File name:

Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe

Full analysis: https://app.any.run/tasks/b014cf0b-950e-48ba-a6a2-45d6a0dcd298
Verdict: Malicious activity
Analysis date: November 30, 2024, 02:49:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

8341D046BBBBEDA740F65752E872C5F7

SHA1:

0FBF68275A0B76710EB52540AEBFEFA47212E865

SHA256:

1016D32627683E47EEB585C4E750BF28CFFB1EF2612D0889FE6F27193AB0E0AA

SSDEEP:

98304:9oTVX7YRb00mNQVbhrQzcRXu3RFEhX5kUnxaNznf72sNov+T7gMi6ehKJuBGyVfa:d2TCNUGKENNT68cFm/KWKQxaxH5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
      • ADPClientService.exe (PID: 6736)
      • ADPClientService.exe (PID: 2756)
    • The process drops C-runtime libraries

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
    • Process drops legitimate windows executable

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • AdODIS-installer.exe (PID: 444)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 6392)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 6392)
    • Drops 7-zip archiver for unpacking

      • AdODIS-installer.exe (PID: 444)
    • Application launched itself

      • AdskAccessUIHost.exe (PID: 6988)
    • Starts itself from another location

      • ADPClientService.exe (PID: 6736)
  • INFO

    • Checks supported languages

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
      • DownloadManager.exe (PID: 7112)
      • AdODIS-installer.exe (PID: 444)
    • Create files in a temporary directory

      • Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exe (PID: 6364)
      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
      • DownloadManager.exe (PID: 7112)
      • AdODIS-installer.exe (PID: 444)
    • Reads the computer name

      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
      • DownloadManager.exe (PID: 7112)
      • AdODIS-installer.exe (PID: 444)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 6392)
    • Checks proxy server information

      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
      • DownloadManager.exe (PID: 7112)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 6392)
      • DownloadManager.exe (PID: 6564)
    • Reads the software policy settings

      • Setup.exe (PID: 6392)
    • Reads Environment values

      • AdODIS-installer.exe (PID: 444)
    • Reads CPU info

      • AdODIS-installer.exe (PID: 444)
    • Process checks whether UAC notifications are on

      • AdODIS-installer.exe (PID: 444)
    • Reads the time zone

      • AdODIS-installer.exe (PID: 444)
    • Creates files in the program directory

      • AdODIS-installer.exe (PID: 444)
      • Setup.exe (PID: 6392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:21 17:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 28160
InitializedDataSize: 558592
UninitializedDataSize: -
EntryPoint: 0x7b64
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Autodesk, Inc.
FileDescription: Autodesk Installation Services
FileVersion: 1.0.0.0
InternalName: ODIS Bootstrap
LegalCopyright: © Autodesk 2019
OriginalFileName: Setup.exe
ProductName: Autodesk Installation Services
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
33
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start autodesk_autocad_lt_2024_en-us_setup_webinstall.exe setup.exe downloadmanager.exe conhost.exe no specs downloadmanager.exe conhost.exe no specs adodis-installer.exe installer.exe no specs adpclientservice.exe conhost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adpclientservice.exe conhost.exe no specs downloadmanager.exe no specs conhost.exe no specs processmanager.exe no specs conhost.exe no specs install_manager.exe no specs loganalyzer.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs adpsdkutil.exe no specs conhost.exe no specs autodesk_autocad_lt_2024_en-us_setup_webinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
444"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\AdODIS-installer.exe" --mode unattended --prefix "C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686" --xmlFilePath "C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686" --useService 0C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\AdODIS-installer.exe
Setup.exe
User:
admin
Company:
Autodesk
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\adodis-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1172C:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\AdpSDKUtil.exe command=GetUserID in=C:\Users\admin\AppData\Local\Temp\adp_GetUserID_2756_4704.in out=C:\Users\admin\AppData\Local\Temp\adp_GetUserID_2756_4704.outC:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\AdpSDKUtil.exeADPClientService.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Desktop SDK
Exit code:
0
Version:
4.4.2.0
Modules
Images
c:\users\admin\appdata\roaming\autodesk\adpsdk\bin\adpsdkutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1616\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeADPClientService.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\AdskAccessUIHost.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\UI Launcher" --app-user-model-id="Autodesk Installer" --app-path="C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\resources\app.asar" --no-sandbox --no-zygote --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2552 --field-trial-handle=1736,i,16669113892714509993,12280705191962450063,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\ui-launcher\AdskAccessUIHost.exeAdskAccessUIHost.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Access User Interface
Exit code:
0
Version:
1.0.0.19
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\ui-launcher\adskaccessuihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\ui-launcher\ffmpeg.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2260C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Installer.exe --install_mode install --manifest C:\Autodesk\WI\{4558A64D-DFA2-3773-BF42-92414FF3F3DF}\setup.xml --manifest_xsd C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\SetupRes\manifest.xsd --url_root https://trial2.autodesk.com --installation_id 82508df5-69f8-4a8d-bdf3-5e89907ff8b7 --substype SUS --trial_mode --hide_eula --install_source C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686 --trigger_point web --installer_version 1.44.0.502C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Installer.exeSetup.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Installer
Exit code:
8
Version:
1.44.0.11
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2280\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDownloadManager.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2756C:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\ADPClientService.exeC:\Users\admin\AppData\Roaming\Autodesk\ADPSDK\bin\ADPClientService.exe
ADPClientService.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Analytics Client Service
Version:
4.4.2.0
Modules
Images
c:\users\admin\appdata\roaming\autodesk\adpsdk\bin\adpclientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2800\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAdpSDKUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3508"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\LogAnalyzer.exe"C:\Users\admin\AppData\Local\Temp\odis_download_dest\15945792850613725686\Setup\LogAnalyzer.exeProcessManager.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Installer
Exit code:
0
Version:
1.44.0.11
Modules
Images
c:\users\admin\appdata\local\temp\odis_download_dest\15945792850613725686\setup\loganalyzer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3920\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAdpSDKUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
19 327
Read events
19 289
Write events
20
Delete events
18

