File name:

microsoft-office-2021-16-0-18025-20104.exe

Full analysis: https://app.any.run/tasks/f2e4ae1a-2a76-4cd1-a1aa-488459ab3ca3
Verdict: Malicious activity
Analysis date: June 04, 2025, 18:36:14
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

D2AB856F005D2FADEAEB1AABB4530BC3

SHA1:

15864CFE10FD93B9D25AD0839BF077CD4D418839

SHA256:

0D8AAACF5A6C8554BB0FF46752824EB2E30912B8F1D6F8F2E72BAB6568B201D3

SSDEEP:

98304:WVpkJ/P8TKmq1+N42G+71kXkz4RdL3IfcsWwoT9d9QrOGYREikFCjVoxwi1mPwl/:802t

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
    • GENERIC has been found (auto)

      • OfficeClickToRun.exe (PID: 8008)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Process drops legitimate windows executable

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
    • Reads security settings of Internet Explorer

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
    • Searches for installed software

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 8008)
    • Application launched itself

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
  • INFO

    • Checks supported languages

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
      • OfficeClickToRun.exe (PID: 7596)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Reads the computer name

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Reads the machine GUID from the registry

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 7596)
      • OfficeClickToRun.exe (PID: 8080)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Process checks computer location settings

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
    • Checks proxy server information

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
      • OfficeClickToRun.exe (PID: 7596)
    • Process checks whether UAC notifications are on

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
    • Creates files or folders in the user directory

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 7596)
    • Reads the software policy settings

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 7596)
      • slui.exe (PID: 7488)
      • OfficeClickToRun.exe (PID: 8080)
    • Create files in a temporary directory

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 7596)
    • Reads Microsoft Office registry keys

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
      • OfficeClickToRun.exe (PID: 7596)
    • Reads Environment values

      • microsoft-office-2021-16-0-18025-20104.exe (PID: 7256)
      • microsoft-office-2021-16-0-18025-20104.exe (PID: 6992)
    • Creates files in the program directory

      • OfficeClickToRun.exe (PID: 8008)
      • OfficeClickToRun.exe (PID: 8080)
    • The sample compiled with arabic language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with german language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with bulgarian language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with english language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with french language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with Italian language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with spanish language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with Indonesian language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with japanese language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with polish language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with russian language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with korean language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with czech language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with portuguese language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with swedish language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with slovak language support

      • OfficeClickToRun.exe (PID: 8008)
    • The sample compiled with chinese language support

      • OfficeClickToRun.exe (PID: 8008)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 8080)
    • The sample compiled with turkish language support

      • OfficeClickToRun.exe (PID: 8008)
    • Manual execution by a user

      • OfficeC2RClient.exe (PID: 7232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:24 19:36:57+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 4568576
InitializedDataSize: 2994176
UninitializedDataSize: -
EntryPoint: 0x3e2b85
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.18025.20104
ProductVersionNumber: 16.0.18025.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.18025.20104
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.18025.20104
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microsoft-office-2021-16-0-18025-20104.exe sppextcomobj.exe no specs slui.exe microsoft-office-2021-16-0-18025-20104.exe #GENERIC officeclicktorun.exe Delivery Optimization User no specs officeclicktorun.exe officeclicktorun.exe slui.exe officec2rclient.exe

Process information

PID
CMD
Path
Indicators
Parent process
1568C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5744C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
6992"C:\Users\admin\AppData\Local\Temp\microsoft-office-2021-16-0-18025-20104.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 C:\Users\admin\AppData\Local\Temp\microsoft-office-2021-16-0-18025-20104.exe
microsoft-office-2021-16-0-18025-20104.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Version:
16.0.18025.20104
Modules
Images
c:\users\admin\appdata\local\temp\microsoft-office-2021-16-0-18025-20104.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7228C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7232"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /progressandlaunch AppTargets="root\office16\excel.exe|root\office16\msaccess.exe|root\office16\mspub.exe|root\office16\onenote.exe|root\office16\outlook.exe|root\office16\powerpnt.exe|root\office16\winword.exe" ManualUpgrade=False ScenarioToTrack="Scenario:{477E0208-58BD-4F33-978A-09BCC9AA9EB1}@INSTALL"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office Click-to-Run Client
Version:
16.0.18827.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7256"C:\Users\admin\AppData\Local\Temp\microsoft-office-2021-16-0-18025-20104.exe" C:\Users\admin\AppData\Local\Temp\microsoft-office-2021-16-0-18025-20104.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.18025.20104
Modules
Images
c:\users\admin\appdata\local\temp\microsoft-office-2021-16-0-18025-20104.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7488"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7596OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=Professional2021Retail.16_en-us_x-none cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.18827.20140 mediatype.16=CDN sourcetype.16=CDN Professional2021Retail.excludedapps.16=groove updatesenabled.16=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=TrueC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
microsoft-office-2021-16-0-18025-20104.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18827.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8008OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=Professional2021Retail.16_en-us_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.18827.20140 mediatype=CDN sourcetype=CDN Professional2021Retail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
microsoft-office-2021-16-0-18025-20104.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
8080"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18827.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
Total events
63 561
Read events
63 047
Write events
312
Delete events
202

