File name:

Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe

Full analysis: https://app.any.run/tasks/b014cf0b-950e-48ba-a6a2-45d6a0dcd298
Verdict: Malicious activity
Analysis date: November 30, 2024, 02:49:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

8341D046BBBBEDA740F65752E872C5F7

SHA1:

0FBF68275A0B76710EB52540AEBFEFA47212E865

SHA256:

1016D32627683E47EEB585C4E750BF28CFFB1EF2612D0889FE6F27193AB0E0AA

SSDEEP:

98304:9oTVX7YRb00mNQVbhrQzcRXu3RFEhX5kUnxaNznf72sNov+T7gMi6ehKJuBGyVfa:d2TCNUGKENNT68cFm/KWKQxaxH5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
      • ADPClientService.exe (PID: 6736)
      • ADPClientService.exe (PID: 2756)
    • The process drops C-runtime libraries

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
    • Process drops legitimate windows executable

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 6392)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 6392)
    • Drops 7-zip archiver for unpacking

      • AdODIS-installer.exe (PID: 444)
    • Application launched itself

      • AdskAccessUIHost.exe (PID: 6988)
    • Starts itself from another location

      • ADPClientService.exe (PID: 6736)
  • INFO

    • Create files in a temporary directory

      • Setup.exe (PID: 6392)
      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • DownloadManager.exe (PID: 6564)
      • DownloadManager.exe (PID: 7112)
      • AdODIS-installer.exe (PID: 444)
    • Creates files or folders in the user directory

      • DownloadManager.exe (PID: 6564)
      • Setup.exe (PID: 6392)
    • Checks supported languages

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
      • AdODIS-installer.exe (PID: 444)
      • DownloadManager.exe (PID: 7112)
    • Reads the computer name

      • DownloadManager.exe (PID: 6564)
      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 7112)
      • AdODIS-installer.exe (PID: 444)
    • Checks proxy server information

      • DownloadManager.exe (PID: 6564)
      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 7112)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 6392)
    • Creates files in the program directory

      • Setup.exe (PID: 6392)
      • AdODIS-installer.exe (PID: 444)
    • Reads the software policy settings

      • Setup.exe (PID: 6392)
    • Reads CPU info

      • AdODIS-installer.exe (PID: 444)
    • Reads the time zone

      • AdODIS-installer.exe (PID: 444)
    • Reads Environment values

      • AdODIS-installer.exe (PID: 444)
    • Process checks whether UAC notifications are on

      • AdODIS-installer.exe (PID: 444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:21 17:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 28160
InitializedDataSize: 558592
UninitializedDataSize: -
EntryPoint: 0x7b64
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Autodesk, Inc.
FileDescription: Autodesk Installation Services
FileVersion: 1.0.0.0
InternalName: ODIS Bootstrap
LegalCopyright: © Autodesk 2019
OriginalFileName: Setup.exe
ProductName: Autodesk Installation Services
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
33
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start autodesk_autocad_lt_2024_en-us_setup_webinstall.exe setup.exe downloadmanager.exe conhost.exe no specs downloadmanager.exe conhost.exe no specs adodis-installer.exe installer.exe no specs adpclientservice.exe conhost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adpclientservice.exe conhost.exe no specs downloadmanager.exe no specs conhost.exe no specs processmanager.exe no specs conhost.exe no specs install_manager.exe no specs loganalyzer.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs autodesk_autocad_lt_2024_en-us_setup_webinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
444"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\AdODIS-installer.exe" --mode unattended --prefix "C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686" --xmlFilePath "C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686" --useService 0C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\AdODIS-installer.exe
Setup.exe
User:
admin
Company:
Autodesk
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\adodis-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1172C:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\AdpSDKUtil.exe command=GetUserID in=C:\Users\admin\AppData\Local\Temp\adp_GetUserID_2756_4704.in out=C:\Users\admin\AppData\Local\Temp\adp_GetUserID_2756_4704.outC:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\AdpSDKUtil.exeADPClientService.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Desktop SDK
Exit code:
0
Version:
4.4.2.0
Modules
Images
c:\users\admin\appdata\roaming\autodesk\adpsdk\bin\adpsdkutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1616\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeADPClientService.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\AdskAccessUIHost.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\UI Launcher" --app-user-model-id="Autodesk Installer" --app-path="C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\resources\app.asar" --no-sandbox --no-zygote --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2552 --field-trial-handle=1736,i,16669113892714509993,12280705191962450063,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\AdskAccessUIHost.exeAdskAccessUIHost.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Access User Interface
Exit code:
0
Version:
1.0.0.19
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\ui-launcher\adskaccessuihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\ui-launcher\ffmpeg.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2260C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Installer.exe --install_mode install --manifest C:\Autodesk\WI\{4558A64D-DFA2-3773-BF42-92414FF3F3DF}\setup.xml --manifest_xsd C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\SetupRes\manifest.xsd --url_root https://trial2.autodesk.com --installation_id 82508df5-69f8-4a8d-bdf3-5e89907ff8b7 --substype SUS --trial_mode --hide_eula --install_source C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686 --trigger_point web --installer_version 1.44.0.502C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Installer.exeSetup.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Installer
Exit code:
8
Version:
1.44.0.11
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2280\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDownloadManager.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2756C:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\ADPClientService.exeC:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\ADPClientService.exe
ADPClientService.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Analytics Client Service
Version:
4.4.2.0
Modules
Images
c:\users\admin\appdata\roaming\autodesk\adpsdk\bin\adpclientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2800\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAdpSDKUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3508"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\LogAnalyzer.exe"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\LogAnalyzer.exeProcessManager.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Installer
Exit code:
0
Version:
1.44.0.11
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\loganalyzer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3920\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAdpSDKUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
19 327
Read events
19 289
Write events
20
Delete events
18

