File name:

PSAgentInstaller.exe

Full analysis: https://app.any.run/tasks/ad8cdafc-dd9c-4b7c-8b0d-44c15d25a39a
Verdict: Malicious activity
Analysis date: December 26, 2023, 10:55:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B41C61FE254B1C1CA243E38222C3709F

SHA1:

41AC991AD54C1238593A9202F8293BEC852D3A7B

SHA256:

1009D6DB73A7B2CC1D82B77141EFD17C3A3A590264315EF019B9BCE8946BB57D

SSDEEP:

98304:9u0sG94xlidCBpJLouPuMVR80M1cWYn9g+YJzsskV2WJUDXAQ74W75wy8W7OE7Sk:mT1iu83Q/SUeht2YHgxIaHQ3cmH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • PSAgentInstaller.tmp (PID: 548)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 1592)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • PSAgentInstaller.tmp (PID: 548)
    • Uses TASKKILL.EXE to kill process

      • PSAgentInstaller.tmp (PID: 548)
    • Starts CMD.EXE for commands execution

      • PSAgentInstaller.tmp (PID: 548)
      • RemovePrintserver.exe (PID: 1784)
      • node.exe (PID: 3436)
      • node.exe (PID: 2136)
    • The process deletes folder without confirmation

      • RemovePrintserver.exe (PID: 1784)
    • Reads the Internet Settings

      • SoftovWD.exe (PID: 3328)
      • PSAgentInstaller.tmp (PID: 548)
      • RemovePrintserver.exe (PID: 1784)
      • node.exe (PID: 3436)
      • sipnotify.exe (PID: 1460)
      • SoftovWD.exe (PID: 336)
      • node.exe (PID: 2136)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1460)
    • Adds/modifies Windows certificates

      • sipnotify.exe (PID: 1460)
  • INFO

    • Checks supported languages

      • PSAgentInstaller.exe (PID: 116)
      • PSAgentInstaller.tmp (PID: 1072)
      • PSAgentInstaller.exe (PID: 1380)
      • PSAgentInstaller.tmp (PID: 548)
      • SoftovWD.exe (PID: 3328)
      • CertMgr.exe (PID: 3304)
      • RemovePrintserver.exe (PID: 1784)
      • node.exe (PID: 3436)
      • node.exe (PID: 3644)
      • IMEKLMG.EXE (PID: 1200)
      • SoftovWD.exe (PID: 336)
      • node.exe (PID: 2136)
      • IMEKLMG.EXE (PID: 1676)
      • node.exe (PID: 2348)
      • wmpnscfg.exe (PID: 2496)
      • SoftovWD.exe (PID: 2656)
      • SoftovWD.exe (PID: 2696)
      • UserInteractive.exe (PID: 2844)
      • SoftovWD.exe (PID: 2780)
      • wmpnscfg.exe (PID: 2536)
    • Create files in a temporary directory

      • PSAgentInstaller.exe (PID: 116)
      • PSAgentInstaller.exe (PID: 1380)
      • PSAgentInstaller.tmp (PID: 548)
    • Drops the executable file immediately after the start

      • PSAgentInstaller.exe (PID: 116)
      • PSAgentInstaller.exe (PID: 1380)
      • PSAgentInstaller.tmp (PID: 548)
    • Reads the computer name

      • PSAgentInstaller.tmp (PID: 1072)
      • PSAgentInstaller.tmp (PID: 548)
      • RemovePrintserver.exe (PID: 1784)
      • node.exe (PID: 3436)
      • PSAgentInstaller.exe (PID: 116)
      • SoftovWD.exe (PID: 3328)
      • node.exe (PID: 3644)
      • IMEKLMG.EXE (PID: 1676)
      • IMEKLMG.EXE (PID: 1200)
      • SoftovWD.exe (PID: 336)
      • node.exe (PID: 2136)
      • wmpnscfg.exe (PID: 2496)
      • wmpnscfg.exe (PID: 2536)
      • node.exe (PID: 2348)
      • UserInteractive.exe (PID: 2844)
    • Manual execution by a user

