File name:

Cold Turkey Micromanager Pro v1.1 Final x86 x64.rar

Full analysis: https://app.any.run/tasks/8d481316-3dad-4b99-9328-e1407138092b
Verdict: Malicious activity
Analysis date: January 04, 2025, 00:37:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
netreactor
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C863C61D7AA8079763C40692CC0E8774

SHA1:

D86B5F7DA357A88802901E129A5979851BB58D84

SHA256:

0D2FB5E8D0E63EE5ED158C1713B425B98C5AD4333FA53F71BCCEEF74E35982DB

SSDEEP:

98304:w+3dh/eOl0Kg7SWLQsRWeXzdfMlFAA0erLdmGO1bNIp6pj0wHR2UvBWgQVZVxc12:GNqu4DByfA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5684)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup.exe (PID: 6748)
      • setup.exe (PID: 6840)
      • setup.tmp (PID: 6864)
    • Reads security settings of Internet Explorer

      • setup.tmp (PID: 6764)
      • Cold Turkey Micromanager.exe (PID: 4504)
    • Reads Microsoft Outlook installation path

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Reads the Windows owner or organization settings

      • setup.tmp (PID: 6864)
    • Process drops legitimate windows executable

      • setup.tmp (PID: 6864)
    • Reads Internet Explorer settings

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Executes as Windows Service

      • MMService.exe (PID: 6960)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 5684)
      • WINWORD.EXE (PID: 5000)
      • Cold Turkey Micromanager.exe (PID: 4504)
    • Create files in a temporary directory

      • setup.exe (PID: 6748)
      • setup.exe (PID: 6840)
      • setup.tmp (PID: 6864)
    • Manual execution by a user

      • setup.exe (PID: 6748)
      • Cold Turkey Micromanager.exe (PID: 6832)
      • Cold Turkey Micromanager.exe (PID: 4504)
      • WINWORD.EXE (PID: 5000)
      • WinRAR.exe (PID: 3552)
      • mspaint.exe (PID: 5400)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5684)
    • Checks supported languages

      • setup.tmp (PID: 6764)
      • setup.exe (PID: 6748)
      • Cold Turkey Micromanager.exe (PID: 4504)
      • setup.tmp (PID: 6864)
      • setup.exe (PID: 6840)
      • MMService.exe (PID: 6960)
    • Process checks computer location settings

      • setup.tmp (PID: 6764)
    • Reads the computer name

      • setup.tmp (PID: 6764)
      • Cold Turkey Micromanager.exe (PID: 4504)
      • setup.tmp (PID: 6864)
      • MMService.exe (PID: 6960)
    • Creates a software uninstall entry

      • setup.tmp (PID: 6864)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 6312)
    • Reads the machine GUID from the registry

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Checks proxy server information

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Creates files in the program directory

      • setup.tmp (PID: 6864)
    • Disables trace logs

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Reads Environment values

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Reads the software policy settings

      • Cold Turkey Micromanager.exe (PID: 4504)
    • .NET Reactor protector has been detected

      • Cold Turkey Micromanager.exe (PID: 4504)
    • Drops encrypted VBS script (Microsoft Script Encoder)

      • WINWORD.EXE (PID: 5000)
    • Sends debugging messages

      • WINWORD.EXE (PID: 5000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 386988
UncompressedSize: 580096
OperatingSystem: Win32
ArchivedFileName: Cold Turkey Micromanager Pro v1.1 Final x86 x64/Crack/Cold Turkey Micromanager.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
14
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs setup.exe setup.tmp no specs setup.exe setup.tmp Copy/Move/Rename/Delete/Link Object no specs cold turkey micromanager.exe no specs cold turkey micromanager.exe mmservice.exe no specs winrar.exe no specs winword.exe ai.exe no specs mspaint.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3080"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "F80F0F59-49B0-41F3-93CD-1A3CA9668D1B" "60BDA7ED-9754-4411-BBC4-C739625487E8" "5000"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3552"C:\Program Files\WinRAR\WinRAR.exe" C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4504"C:\Program Files\Cold Turkey Micromanager\Cold Turkey Micromanager.exe" C:\Program Files\Cold Turkey Micromanager\Cold Turkey Micromanager.exe
explorer.exe
User:
admin
Company:
Cold Turkey Software
Integrity Level:
HIGH
Description:
Cold Turkey Micromanager
Version:
1.0.0.0
Modules
Images
c:\program files\cold turkey micromanager\cold turkey micromanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5000"C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\Desktop\somethingless.rtf" /o ""C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
5400"C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\similarpractice.png"C:\Windows\System32\mspaint.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Paint
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mspaint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5684"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Cold Turkey Micromanager Pro v1.1 Final x86 x64.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6312C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
6704C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6748"C:\Users\admin\Desktop\Cold Turkey Micromanager Pro v1.1 Final x86 x64\setup.exe" C:\Users\admin\Desktop\Cold Turkey Micromanager Pro v1.1 Final x86 x64\setup.exe
explorer.exe
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
MEDIUM
Description:
Cold Turkey Micromanager Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\cold turkey micromanager pro v1.1 final x86 x64\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6764"C:\Users\admin\AppData\Local\Temp\is-FVJ3Q.tmp\setup.tmp" /SL5="$30220,4536375,839680,C:\Users\admin\Desktop\Cold Turkey Micromanager Pro v1.1 Final x86 x64\setup.exe" C:\Users\admin\AppData\Local\Temp\is-FVJ3Q.tmp\setup.tmpsetup.exe
User:
admin
Company:
Cold Turkey Software, Inc.
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fvj3q.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
19 054
Read events
18 624
Write events
408
Delete events
22

