File name:

e_CONCAR_NET_v12.59_Act64.exe

Full analysis: https://app.any.run/tasks/dfdf5d62-e953-46a0-88a0-22c04e7b3373
Verdict: Malicious activity
Analysis date: June 21, 2024, 22:49:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AC403CD6A679019B7E23EFCFDF2AE424

SHA1:

4BA5EF0D952883DF9DB97DBF5B2F078B89102F82

SHA256:

12CF6724D3833527059B199FC651E26F1101ACF9978889EA8966CB13EFAE85BA

SSDEEP:

98304:YOtcov5+TGBl9e5oFVWtjoe+itgOK56TNww1p2GUftLUaW56o/gGSCPDD03ERn5f:CF3TWTezyGnAc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • dotNetFx45_Full_setup.exe (PID: 3528)
      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Creates a writable file in the system directory

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Process drops legitimate windows executable

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
    • Starts CMD.EXE for commands execution

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Executable content was dropped or overwritten

      • dotNetFx45_Full_setup.exe (PID: 3528)
      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Executing commands from a ".bat" file

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Reads the Internet Settings

      • Setup.exe (PID: 2432)
  • INFO

    • Checks supported languages

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
      • wmpnscfg.exe (PID: 3080)
    • Creates files in the program directory

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Reads the computer name

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
      • wmpnscfg.exe (PID: 3080)
    • Create files in a temporary directory

      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Reads CPU info

      • Setup.exe (PID: 2432)
    • Manual execution by a user

      • msedge.exe (PID: 2540)
      • wmpnscfg.exe (PID: 3080)
    • The process uses the downloaded file

      • msedge.exe (PID: 3388)
      • msedge.exe (PID: 2716)
    • Application launched itself

      • msedge.exe (PID: 3572)
      • msedge.exe (PID: 2540)
    • Reads the machine GUID from the registry

      • dotNetFx45_Full_setup.exe (PID: 3528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (28.3)
.exe | Win32 EXE PECompact compressed (generic) (27.3)
.exe | Win32 Executable MS Visual C++ (generic) (20.5)
.exe | Win64 Executable (generic) (18.1)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:04:24 17:55:34+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 139264
InitializedDataSize: 7516160
UninitializedDataSize: -
EntryPoint: 0x1c888
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.59.0.0
ProductVersionNumber: 12.59.0.0
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: Real Systems S.A.
FileDescription: Concar Electrónico e-CONCAR NET
FileVersion: 12.59
InternalName: E-CONCAR.NET.exe
LegalCopyright: Producto Registrado (R) 1994-2024
LegalTrademarks: Real Systems S.A.
OriginalFileName: install.EXE
PrivateBuild:
ProductName: Concar Electrónico e-CONCAR NET
ProductVersion: 12.59
SpecialBuild:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
30
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start e_concar_net_v12.59_act64.exe cmd.exe no specs dotnetfx45_full_setup.exe setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs e_concar_net_v12.59_act64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2172 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
312"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1252 --field-trial-handle=1360,i,16595124020108094243,1025017388508412380,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1244 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
976"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=4356 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1144"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1524 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1428"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1336 --field-trial-handle=1360,i,16595124020108094243,1025017388508412380,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1600"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4376 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1680"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a79f598,0x6a79f5a8,0x6a79f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2192C:\Windows\system32\cmd.exe /c C:\RSCONCAR\EJECUT~1.BATC:\Windows\System32\cmd.exee_CONCAR_NET_v12.59_Act64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2984 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
14 606
Read events
14 508
Write events
82
Delete events
16

Modification events

(PID) Process:(2936) e_CONCAR_NET_v12.59_Act64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:InstallConstruct
Value:
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
E016898B047A2F00
(PID) Process:(3572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault
Operation:delete valueName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
Executable files
103
Suspicious files
69
Text files
324
Unknown types
6

Dropped files

PID
Process
Filename
Type
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\ic3E0E.cab
MD5:
SHA256:
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\inFD86.datcompressed
MD5:A6A29FC3D57168CF82DF20CCA53C61FC
SHA256:6E858FA63ADFEBA1B7BE047DC99E76B510867918D79B54FC632CB8545B607789
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\set6FBF.tmpbinary
MD5:A6F617AA084DF2372253954F0D266290
SHA256:82DA30CD39E28F91AAE90BB74D8ACE30F6460562A086AAAD7385D59D46B0B94A
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\CodeList_CurrencyCode_ISO_7_04.xsdxml
MD5:F02DAF9648E9D02E5A3D13AE8C56DF35
SHA256:30743C1FD484C8650450A88717E243365424EEE6024B5C05B3E9F7DD172417FA
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-Invoice-1.0.xsdxml
MD5:3BA468C9CC903E468A027E67C091BFF7
SHA256:2EAC1EF3D00F8015F57163F8BC616B10A7D7A431C43D7012BCAC8C642433A973
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-CreditNote-1.0.xsdxml
MD5:D5E21D827E4022EFADE6AD2E918B4C32
SHA256:A2B3B049B70466D37E9F4C2B8591F382DBCE379225941AC92721269F0E5DB0F7
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-DebitNote-1.0.xsdxml
MD5:F9077AEC84F686F49E89A1803476986A
SHA256:2B3D969F4F8F20F497CC3F2A89E0F548294469FB5E1A1329046A17C1600D005F
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\CodeList_UnitCode_UNECE_7_04.xsdxml
MD5:4C3F4973BDD83300689B2209174E437C
SHA256:DD38AFEE99A3070BD4E6A26B6DC4DB396FE36592D219F4A45CF8257E8EDEAD67
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBL-CommonAggregateComponents-2.0.xsdxml
MD5:EDE770ED6CEEA6D3A10F31213A37EB3E
SHA256:018F2DDF065A02E365C4A4B1CA5D8BC2A377788FD73DDBCBF13B8ED91495D467
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBL-ExtensionContentDatatype-2.0.xsdxml
MD5:244AF9DF364739E8BBCB031B060A35B6
SHA256:B44A8B095F66BA08F3E01A4148785F981FE13891A4D9CC16732D139D8E2603F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
21
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
104.85.249.161:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
PL
unknown
1372
svchost.exe
GET
200
23.36.165.138:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
973 b
unknown
1372
svchost.exe
GET
200
104.85.249.160:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
PL
binary
1.01 Kb
unknown
1060
svchost.exe
GET
304
104.85.249.161:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
PL
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
104.85.249.161:80
ctldl.windowsupdate.com
Akamai International B.V.
PL
unknown
1372
svchost.exe
104.85.249.160:80
ctldl.windowsupdate.com
Akamai International B.V.
PL
unknown
1372
svchost.exe
23.36.165.138:80
www.microsoft.com
Akamai International B.V.
US
unknown
2540
msedge.exe
239.255.255.250:1900
whitelisted
1144
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1144
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 104.85.249.161
  • 104.85.249.160
whitelisted
crl.microsoft.com
  • 104.85.249.160
  • 104.85.249.145
whitelisted
www.microsoft.com
  • 23.36.165.138
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.microsoft.com
  • 104.80.14.54
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
download.microsoft.com
  • 23.36.165.114
whitelisted
www.bing.com
  • 2.18.29.217
  • 2.18.29.168
  • 2.18.29.185
  • 2.18.29.155
  • 2.18.29.218
  • 2.18.29.200
  • 2.18.29.154
  • 2.18.29.171
  • 2.18.29.195
whitelisted

Threats

No threats detected
No debug info