File name:

aspnetcore-runtime-8.0.8-win-x64.exe

Full analysis: https://app.any.run/tasks/7a421325-645f-46c2-891c-24f4e3fd74a5
Verdict: Malicious activity
Analysis date: August 26, 2024, 06:24:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6F56897E53C987931F68ED1F1CA04063

SHA1:

4E8A77A431CD04B3B5E3ECED67C6224EF418E8C0

SHA256:

0F00E3E8630D8261B1962DA3BB4DF136E85F17FE15412D863BE8F61256AD9E63

SSDEEP:

98304:q1svXJG6gIS6wHtj3/ZV5N8T5Whj2FsVw7bEMWkF4PyKKm2pAf9wO91HBpqp2wXP:eADc8zGVaisc+GAMvg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
    • Process drops legitimate windows executable

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • msiexec.exe (PID: 6892)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Starts a Microsoft application from unusual location

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Executable content was dropped or overwritten

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Searches for installed software

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • dllhost.exe (PID: 6996)
    • Starts itself from another location

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Reads the date of Windows installation

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Reads security settings of Internet Explorer

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7040)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6892)
    • Creates a software uninstall entry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6892)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6892)
  • INFO

    • Checks supported languages

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
      • msiexec.exe (PID: 2132)
    • Create files in a temporary directory

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6688)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Reads the computer name

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
      • msiexec.exe (PID: 2132)
    • Process checks computer location settings

      • aspnetcore-runtime-8.0.8-win-x64.exe (PID: 6712)
    • Creates files in the program directory

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
    • Reads the machine GUID from the registry

      • AspNetCoreSharedFrameworkBundle-x64.exe (PID: 6948)
      • msiexec.exe (PID: 6892)
    • Reads the software policy settings

      • msiexec.exe (PID: 6892)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6892)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6892)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:22 22:14:43+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 314368
InitializedDataSize: 164352
UninitializedDataSize: -
EntryPoint: 0x302e5
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.0.8.24369
ProductVersionNumber: 8.0.8.24369
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
FileVersion: 8.0.8.24369
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: AspNetCoreSharedFrameworkBundle-x64.exe
ProductName: Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
ProductVersion: 8.0.8.24369
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start aspnetcore-runtime-8.0.8-win-x64.exe aspnetcore-runtime-8.0.8-win-x64.exe aspnetcoresharedframeworkbundle-x64.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2132C:\Windows\syswow64\MsiExec.exe -Embedding 6731BAA0E099D1BAC4E63419F9FB1FCAC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6388C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6688"C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe" C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\aspnetcore-runtime-8.0.8-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6712"C:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\aspnetcore-runtime-8.0.8-win-x64.exe" -burn.filehandle.attached=700 -burn.filehandle.self=616 C:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe
aspnetcore-runtime-8.0.8-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\{3d09b568-e133-4599-abe5-e71d9b9f3bd1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6892C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6948"C:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.be\AspNetCoreSharedFrameworkBundle-x64.exe" -q -burn.elevated BurnPipe.{D847F40E-A827-47EB-801B-035C3E904003} {EC32CA33-F4F7-4AA0-8C33-472C8DF60C6B} 6712C:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.be\AspNetCoreSharedFrameworkBundle-x64.exe
aspnetcore-runtime-8.0.8-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ASP.NET Core 8.0.8 - Shared Framework (x64)
Exit code:
0
Version:
8.0.8.24369
Modules
Images
c:\users\admin\appdata\local\temp\{196fc09c-0431-44ca-986f-0d031dd819fe}\.be\aspnetcoresharedframeworkbundle-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6996C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
7040C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 880
Read events
11 365
Write events
480
Delete events
35

Modification events

(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6712) aspnetcore-runtime-8.0.8-win-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6948) AspNetCoreSharedFrameworkBundle-x64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000004BDF5DAE80F7DA01241B0000281B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000000E4560AE80F7DA01541B00006C1B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000031B0B3AE80F7DA01541B00006C1B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
480000000000000031B0B3AE80F7DA01541B00006C1B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000ED7BB8AE80F7DA01541B00006C1B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000003734BDAE80F7DA01541B00006C1B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
146
Suspicious files
18
Text files
24
Unknown types
5

Dropped files

PID
Process
Filename
Type
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\2052\thm.wxlxml
MD5:746BA4C9816D9E151D4814D606BB5B17
SHA256:B50A6DE4C1834889DC39BD3944D6539FCF13FDB544769DE738A36BB4838C1E1F
6688aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{3D09B568-E133-4599-ABE5-E71D9B9F3BD1}\.cr\aspnetcore-runtime-8.0.8-win-x64.exeexecutable
MD5:27BB02F0A2317DEAEC8D506618989834
SHA256:2289EEEE46F1ABFA20851025E8E2EA393A966F50A52144F149ED5A9B6A465925
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1028\thm.wxlxml
MD5:423EE6BAFEB6F2D8D3C9C9BD12DB179B
SHA256:B427A8FF060943FC26EBC09A3652D3B233F590D883BDD997365DC7FD42D9C445
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1029\thm.wxlxml
MD5:BAB2CEA64BA8779D11C881BB497E254F
SHA256:7A3D1C7744F8E07A4F456F7A2EB99630568C617F4655092E93E62EA966F82228
6996dllhost.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1033\thm.wxlxml
MD5:D4226D322E0A676476DB291AB59C0CD1
SHA256:65507DDC6F2AB2A93B684684BA1D69FDF0B024296367CDCE5DAD31D5E49813D0
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\.ba\1040\thm.wxlxml
MD5:F5FAF70E5413B4CD0D4BE910EBFA47DE
SHA256:381D318AE2AD67D7DE09F4B3AA215F329C034FD38C5C79E3FD4862D45A4A7017
6712aspnetcore-runtime-8.0.8-win-x64.exeC:\Users\admin\AppData\Local\Temp\{196FC09C-0431-44CA-986F-0D031DD819FE}\AspNetCoreSharedFramework_x64
MD5:
SHA256:
6948AspNetCoreSharedFrameworkBundle-x64.exeC:\ProgramData\Package Cache\.unverified\AspNetCoreSharedFramework_x64
MD5:
SHA256:
6948AspNetCoreSharedFrameworkBundle-x64.exeC:\ProgramData\Package Cache\{1A631874-52CA-3CD6-84C2-0465F1280EDA}v8.0.8.24369\aspnetcore-runtime-8.0.8-servicing.24369.8-win-x64.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6292
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6892
msiexec.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
6292
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4296
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
2580
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2580
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5372
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
unknown
6292
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6292
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
www.bing.com
  • 2.23.209.176
  • 2.23.209.168
  • 2.23.209.166
  • 2.23.209.177
  • 2.23.209.169
  • 2.23.209.175
  • 2.23.209.172
  • 2.23.209.173
  • 2.23.209.167
whitelisted
r.bing.com
  • 2.23.209.161
  • 2.23.209.157
  • 2.23.209.162
  • 2.23.209.159
  • 2.23.209.154
  • 2.23.209.150
  • 2.23.209.158
  • 2.23.209.166
  • 2.23.209.160
  • 2.23.209.189
  • 2.23.209.183
  • 2.23.209.185
  • 2.23.209.180
  • 2.23.209.188
  • 2.23.209.181
  • 2.23.209.191
  • 2.23.209.182
  • 2.23.209.186
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.71
whitelisted

Threats

No threats detected
No debug info