File name:

DMDE Professional Edition 4.0.0.800 Portable.rar

Full analysis: https://app.any.run/tasks/5157440f-0cdb-4e85-bf9e-62c86857cbdd
Verdict: Malicious activity
Analysis date: January 05, 2026, 13:14:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
upx
delphi
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

654BD7979E69B4982580D2BFC24407C7

SHA1:

342AA1CD427E18B60C1EF822766CF69625096838

SHA256:

13D2427D1896D756AAE854C9449DFD89E494B1B335BA99822199921C5233B13F

SSDEEP:

98304:xdKK5EyVUjpoLZfB/4T/iBKaaKPgq1gk42ZJ/hiHQ1GK2eiUHoDfCRp+s95piSw/:FswS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • dmde.exe (PID: 7352)
      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 6056)
      • dmde.exe (PID: 5492)
      • dmde.exe (PID: 5764)
      • dmde.exe (PID: 7324)
      • dmde.exe (PID: 3136)
      • dmde.exe (PID: 1844)
      • dmde.exe (PID: 7876)
      • dmde.exe (PID: 5900)
      • dmde.exe (PID: 1700)
      • dmde.exe (PID: 3196)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • keygen.exe (PID: 7972)
      • dmde.exe (PID: 5492)
      • dmde.exe (PID: 3196)
    • There is functionality for taking screenshot (YARA)

      • keygen.exe (PID: 7972)
      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 5492)
      • dmde.exe (PID: 7324)
      • dmde.exe (PID: 5900)
      • dmde.exe (PID: 3196)
    • Executable content was dropped or overwritten

      • keygen.exe (PID: 7972)
    • Executes application which crashes

      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 5492)
      • dmde.exe (PID: 1844)
  • INFO

    • Manual execution by a user

      • keygen.exe (PID: 7972)
      • dmde.exe (PID: 7352)
      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 5492)
      • dmde.exe (PID: 6056)
      • dmde.exe (PID: 5764)
      • dmde.exe (PID: 7324)
      • dmde.exe (PID: 3136)
      • dmde.exe (PID: 1844)
      • dmde.exe (PID: 7876)
      • dmde.exe (PID: 5900)
      • dmde.exe (PID: 1700)
      • dmde.exe (PID: 3196)
    • Reads the computer name

      • keygen.exe (PID: 7972)
      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 5492)
      • TextInputHost.exe (PID: 3796)
      • dmde.exe (PID: 7324)
      • dmde.exe (PID: 1844)
      • dmde.exe (PID: 3196)
      • dmde.exe (PID: 5900)
    • The sample compiled with russian language support

      • WinRAR.exe (PID: 7568)
    • Checks supported languages

      • keygen.exe (PID: 7972)
      • dmde.exe (PID: 7336)
      • dmde.exe (PID: 5492)
      • TextInputHost.exe (PID: 3796)
      • dmde.exe (PID: 7324)
      • dmde.exe (PID: 1844)
      • dmde.exe (PID: 5900)
      • dmde.exe (PID: 3196)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7568)
    • Compiled with Borland Delphi (YARA)

      • keygen.exe (PID: 7972)
    • UPX packer has been detected

      • keygen.exe (PID: 7972)
    • Checks proxy server information

      • WerFault.exe (PID: 7776)
      • slui.exe (PID: 4288)
      • WerFault.exe (PID: 2856)
      • WerFault.exe (PID: 2568)
      • WerFault.exe (PID: 4632)
      • WerFault.exe (PID: 7388)
      • WerFault.exe (PID: 4220)
      • dmde.exe (PID: 3196)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7776)
      • WerFault.exe (PID: 2856)
      • WerFault.exe (PID: 2568)
      • WerFault.exe (PID: 4632)
      • WerFault.exe (PID: 4220)
      • WerFault.exe (PID: 7388)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 519088
UncompressedSize: 529408
OperatingSystem: Win32
ArchivedFileName: DMDE Professional Edition 4.0.0.800 Portable/keygen.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
184
Monitored processes
23
Malicious processes
0
Suspicious processes
12

Behavior graph

Click at the process to see the details
start winrar.exe keygen.exe dmde.exe no specs dmde.exe slui.exe werfault.exe werfault.exe dmde.exe no specs dmde.exe textinputhost.exe no specs werfault.exe werfault.exe dmde.exe no specs dmde.exe openwith.exe no specs dmde.exe no specs dmde.exe werfault.exe werfault.exe dmde.exe no specs dmde.exe dmde.exe no specs dmde.exe