Modification events

(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionStartCount
Value:
1
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionCleanCloseCount
Value:
1
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:Uptime
Value:
76B0100000000000
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:CalUptime
Value:
079DC50100000000
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionStartCount
Value:
2
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionCleanCloseCount
Value:
2
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:Uptime
Value:
A0ACB90300000000
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:CalUptime
Value:
6461D52A00000000
(PID) Process:(2260) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\core\CER\1.44.0.11
Operation:writeName:SessionStartCount
Value:
1
(PID) Process:(6988) AdskAccessUIHost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
Executable files
166
Suspicious files
237
Text files
129
Unknown types
4

Dropped files

PID
Process
Filename
Type
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\senddmp.exe.configxml
MD5:C64632957C9A46B320E412D857E176C0
SHA256:16A5B2D1D7CC9914BCE73914D4D956D3BA7A2EC34E3D41E876F2E265C15D8096
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\odis.bs.wx\odis.bs.wx.manifesttext
MD5:A0D321519E9033FF86F801C697E98F65
SHA256:4A838B3F4655290A5B36D80479CE8D7E483BD29DD03AEC8D03944FCEA68F560C
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\SetupRes\add.logconfigtext
MD5:7277BAD79C54DD9AEF4588A1DCF6DD5E
SHA256:1A584768CE704C99529F839EE4B7911F181D47CA5082DAD7CB5F8322EFBD619E
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\ko-KR\senddmp.resources.dllexecutable
MD5:62D2A182BFBDD9C6553153FC33CD3409
SHA256:D14D8B23475C02A6A728ABA0E2BB9FCF4A57335486D25A7A767F3133BE22FC0C
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\bootstrap.jsonbinary
MD5:04F089DBB1A85CC8CA085C97E9993094
SHA256:9E725F2AC6677806B22AE38DEB24FEA234FADC543C508CF3F81EF0DF99C29FB1
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\de-DE\senddmp.resources.dllexecutable
MD5:9E996ACD109F741CECED16EB58B187CF
SHA256:DC03F9111B9B8AC01FF499AD04B2AD278018BB1E69D1920EE588AC0773E6DEAF
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\SetupRes\ad.logconfigtext
MD5:50E80477F86AE6C0EC808EA5306305CF
SHA256:5A1086F5F5AB390F98BC8B4F73DFCD71AA4AED22E2E5BF96200F3A7BB618810A
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\odis.bs.win\odis.bs.win.manifesttext
MD5:B131428CEA917BB73CE4DEE4CB5B658D
SHA256:764D9D37DE8E4DE01A4007F563DC8B0D03989A39F9DFE42090652026AA195AC3
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\ja-JP\senddmp.resources.dllexecutable
MD5:EEE7FDB04F4D5AD9ADB1991E202441A0
SHA256:66C4C040505C1C3B1EDB6C5C61363EAFD9CF378C58F3D57A367EDEEE1E24D89F
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\en-US\senddmp.resources.dllexecutable
MD5:751D2EF3B937E826E2DEE0AC7185E328
SHA256:AD643DBFC14FB7504F9A06F700FBA656F00DD6F75CC42DB56B8C58367C0FEBCF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
112
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAFhuAO9idz6cc%2Bn8%2Bj%2BjJI%3D
unknown
whitelisted
4392
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4392
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1344
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAMAeNEyEUtosA1ynBJKgZI%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
188
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3976
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
184.30.17.189:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.145
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.110
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.20
whitelisted
trial2.autodesk.com
  • 23.41.253.223
whitelisted
compsvc.delivery.autodesk.com
  • 44.219.39.178
  • 100.25.6.15
  • 34.198.84.90
whitelisted

Threats

No threats detected
No debug info