File name:

e_CONCAR_NET_v12.59_Act64.exe

Full analysis: https://app.any.run/tasks/dfdf5d62-e953-46a0-88a0-22c04e7b3373
Verdict: Malicious activity
Analysis date: June 21, 2024, 22:49:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AC403CD6A679019B7E23EFCFDF2AE424

SHA1:

4BA5EF0D952883DF9DB97DBF5B2F078B89102F82

SHA256:

12CF6724D3833527059B199FC651E26F1101ACF9978889EA8966CB13EFAE85BA

SSDEEP:

98304:YOtcov5+TGBl9e5oFVWtjoe+itgOK56TNww1p2GUftLUaW56o/gGSCPDD03ERn5f:CF3TWTezyGnAc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Drops the executable file immediately after the start

      • dotNetFx45_Full_setup.exe (PID: 3528)
      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
    • Executable content was dropped or overwritten

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
    • Drops 7-zip archiver for unpacking

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Executing commands from a ".bat" file

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Starts CMD.EXE for commands execution

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Reads the Internet Settings

      • Setup.exe (PID: 2432)
  • INFO

    • Checks supported languages

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
      • wmpnscfg.exe (PID: 3080)
    • Create files in a temporary directory

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
    • Reads the computer name

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
      • dotNetFx45_Full_setup.exe (PID: 3528)
      • Setup.exe (PID: 2432)
      • wmpnscfg.exe (PID: 3080)
    • Creates files in the program directory

      • e_CONCAR_NET_v12.59_Act64.exe (PID: 2936)
    • Reads the machine GUID from the registry

      • dotNetFx45_Full_setup.exe (PID: 3528)
    • Reads CPU info

      • Setup.exe (PID: 2432)
    • Application launched itself

      • msedge.exe (PID: 3572)
      • msedge.exe (PID: 2540)
    • Manual execution by a user

      • msedge.exe (PID: 2540)
      • wmpnscfg.exe (PID: 3080)
    • The process uses the downloaded file

      • msedge.exe (PID: 2716)
      • msedge.exe (PID: 3388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (28.3)
.exe | Win32 EXE PECompact compressed (generic) (27.3)
.exe | Win32 Executable MS Visual C++ (generic) (20.5)
.exe | Win64 Executable (generic) (18.1)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:04:24 17:55:34+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 139264
InitializedDataSize: 7516160
UninitializedDataSize: -
EntryPoint: 0x1c888
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.59.0.0
ProductVersionNumber: 12.59.0.0
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: Real Systems S.A.
FileDescription: Concar Electrónico e-CONCAR NET
FileVersion: 12.59
InternalName: E-CONCAR.NET.exe
LegalCopyright: Producto Registrado (R) 1994-2024
LegalTrademarks: Real Systems S.A.
OriginalFileName: install.EXE
PrivateBuild:
ProductName: Concar Electrónico e-CONCAR NET
ProductVersion: 12.59
SpecialBuild:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
30
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start e_concar_net_v12.59_act64.exe cmd.exe no specs dotnetfx45_full_setup.exe setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs e_concar_net_v12.59_act64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2172 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
312"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1252 --field-trial-handle=1360,i,16595124020108094243,1025017388508412380,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1244 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
976"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=4356 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1144"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1524 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1428"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1336 --field-trial-handle=1360,i,16595124020108094243,1025017388508412380,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1600"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4376 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1680"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a79f598,0x6a79f5a8,0x6a79f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2192C:\Windows\system32\cmd.exe /c C:\RSCONCAR\EJECUT~1.BATC:\Windows\System32\cmd.exee_CONCAR_NET_v12.59_Act64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2984 --field-trial-handle=1336,i,11121841484954417966,11542751649105998892,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
14 606
Read events
14 508
Write events
82
Delete events
16

Modification events

(PID) Process:(2936) e_CONCAR_NET_v12.59_Act64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:InstallConstruct
Value:
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3572) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
E016898B047A2F00
(PID) Process:(3572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault
Operation:delete valueName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
Executable files
103
Suspicious files
69
Text files
324
Unknown types
6