Modification events

(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Cold Turkey Micromanager Pro v1.1 Final x86 x64.rar
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5684) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6864) setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6498E673-B9C2-4544-A722-2E854B5B573F}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.1.0-beta
(PID) Process:(6864) setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6498E673-B9C2-4544-A722-2E854B5B573F}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Cold Turkey Micromanager
Executable files
78
Suspicious files
172
Text files
67
Unknown types
6

Dropped files

PID
Process
Filename
Type
6864setup.tmpC:\Program Files\Cold Turkey Micromanager\is-MSURL.tmpexecutable
MD5:1D63BA0BFF134B408853A77A50A49FDD
SHA256:886F75A21201493D735E012C180EE98835AD4704772BDA3B25DC6C9743E03023
6864setup.tmpC:\Users\admin\AppData\Local\Temp\is-6HQ68.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6840setup.exeC:\Users\admin\AppData\Local\Temp\is-9I0NL.tmp\setup.tmpexecutable
MD5:C234BD61E05C24A98F555DB25980C68B
SHA256:6A8F7626CBCC6FE465E8077262EB6E455EF5AF8128D7D03BD15A15F19570A0B0
5684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5684.37370\Cold Turkey Micromanager Pro v1.1 Final x86 x64\Crack\how2do.txttext
MD5:7A7C0E4C063CB965220EFA0841538BBB
SHA256:035928B844BEEE3941A301610E954593B15E030F9A382A22F73C583A993D6E02
6748setup.exeC:\Users\admin\AppData\Local\Temp\is-FVJ3Q.tmp\setup.tmpexecutable
MD5:C234BD61E05C24A98F555DB25980C68B
SHA256:6A8F7626CBCC6FE465E8077262EB6E455EF5AF8128D7D03BD15A15F19570A0B0
5684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5684.37370\Cold Turkey Micromanager Pro v1.1 Final x86 x64\how2do.txttext
MD5:B955B854084550A88928CF8CD4F4515A
SHA256:2F35D281DFEA0B45ADBCE2C9078F97A162026FA48A5F99771203DB1FD148A1C0
6864setup.tmpC:\Program Files\Cold Turkey Micromanager\unins000.exeexecutable
MD5:1D63BA0BFF134B408853A77A50A49FDD
SHA256:886F75A21201493D735E012C180EE98835AD4704772BDA3B25DC6C9743E03023
6864setup.tmpC:\Program Files\Cold Turkey Micromanager\Cold Turkey Micromanager.exeexecutable
MD5:700BDF4CF0CAA21BF1EA9E64FDF15A87
SHA256:9D53F6D0C318F3F493224CE739898C9D5DB7E768F18A0ED4C7C3A4B2AD27CEB5
5684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5684.37370\Cold Turkey Micromanager Pro v1.1 Final x86 x64\setup.exeexecutable
MD5:CF52C3127CEF5EE75C031C60FBBB27C4
SHA256:382088D00031A556B3204BF3835B0078FE158FB92A10E8E6FBE66240022B2516
6864setup.tmpC:\Program Files\Cold Turkey Micromanager\is-2GQ11.tmpexecutable
MD5:700BDF4CF0CAA21BF1EA9E64FDF15A87
SHA256:9D53F6D0C318F3F493224CE739898C9D5DB7E768F18A0ED4C7C3A4B2AD27CEB5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
90
DNS requests
40
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2756
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1156
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5000
WINWORD.EXE
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5000
WINWORD.EXE
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
whitelisted
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1156
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5000
WINWORD.EXE
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
440
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
  • 2.16.164.49
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 184.30.230.103
  • 184.30.21.171
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.133
  • 40.126.32.138
unknown
go.microsoft.com
  • 23.56.254.14
whitelisted
arc.msn.com
  • 20.199.58.43
unknown
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
Process
Message
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.