      • chrome.exe (PID: 1560)
      • IMEKLMG.EXE (PID: 1676)
      • IMEKLMG.EXE (PID: 1200)
      • SoftovWD.exe (PID: 336)
      • wmpnscfg.exe (PID: 2536)
      • SoftovWD.exe (PID: 2696)
      • SoftovWD.exe (PID: 2656)
      • SoftovWD.exe (PID: 2780)
      • wmpnscfg.exe (PID: 2496)
    • Application launched itself

      • chrome.exe (PID: 1560)
      • node.exe (PID: 3436)
      • node.exe (PID: 2136)
    • Process drops legitimate windows executable

      • PSAgentInstaller.tmp (PID: 548)
    • Creates files in the program directory

      • PSAgentInstaller.tmp (PID: 548)
      • node.exe (PID: 3436)
    • Checks operating system version

      • node.exe (PID: 3436)
      • node.exe (PID: 2136)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1512)
      • sipnotify.exe (PID: 1460)
    • Reads the machine GUID from the registry

      • node.exe (PID: 3644)
      • CertMgr.exe (PID: 3304)
      • node.exe (PID: 3436)
      • node.exe (PID: 2136)
      • node.exe (PID: 2348)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 1676)
      • IMEKLMG.EXE (PID: 1200)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.4.203.0
ProductVersionNumber: 3.4.203.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Softov Medical Systems ltd
FileDescription: PSAgent PSAgent - CRT Setup
FileVersion: 3.4.203
LegalCopyright:
ProductName: PSAgent PSAgent - CRT
ProductVersion: 3.4.203
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
44
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start psagentinstaller.exe no specs psagentinstaller.tmp no specs psagentinstaller.exe psagentinstaller.tmp taskkill.exe no specs taskkill.exe no specs cmd.exe no specs schtasks.exe no specs removeprintserver.exe no specs cmd.exe no specs cmd.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs softovwd.exe no specs certmgr.exe no specs node.exe cmd.exe no specs node.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs softovwd.exe no specs node.exe cmd.exe no specs node.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs softovwd.exe no specs softovwd.exe no specs softovwd.exe no specs userinteractive.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\PSAgentInstaller.exe" C:\Users\admin\AppData\Local\Temp\PSAgentInstaller.exeexplorer.exe
User:
admin
Company:
Softov Medical Systems ltd
Integrity Level:
MEDIUM
Description:
PSAgent PSAgent - CRT Setup
Exit code:
0
Version:
3.4.203
Modules
Images
c:\users\admin\appdata\local\temp\psagentinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
336"C:\Program Files\PSAgent\SoftovWD.exe" -v 0 node.exe app.jsC:\Program Files\PSAgent\SoftovWD.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\psagent\softovwd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
532"taskkill.exe" /f /im SoftovWD.exeC:\Windows\System32\taskkill.exePSAgentInstaller.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
548"C:\Users\admin\AppData\Local\Temp\is-7E2VB.tmp\PSAgentInstaller.tmp" /SL5="$601B2,10678126,58368,C:\Users\admin\AppData\Local\Temp\PSAgentInstaller.exe" /SPAWNWND=$401AE /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-7E2VB.tmp\PSAgentInstaller.tmp
PSAgentInstaller.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7e2vb.tmp\psagentinstaller.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
712schtasks /Delete /F /TN printserverC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
884"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3668 --field-trial-handle=1168,i,934747547500745306,10898255014534000771,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
900"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1284 --field-trial-handle=1168,i,934747547500745306,10898255014534000771,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1072"C:\Users\admin\AppData\Local\Temp\is-QD53T.tmp\PSAgentInstaller.tmp" /SL5="$301AA,10678126,58368,C:\Users\admin\AppData\Local\Temp\PSAgentInstaller.exe" C:\Users\admin\AppData\Local\Temp\is-QD53T.tmp\PSAgentInstaller.tmpPSAgentInstaller.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qd53t.tmp\psagentinstaller.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1200"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1116 --field-trial-handle=1168,i,934747547500745306,10898255014534000771,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
8 625
Read events
8 523
Write events
93
Delete events
9