Dropped files

PID
Process
Filename
Type
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\ic3E0E.cab
MD5:
SHA256:
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\set6FBF.tmpbinary
MD5:A6F617AA084DF2372253954F0D266290
SHA256:82DA30CD39E28F91AAE90BB74D8ACE30F6460562A086AAAD7385D59D46B0B94A
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-CreditNote-1.0.xsdxml
MD5:D5E21D827E4022EFADE6AD2E918B4C32
SHA256:A2B3B049B70466D37E9F4C2B8591F382DBCE379225941AC92721269F0E5DB0F7
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\CodeList_CurrencyCode_ISO_7_04.xsdxml
MD5:F02DAF9648E9D02E5A3D13AE8C56DF35
SHA256:30743C1FD484C8650450A88717E243365424EEE6024B5C05B3E9F7DD172417FA
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\dotNetFx45_Full_setup.exeexecutable
MD5:9E8253F0A993E53B4809DBD74B335227
SHA256:E434828818F81E6E1F5955E84CAEC08662BD154A80B24A71A2EDA530D8B2F66A
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-Invoice-1.0.xsdxml
MD5:3BA468C9CC903E468A027E67C091BFF7
SHA256:2EAC1EF3D00F8015F57163F8BC616B10A7D7A431C43D7012BCAC8C642433A973
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-DebitNote-1.0.xsdxml
MD5:F9077AEC84F686F49E89A1803476986A
SHA256:2B3D969F4F8F20F497CC3F2A89E0F548294469FB5E1A1329046A17C1600D005F
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\CodeList_LanguageCode_ISO_7_04.xsdxml
MD5:D163E04846D9D2BB57DE13E13D2C91A0
SHA256:42A5FD3EEAE2F19160E1628E12A70A5AF367046A42A407E632292ACD57B6519E
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\UBLPE-VoidedDocuments-1.0.xsdxml
MD5:A7F6C6FAA1361F5C8370728EE414C0CF
SHA256:1C7FA3C49F84AD9C580FD802BF751D562D1CF475F6FCFA73C7DEC4566D550E7A
2936e_CONCAR_NET_v12.59_Act64.exeC:\Users\admin\AppData\Local\Temp\2024-06-21_23-50-08\~ic30\CCTS_CCT_SchemaModule-2.0.xsdxml
MD5:FC244285D6C12A73EB32B63B03477489
SHA256:D5FCF183B62D1E23021F1F62A5B129C9E1EF1FC7C451CF3D2F23E3FE5A8EFBFD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
21
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
104.85.249.161:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
104.85.249.160:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1060
svchost.exe
GET
304
104.85.249.161:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
unknown
unknown
1372
svchost.exe
GET
200
23.36.165.138:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
104.85.249.161:80
ctldl.windowsupdate.com
Akamai International B.V.
PL
unknown
1372
svchost.exe
104.85.249.160:80
ctldl.windowsupdate.com
Akamai International B.V.
PL
unknown
1372
svchost.exe
23.36.165.138:80
www.microsoft.com
Akamai International B.V.
US
unknown
2540
msedge.exe
239.255.255.250:1900
whitelisted
1144
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1144
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 104.85.249.161
  • 104.85.249.160
whitelisted
crl.microsoft.com
  • 104.85.249.160
  • 104.85.249.145
whitelisted
www.microsoft.com
  • 23.36.165.138
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.microsoft.com
  • 104.80.14.54
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
download.microsoft.com
  • 23.36.165.114
whitelisted
www.bing.com
  • 2.18.29.217
  • 2.18.29.168
  • 2.18.29.185
  • 2.18.29.155
  • 2.18.29.218
  • 2.18.29.200
  • 2.18.29.154
  • 2.18.29.171
  • 2.18.29.195
whitelisted

Threats

No threats detected
No debug info