File name:

b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.zip

Full analysis: https://app.any.run/tasks/4df1e9f9-1427-471b-a78e-260871562c02
Verdict: Malicious activity
Analysis date: May 18, 2025, 04:16:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

6A01D2D659605D3E3DD7711F065422AB

SHA1:

AAA100E12EE120AA40591F51BC0E353AB173A6D5

SHA256:

18FB7D109B28D9CD62625915FB630E495A289E0ED7877EB14DEF6A1D76129A22

SSDEEP:

98304:Z0ludlFzkF0UjLg1x4eskjFhOPXulghZ7fXQfPT30mli4ZEZlJPGlJMOwxIDFKLK:1k5y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Creates a software uninstall entry

      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Executable content was dropped or overwritten

      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 7316)
      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Reads the software policy settings

      • FirefoxAutocompleteSpy.exe (PID: 2136)
      • slui.exe (PID: 7484)
    • Application launched itself

      • firefox.exe (PID: 4408)
      • firefox.exe (PID: 1324)
    • Creates files in the program directory

      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Checks supported languages

      • FirefoxAutocompleteSpy.exe (PID: 2136)
      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Reads the computer name

      • FirefoxAutocompleteSpy.exe (PID: 2136)
      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7316)
    • Manual execution by a user

      • firefox.exe (PID: 4408)
      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
    • Create files in a temporary directory

      • b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe (PID: 8008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0003
ZipCompression: Unknown (99)
ZipModifyDate: 2025:05:18 04:16:44
ZipCRC: 0xef7f17ab
ZipCompressedSize: 1883199
ZipUncompressedSize: 1994051
ZipFileName: b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
18
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe firefoxautocompletespy.exe slui.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1324"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1660C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2092"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4948 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4988 -prefMapHandle 4984 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c3b979ab-8f23-4106-b59f-4eb1e0d67ecc} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0d4246510 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
2136"C:\Program Files (x86)\SecurityXploded\FirefoxAutocompleteSpy\FirefoxAutocompleteSpy.exe"C:\Program Files (x86)\SecurityXploded\FirefoxAutocompleteSpy\FirefoxAutocompleteSpy.exe
b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exe
User:
admin
Integrity Level:
HIGH
Description:
Free Firefox Autocomplete Data Viewer Software
Exit code:
2
Version:
1.0.0.0
Modules
Images
c:\program files (x86)\securityxploded\firefoxautocompletespy\firefoxautocompletespy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3784"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5048 -childID 4 -isForBrowser -prefsHandle 5132 -prefMapHandle 5136 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1544 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {95de8a3b-7231-42a1-83fe-d5e2fb6f084b} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0d5990150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
4208"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5096 -childID 3 -isForBrowser -prefsHandle 5064 -prefMapHandle 5000 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1544 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {468e8fa1-5bb8-4fe8-98a5-1140c910130d} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0d5049f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
4408"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\crypt32.dll
5428"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5316 -childID 5 -isForBrowser -prefsHandle 5236 -prefMapHandle 5240 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1544 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a8cde854-c5b5-40e3-9f0c-ae8738fd63c2} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0d5990310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6132"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2152 -parentBuildID 20240213221259 -prefsHandle 2144 -prefMapHandle 2140 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ff0abb53-eb55-4e0f-a793-a31710d2096c} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0beb7f910 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
6156"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1912 -parentBuildID 20240213221259 -prefsHandle 1840 -prefMapHandle 1812 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {796c17d8-2684-4039-aa0e-66cc91b6afbd} 1324 "\\.\pipe\gecko-crash-server-pipe.1324" 1f0cb9ebe10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
Total events
15 598
Read events
15 566
Write events
19
Delete events
13

Modification events

(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:13
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:12
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:11
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:10
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:9
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:8
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:7
Value:
(PID) Process:(7316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:6
Value:
Executable files
4
Suspicious files
180
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
1324firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Users\admin\AppData\Local\Temp\nseF32D.tmp\leftimg.bmpimage
MD5:FED15D24B58084083108467F74594FB0
SHA256:6F9036B61578860DEF95C555ED0250E9AFA12655DD84BAAC3A58E1A8CD8AB78E
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Users\admin\AppData\Local\Temp\nseF32D.tmp\header.bmpimage
MD5:A82F1ACE111DCED1899E650296E8D571
SHA256:03EC932149A3F3FE2DFE790B572CDE4C545ABC7EA23CA92F8A02D8E513FC9096
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Users\admin\AppData\Local\Temp\nseF32D.tmp\btmimg.bmpimage
MD5:8FD1DA0AA89C6DB3D490726A4339C4E2
SHA256:CA4891E11CB210032A990310F2CD35E55A2BA348AA9AFBBF18FC7B8446E37ED3
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Users\admin\AppData\Local\Temp\nseF32D.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Program Files (x86)\SecurityXploded\FirefoxAutocompleteSpy\FirefoxAutocompleteSpy.exeexecutable
MD5:83A4F5C6C67188588241D1F774CE568D
SHA256:1F4FA7374CFC4AD4A02ADC78953D03AF1DD3C69CB15358D55DF23B80DA2DE7B1
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Users\admin\AppData\Local\Temp\nseF32D.tmp\isWelcome.inibinary
MD5:9D2BD569029F8C546EBF966AF44C54D2
SHA256:DA42F25D2438686218F67EAA50325FC6FD4384D32A34A81E348F07BC10CD2542
1324firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Program Files (x86)\SecurityXploded\FirefoxAutocompleteSpy\Readme.htmlhtml
MD5:4C71DC4EFD724C9B8CEAAAE69BBE44F2
SHA256:6D3AF812E601D2645E3B12021C15F5CA30B3B46993E968B5C3ED3516399DB226
8008b1e033a7c2262966923da22894828a9941a7affaf15ba5cd3ffc154c0f584d38.exeC:\Program Files (x86)\SecurityXploded\FirefoxAutocompleteSpy\SecurityXploded_License.rtftext
MD5:316CC59FE8FAD0FF382DE96ACDAB2894
SHA256:4CC7B7DC863DA1DFAF197BF4198518C9FBDB088D6DE7790793F7715772A8A890
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
100
DNS requests
108
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
896
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
896
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1324
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
1324
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
2136
FirefoxAutocompleteSpy.exe
GET
301
104.26.14.162:80
http://www.securityxploded.com/product_versions.xml
unknown
whitelisted
1324
firefox.exe
POST
200
184.24.77.79:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
896
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 23.35.229.160
whitelisted
google.com
  • 172.217.16.206
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.64
  • 40.126.31.69
  • 40.126.31.129
  • 20.190.159.130
  • 40.126.31.3
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
www.securityxploded.com
  • 104.26.14.162
  • 104.26.15.162
  • 172.67.68.59
  • 2606:4700:20::681a:ea2
  • 2606:4700:20::ac43:443b
  • 2606:4700:20::681a:fa2
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info