Modification events

(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionStartCount
Value:
1
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionCleanCloseCount
Value:
1
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:Uptime
Value:
76B0100000000000
(PID) Process:(6564) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:CalUptime
Value:
079DC50100000000
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionStartCount
Value:
2
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:SessionCleanCloseCount
Value:
2
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:Uptime
Value:
A0ACB90300000000
(PID) Process:(7112) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\1.42.0.6
Operation:writeName:CalUptime
Value:
6461D52A00000000
(PID) Process:(2260) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\core\CER\1.44.0.11
Operation:writeName:SessionStartCount
Value:
1
(PID) Process:(6988) AdskAccessUIHost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
Executable files
166
Suspicious files
237
Text files
129
Unknown types
4

Dropped files

PID
Process
Filename
Type
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\bootstrap.jsonbinary
MD5:04F089DBB1A85CC8CA085C97E9993094
SHA256:9E725F2AC6677806B22AE38DEB24FEA234FADC543C508CF3F81EF0DF99C29FB1
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\odis.bs.win\odis.bs.win.manifesttext
MD5:B131428CEA917BB73CE4DEE4CB5B658D
SHA256:764D9D37DE8E4DE01A4007F563DC8B0D03989A39F9DFE42090652026AA195AC3
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\cs-CZ\senddmp.resources.dllexecutable
MD5:BE8046D3B2BC813D7719FF348805CA12
SHA256:14A286BEF86A01E13FA02C48400A71153A73F62177D17E1A0B1B897B6BB1CBD5
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\cer_core.dllexecutable
MD5:62B9AF4C067115043B687AC5F0852636
SHA256:7DDBD63BE8BF100CD121E534A86E59B75E136580465E6809DBC685900C5DD24E
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\Autodesk_dialog_512x512.pngimage
MD5:36DF17F969396609A4C3B2FDA06C3D76
SHA256:BFF55FCAF87784D76ACF68F10B9D0A13DA938BA2EADEB8A8482FC0A28E618237
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\upiconfig.xmltext
MD5:4044C51DAD7D47C5D7D8B266EDEFDA93
SHA256:FD168E980EF39CFCC3D0937C48039B78AAD8ED4825B06E80A643C0266CEF490D
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\senddmp.exe.configxml
MD5:C64632957C9A46B320E412D857E176C0
SHA256:16A5B2D1D7CC9914BCE73914D4D956D3BA7A2EC34E3D41E876F2E265C15D8096
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\strings.xmlxml
MD5:B89A99DB79F644A690721C11A1274958
SHA256:AE652E226F0D983D0445178DCF8152265426460CABD6CFE49F7D5D9966C24A9B
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\SetupRes\ad.logconfigtext
MD5:50E80477F86AE6C0EC808EA5306305CF
SHA256:5A1086F5F5AB390F98BC8B4F73DFCD71AA4AED22E2E5BF96200F3A7BB618810A
6364Autodesk_AutoCAD_LT_2024_en-US_setup_webinstall.exeC:\Users\admin\AppData\Local\Temp\7z33BE58DC\ODIS\CER\de-DE\senddmp.resources.dllexecutable
MD5:9E996ACD109F741CECED16EB58B187CF
SHA256:DC03F9111B9B8AC01FF499AD04B2AD278018BB1E69D1920EE588AC0773E6DEAF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
112
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6392
Setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAFhuAO9idz6cc%2Bn8%2Bj%2BjJI%3D
unknown
whitelisted
4392
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4392
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1344
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
188
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3976
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
184.30.17.189:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.145
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.110
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.20
whitelisted
trial2.autodesk.com
  • 23.41.253.223
whitelisted
compsvc.delivery.autodesk.com
  • 44.219.39.178
  • 100.25.6.15
  • 34.198.84.90
whitelisted

Threats

No threats detected
No debug info