Modification events

(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ru-ru
Value:
2
(PID) Process:(7256) microsoft-office-2021-16-0-18025-20104.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:tr-tr
Value:
2
Executable files
409
Suspicious files
247
Text files
177
Unknown types
64

Dropped files

PID
Process
Filename
Type
7256microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9834F19C-DF76-4A5A-B3FA-1B2A904DAC2Dxml
MD5:E8CCB63F79962D4D9C2B2FC12F5D520E
SHA256:07A1F35C901C0A7059A50E4B020D073FB729ADAAE436D916C76649F4B5669154
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\microsoft-office-2021-16-0-18025-20104.exe.db-journalbinary
MD5:A1A2A4F515F3C6CE90D65F3F3021D90A
SHA256:99A92C946B8BE58097C94BB55C9613ACE939E7C65B076DD4979BD86648DE1414
7256microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\microsoft-office-2021-16-0-18025-20104.exe.dbsqlite
MD5:D0DE7DB24F7B0C0FE636B34E253F1562
SHA256:B6DC74E4A39FFA38ED8C93D58AADEB7E7A0674DAC1152AF413E9DA7313ADE6ED
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A583E2A51BFBDC1E492A57B7C8325850binary
MD5:3206F92E0D3A85C0972A0CDBD677D78C
SHA256:38D86C24059E3ADC20EFAD0923A1004E09941B44BB2F4B8D775C3E7AEE500901
7256microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\microsoft-office-2021-16-0-18025-20104.exe.db-shmbinary
MD5:84712B3BB836D258F493C6E6B5486483
SHA256:337E32A0001EA53F10BF493DA9ECD28C7C778837A83335EF3A9B161D9D1DFA39
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\36AC0BE60E1243344AE145F746D881FEbinary
MD5:B4980C59FCE6DE866BC44BAD7C91BA96
SHA256:60CA889412C8DB101C94EF8201CADD0E9A4C622E91F4C767CFBEA4E06DEA09DD
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:3B5DA32505A8A7E5ABAAB66BFB161033
SHA256:62EFE674599C49D15918886FEEE6A264203600358336703EAC13704CD187213E
8008OfficeClickToRun.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD-20250604-1836.logtext
MD5:2CC4A5E3F08DBE017CF496714F9DBCDB
SHA256:BD206B015E70B71355669F7926A7A8081556073678DCB1A2D925F91D42410308
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R2D27F406-3DE5-4F51-AA5D-54FD6040807A\v64.hashtext
MD5:1330F7C9B20E0848932F22A6548B48D8
SHA256:63EC45BF107A62C00A52092253BC7064942A89B25372BB1D1CD7CB08572D1E63
6992microsoft-office-2021-16-0-18025-20104.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0B8A20E1F3F4D73D52A19929F922C892der
MD5:A511DAB56DC44A64A1114B7814E4F8C6
SHA256:08FA57906B20E454242889F05F1609C276B91A06561121E9012A88A50FF23F9F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
219
TCP/UDP connections
199
DNS requests
128
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5024
svchost.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7776
svchost.exe
GET
200
199.232.210.172:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.18827.20140/i640.cab.phf
unknown
whitelisted
7776
svchost.exe
GET
206
199.232.210.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.18827.20140/i640.cab
unknown
whitelisted
7776
svchost.exe
GET
206
199.232.214.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.18827.20140/i640.cab
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5024
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6992
microsoft-office-2021-16-0-18025-20104.exe
HEAD
200
2.16.168.205:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.16026.20146.cab
unknown
whitelisted
6992
microsoft-office-2021-16-0-18025-20104.exe
HEAD
200
2.16.168.205:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18827.20140.cab
unknown
whitelisted
6992
microsoft-office-2021-16-0-18025-20104.exe
HEAD
200
2.16.168.205:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18827.20140.cab
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5576
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
5024
svchost.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5024
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
7256
microsoft-office-2021-16-0-18025-20104.exe
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
  • 184.25.50.8
  • 184.25.50.10
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
  • 184.30.21.171
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
  • 52.109.32.97
  • 52.109.28.46
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.110.17.32
  • 52.110.17.70
  • 52.110.17.26
  • 52.110.17.60
  • 52.110.17.59
  • 52.110.17.3
  • 52.110.17.21
  • 52.110.17.75
whitelisted
f.c2r.ts.cdn.office.net
  • 2.16.168.205
  • 2.16.168.214
  • 199.232.210.172
  • 199.232.214.172
whitelisted
mobile.events.data.microsoft.com
  • 40.79.173.40
  • 20.189.173.8
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 23.54.109.203
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.3
  • 40.126.31.131
  • 20.190.159.129
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.130
  • 20.190.159.73
whitelisted

Threats

No threats detected
No debug info