022003A002200DEEB22002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022002C0022005400690074006C00650022003A002200530063007200650065006E00200073006E006900700022002C002200490063006F006E0022003A00220006F422002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220051007500690063006B0054006F00670067006C006500540065006D0070006C006100740065004400650073006B0074006F00700022002C002200540079007000650022003A0031007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220047007200690064005600690065007700470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0034002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220043007500730074006F006D00540065006D0070006C006100740065004B006500790022003A00220053006C006900640065007200470072006F0075007000540065006D0070006C0061007400650043006F006D00700061006300740022002C0022004D0069006E0052006F007700730022003A0030002C00220052006F0077005700690064007400680022003A0031002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D005D007D0000000000
(PID) Process:(3812) ShellExperienceHost.exeKey:\REGISTRY\A\{ec6344ba-7740-e13f-8dcc-37462428f73a}\LocalState
Operation:writeName:layout
Value:
5B007B0022004E0061006D00650022003A00220054006F00670067006C006500730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041007600610069006C00610062006C0065004E006500740077006F0072006B00730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006C006C00530065007400740069006E006700730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004C006F0063006100740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005100750069006500740048006F0075007200730022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C00750065004C00690067006800740052006500640075006300740069006F006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00560070006E0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00500072006F006A0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006E006E0065006300740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00530063007200650065006E0043006C0069007000700069006E00670022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006100740074006500720079005300610076006500720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0042006C007500650074006F006F007400680022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E005400610062006C00650074004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0052006F0074006100740069006F006E004C006F0063006B0022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0043006F006C006F007200500072006F00660069006C00650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E00430065006C006C0075006C006100720022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004D006F00620069006C00650048006F007400730070006F00740022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E0041006900720070006C0061006E0065004D006F006400650022007D002C007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004E006500610072005300680061007200650022007D005D007D002C007B0022004E0061006D00650022003A00220046006C006F007700730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B005D007D002C007B0022004E0061006D00650022003A00220053006C006900640065007200730022002C00220051007500690063006B0041006300740069006F006E00730022003A005B007B00220046007200690065006E0064006C0079004E0061006D00650022003A0022004D006900630072006F0073006F00660074002E0051007500690063006B0041006300740069006F006E002E004200720069006700680074006E0065007300730022007D005D007D005D000000274DCBA39B65DB01
(PID) Process:(3812) ShellExperienceHost.exeKey:HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture
Operation:writeName:GroupCount
Value:
3
(PID) Process:(3812) ShellExperienceHost.exeKey:HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture
Operation:writeName:Toggles
Value:
Toggles,Microsoft.QuickAction.AvailableNetworks:false,Microsoft.QuickAction.AllSettings:false,Microsoft.QuickAction.Location:false,Microsoft.QuickAction.QuietHours:false,Microsoft.QuickAction.BlueLightReduction:false,Microsoft.QuickAction.Vpn:false,Microsoft.QuickAction.Project:false,Microsoft.QuickAction.Connect:false,Microsoft.QuickAction.ScreenClipping:false
(PID) Process:(3812) ShellExperienceHost.exeKey:HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture
Operation:writeName:Flows
Value:
Flows
(PID) Process:(3812) ShellExperienceHost.exeKey:HKEY_CURRENT_USER\Control Panel\Quick Actions\Control Center\QuickActionsStateCapture
Operation:writeName:Sliders
Value:
Sliders
(PID) Process:(6500) Antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\vtuploader
Operation:writeName:Icon
Value:
C:\Program Files (x86)\VirusTotalUploader2\VirusTotalUploader2.2.exe,0
(PID) Process:(6500) Antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Virustotal\VTUploader
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\VirusTotalUploader2
(PID) Process:(6500) Antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VTUploader
Operation:writeName:DisplayName
Value:
VirusTotal Uploader 2.2
Executable files
8
Suspicious files
417
Text files
46
Unknown types
7

Dropped files

PID
Process
Filename
Type
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1465ec.TMP
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1465ec.TMP
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1465ec.TMP
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1465ec.TMP
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF1465fc.TMP
MD5:
SHA256:
7552chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
122
DNS requests
124
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5268
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/mleab47izotil6qv3goi2qnzb4_20250105.712697894.14/obedbbhbpmojnkanicioggnmelmoomoc_20250105.712697894.14_all_ENUS500000_adrawdzru5huqzgurwx7xv4jv3ua.crx3
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5592
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5592
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6840
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5268
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads7ltfl2gw6hxwgakn3sxrkoijq_9.53.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.53.0_all_iky7dhj3jd5su3axccoshyd4xm.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
40.119.249.228:443
MICROSOFT-CORP-MSN-AS-BLOCK
SG
unknown
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.119.249.228:443
MICROSOFT-CORP-MSN-AS-BLOCK
SG
unknown
4712
MoUsoCoreWorker.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.202
  • 2.23.227.215
  • 2.23.227.221
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.68
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.20
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.76
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
r.bing.com
  • 2.23.227.202
  • 2.23.227.198
  • 2.23.227.221
  • 2.23.227.208
whitelisted

Threats

PID
Process
Class
Message
7724
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7724
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
1 ETPRO signatures available at the full report
No debug info