Process information

PID
CMD
Path
Indicators
Parent process
1700"C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe" C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exeexplorer.exe
User:
admin
Company:
DMDE Software
Integrity Level:
MEDIUM
Description:
DMDE 4.0.0.800 - Data Recovery Software
Exit code:
3221226540
Version:
4.0.0.800
Modules
Images
c:\users\admin\desktop\dmde professional edition 4.0.0.800 portable\x64\dmde.exe
c:\windows\system32\ntdll.dll
1844"C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe" C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe
explorer.exe
User:
admin
Company:
DMDE Software
Integrity Level:
HIGH
Description:
DMDE 4.0.0.800 - Data Recovery Software
Exit code:
3221226525
Version:
4.0.0.800
Modules
Images
c:\users\admin\desktop\dmde professional edition 4.0.0.800 portable\x64\dmde.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2568C:\WINDOWS\system32\WerFault.exe -u -p 5492 -s 1792C:\Windows\System32\WerFault.exe
dmde.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
2856C:\WINDOWS\system32\WerFault.exe -u -p 5492 -s 1860C:\Windows\System32\WerFault.exe
dmde.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
3136"C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe" C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exeexplorer.exe
User:
admin
Company:
DMDE Software
Integrity Level:
MEDIUM
Description:
DMDE 4.0.0.800 - Data Recovery Software
Exit code:
3221226540
Version:
4.0.0.800
Modules
Images
c:\users\admin\desktop\dmde professional edition 4.0.0.800 portable\x64\dmde.exe
c:\windows\system32\ntdll.dll
3196"C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe" C:\Users\admin\Desktop\DMDE Professional Edition 4.0.0.800 Portable\x64\dmde.exe
explorer.exe
User:
admin
Company:
DMDE Software
Integrity Level:
HIGH
Description:
DMDE 4.0.0.800 - Data Recovery Software
Version:
4.0.0.800
Modules
Images
c:\users\admin\desktop\dmde professional edition 4.0.0.800 portable\x64\dmde.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3796"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
4220C:\WINDOWS\system32\WerFault.exe -u -p 1844 -s 852C:\Windows\System32\WerFault.exe
dmde.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4288C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4632C:\WINDOWS\system32\WerFault.exe -u -p 7336 -s 872C:\Windows\System32\WerFault.exe
dmde.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
47 793
Read events
47 430
Write events
332
Delete events
31

Modification events

(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\DMDE Professional Edition 4.0.0.800 Portable.rar
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7568) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7972) keygen.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(7972) keygen.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0400000013000000030000000000000012000000110000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
Executable files
7
Suspicious files
28
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\keygen.exeexecutable
MD5:0568EB9C946501D350F15EA895EB0EA2
SHA256:E780C26EFBBC1229D4966B110D20749ADAEEDB81A63E6C1C04182CE8FCFED552
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\changelog.txttext
MD5:BDA7630A0A95C3CC257B3D09A67D4E4A
SHA256:2FF63417EAD6DDEB1050E20017C025DCA59E99701E87420B3B350303693FC347
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\deviohsc.txttext
MD5:E31DED4197B39EAA8350B13CF62C08DB
SHA256:524A4AC63C40D18018B3471F6FB163B28E36F6D138B8071D382C7332B1B80755
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\locals\de.lngtext
MD5:AF506CDE306F79BA4EEFFC462FC91A22
SHA256:7CE81742E49DB373AA81B802464DC3FA1B41C4AFEAD428C0662F8B4CB11F3270
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\dev32.dllexecutable
MD5:868DBF6213B2005F35C8BC5AD5067587
SHA256:1185ABB6E6675D600835D430711D125B132210491D189814E9A12A3F29579B29
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\dmde.exeexecutable
MD5:79A9DDA90BE02E8E8CD3C1BD52F4AA77
SHA256:3730342CA4EEC833DE90F555DA31FBF5EAFF888DAEE776CD56C74DA77E50C82E
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\dev9x.dllexecutable
MD5:67758AD9A13DE6A18799919DEC92F2FE
SHA256:02A9290BC89C22840A090AAE3EBCE5FD2D51AEFB67B44888E2EFEF73F47AAAD0
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\dmde.inibinary
MD5:F72E98695BE868FDAF5E4083572982AE
SHA256:EDAB902E8B520C42368A9CC1EC4BB2D30C91A4F648F919B0443FB9EA9727AF31
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\eula.txttext
MD5:25A0EF39438E9F18B819033CCC7A4729
SHA256:BBEA026E7EBAABDFAD3D56A5640558A973EA0A1447D7CE25F20A44A014685133
7568WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7568.3682\DMDE Professional Edition 4.0.0.800 Portable\x32\dmde_en.chmbinary
MD5:90E2D2FB1437CB713A2F7FDB7DC0E941
SHA256:4758ADB959ABC8A0661DD7EDD500F3F2053DB308B330D574A47D3E6FC105D239
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
38
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6900
SIHClient.exe
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6900
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6900
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5464
svchost.exe
POST
200
20.190.160.65:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
404
svchost.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=562&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.48 Kb
whitelisted
5464
svchost.exe
POST
200
20.190.160.65:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
5464
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
404
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5492
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
404
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5464
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5464
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
404
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
404
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.251.208.14
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.133
  • 20.190.160.3
  • 40.126.32.134
  • 20.190.160.4
  • 20.190.160.67
  • 40.126.32.68
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
self.events.data.microsoft.com
  • 51.116.246.106
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info