File name:

aspnetcore-runtime-8.0.8-win-x64.exe

Full analysis: https://app.any.run/tasks/7a421325-645f-46c2-891c-24f4e3fd74a5
Verdict: Malicious activity
Analysis date: August 26, 2024, 06:24:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6F56897E53C987931F68ED1F1CA04063

SHA1:

4E8A77A431CD04B3B5E3ECED67C6224EF418E8C0

SHA256:

0F00E3E8630D8261B1962DA3BB4DF136E85F17FE15412D863BE8F61256AD9E63

SSDEEP:

98304:q1svXJG6gIS6wHtj3/ZV5N8T5Whj2FsVw7bEMWkF4PyKKm2pAf9wO91HBpqp2wXP:eADc8zGVaisc+GAMvg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Process drops legitimate windows executable

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
    • Drops the executable file immediately after the start

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
    • Executable content was dropped or overwritten

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Searches for installed software

      • dllhost.exe (PID: 6996)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7040)
    • Reads security settings of Internet Explorer

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Reads the date of Windows installation

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Starts itself from another location

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Creates a software uninstall entry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6892)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6892)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6892)
  • INFO

    • Checks supported languages

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
      • msiexec.exe (PID: 2132)
    • Create files in a temporary directory

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Reads the computer name

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • msiexec.exe (PID: 6892)
      • msiexec.exe (PID: 2132)
    • Creates files in the program directory

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Process checks computer location settings

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Reads the software policy settings

      • msiexec.exe (PID: 6892)
    • Reads the machine GUID from the registry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6892)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6892)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:22 22:14:43+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 314368
InitializedDataSize: 164352
UninitializedDataSize: -
EntryPoint: 0x302e5
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.0.8.24369
ProductVersionNumber: 8.0.8.24369
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
FileVersion: 8.0.8.24369
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: AspNetCoreSharedFrameworkBundle-x64.exe
ProductName: Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
ProductVersion: 8.0.8.24369
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start aspnetcore-runtime-8.0.8-win-x64.exe aspnetcore-runtime-8.0.8-win-x64.exe aspnetcoresharedframeworkbundle-x64.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2132C:\Windows\syswow64\MsiExec.exe -Embedding 6731BAA0E099D1BAC4E63419F9FB1FCAC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6388C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6688"C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe" C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\aspnetcore-runtime-8.0.8-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6712"C:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe" -burn.filehandle.attached=700 -burn.filehandle.self=616 C:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe
aspnetcore-runtime-8.0.8-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\{3d09b568-e133-4599-abe5-e71d9b9f3bd1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6892C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6948"C:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.be\AspNetCoreSharedFrameworkBundle-x64.exe" -q -burn.elevated BurnPipe.{D847F40E-A827-47EB-801B-035C3E904003} {EC32CA33-F4F7-4AA0-8C33-472C8DF60C6B} 6712C:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.be\AspNetCoreSharedFrameworkBundle-x64.exe
aspnetcore-runtime-8.0.8-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\{196fc09c-0431-44ca-986f-0d031dd819fe}\.be\aspnetcoresharedframeworkbundle-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6996C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
7040C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 880
Read events
11 365
Write events
480
Delete events
35

Modification events

(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6948) AspNetCoreSharedFrameworkBundle-x64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000004BDF5DAE80F7DA01241B0000281B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000000E4560AE80F7DA01541B00006C1B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000031B0B3AE80F7DA01541B00006C1B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
480000000000000031B0B3AE80F7DA01541B00006C1B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000ED7BB8AE80F7DA01541B00006C1B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000003734BDAE80F7DA01541B00006C1B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
146
Suspicious files
18
Text files
24
Unknown types
5

Dropped files

PID
Process
Filename
Type
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\2052\thm.wxlxml
MD5:746BA4C9816D9E151D4814D606BB5B17
SHA256:B50A6DE4C1834889DC39BD3944D6539FCF13FDB544769DE738A36BB4838C1E1F
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\wixstdba.dllexecutable
MD5:F68F43F809840328F4E993A54B0D5E62
SHA256:E921F69B9FB4B5AD4691809D06896C5F1D655AB75E0CE94A372319C243C56D4E
6688aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exeexecutable
MD5:27BB02F0A2317DEAEC8D506618989834
SHA256:2289EEEE46F1ABFA20851025E8E2EA393A966F50A52144F149ED5A9B6A465925
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1031\thm.wxlxml
MD5:640087421D90D8CB132AF3563AD719DF
SHA256:4717A1D19F622D64B446B9995C5388E40BFC3B0E87C6B96F12A9F3562F5AF279
6996dllhost.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1036\thm.wxlxml
MD5:D7D57C17E633E99888CAABADBA8093AB
SHA256:607F94E200ED131CC0439D326491A2ECF1FD8A2EB4F1664E12FA7EE6DC914C94
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1028\thm.wxlxml
MD5:423EE6BAFEB6F2D8D3C9C9BD12DB179B
SHA256:B427A8FF060943FC26EBC09A3652D3B233F590D883BDD997365DC7FD42D9C445
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\AspNetCoreSharedFramework_x64
MD5:
SHA256:
6948AspNetCoreSharedFrameworkBundle-x64.exeC:\ProgramData\Package Cache\.unverified\AspNetCoreSharedFramework_x64
MD5:
SHA256:
6948AspNetCoreSharedFrameworkBundle-x64.exeC:\ProgramData\Package Cache\{1A631874-52CA-3CD6-84C2-0465F1280EDA}v8.0.8.24369\aspnetcore-runtime-8.0.8-servicing.24369.8-win-x64.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6292
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6292
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6892
msiexec.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4296
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
2580
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2580
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5372
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
unknown
6292
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6292
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
www.bing.com
  • 2.23.209.176
  • 2.23.209.168
  • 2.23.209.166
  • 2.23.209.177
  • 2.23.209.169
  • 2.23.209.175
  • 2.23.209.172
  • 2.23.209.173
  • 2.23.209.167
whitelisted
r.bing.com
  • 2.23.209.161
  • 2.23.209.157
  • 2.23.209.162
  • 2.23.209.159
  • 2.23.209.154
  • 2.23.209.150
  • 2.23.209.158
  • 2.23.209.166
  • 2.23.209.160
  • 2.23.209.189
  • 2.23.209.183
  • 2.23.209.185
  • 2.23.209.180
  • 2.23.209.188
  • 2.23.209.181
  • 2.23.209.191
  • 2.23.209.182
  • 2.23.209.186
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.71
whitelisted

Threats

No threats detected
No debug info