Modification events

(PID) Process:(1784) RemovePrintserver.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1784) RemovePrintserver.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1784) RemovePrintserver.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1784) RemovePrintserver.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(1560) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
Executable files
40
Suspicious files
528
Text files
2 966
Unknown types
0

Dropped files

PID
Process
Filename
Type
548PSAgentInstaller.tmpC:\Program Files\PSAgent\unins000.exeexecutable
MD5:1575D2C0FC36B21767947B4DEC34AEA5
SHA256:710D7CD708018605D4D4B88F886AA379C039B7424417504CA51A18A3283AB0F7
116PSAgentInstaller.exeC:\Users\admin\AppData\Local\Temp\is-QD53T.tmp\PSAgentInstaller.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
548PSAgentInstaller.tmpC:\Program Files\PSAgent\keys\localhost.crttext
MD5:833ED4F31F68649992E61642050D3B16
SHA256:5D892E735CB1D389D4471BDD4561131D66CFD2BAAD4B12C0AB87F5F4E814B2B8
1380PSAgentInstaller.exeC:\Users\admin\AppData\Local\Temp\is-7E2VB.tmp\PSAgentInstaller.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
548PSAgentInstaller.tmpC:\Program Files\PSAgent\is-MKMUL.tmpexecutable
MD5:1575D2C0FC36B21767947B4DEC34AEA5
SHA256:710D7CD708018605D4D4B88F886AA379C039B7424417504CA51A18A3283AB0F7
548PSAgentInstaller.tmpC:\Users\admin\AppData\Local\Temp\is-A61NG.tmpexecutable
MD5:51AE57A591764B5A66D23BAAF77E0738
SHA256:C61F8BC622A70FB3CC4802492251462D2764D7BD6366D5AC49A15F0E2AF0FF0E
548PSAgentInstaller.tmpC:\Users\admin\AppData\Local\Temp\RemovePrintserver.exeexecutable
MD5:51AE57A591764B5A66D23BAAF77E0738
SHA256:C61F8BC622A70FB3CC4802492251462D2764D7BD6366D5AC49A15F0E2AF0FF0E
548PSAgentInstaller.tmpC:\Program Files\PSAgent\keys\is-3Q5EC.tmptext
MD5:776DE191578EECDF2FA1F53457E58DD7
SHA256:93E33D3AB9C482BDF328320E3536CF8184A2020F65071C997072C6D2B69C4DDB
548PSAgentInstaller.tmpC:\Program Files\PSAgent\node_modules\.bin\is-RBE0V.tmptext
MD5:8456BFC29F1721F42722AE7C32561DD4
SHA256:D3345C505CFAA30F5C581416777D3FEA6E2637E50F37F4E0ED7BEE3E3B7ACA57
548PSAgentInstaller.tmpC:\Program Files\PSAgent\node_modules\.bin\rimraf.cmdtext
MD5:2C9E6BF63327CD4D5125ED81486B4B6C
SHA256:62F6D23F78750BE2C02554C749B8BC515E1B33FA358619A5DF0D112672D0F9FB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1460
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133480619888750000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1560
chrome.exe
239.255.255.250:1900
whitelisted
1384
chrome.exe
142.250.184.227:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
1384
chrome.exe
142.250.185.196:443
www.google.com
GOOGLE
US
whitelisted
1384
chrome.exe
142.251.5.84:443
accounts.google.com
GOOGLE
US
unknown
1384
chrome.exe
142.250.185.131:443
www.gstatic.com
GOOGLE
US
whitelisted
1384
chrome.exe
142.250.185.206:443
apis.google.com
GOOGLE
US
whitelisted
1384
chrome.exe
142.250.185.227:443
update.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 142.250.184.227
whitelisted
accounts.google.com
  • 142.251.5.84
shared
www.google.com
  • 142.250.185.196
whitelisted
www.gstatic.com
  • 142.250.185.131
whitelisted
apis.google.com
  • 142.250.185.206
whitelisted
update.googleapis.com
  • 142.250.185.227
whitelisted
qa-new.labos.cloud
  • 104.26.13.155
  • 172.67.73.69
  • 104.26.12.155
unknown
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

No threats detected
No debug info