File name:

OfficeSetup.exe

Full analysis: https://app.any.run/tasks/343d9071-6686-416a-9fee-10b11af6c1a6
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:48:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

07E466E6FA4D2BEC8FD118B1CA90D8DB

SHA1:

F8EA01D80B7E4CA925B55D419372E3D31FAF62CD

SHA256:

19378D348529E8DFE298266A2179B0F90B8F77AFB3AA62BDF27961775D7945C9

SSDEEP:

98304:cAaq0sIWeyOyTyXOsTgOi+QwyDMI+KJEj/nh5eyX+4Ht1PuLIH9EBiqG97dcqnss:e26Bt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • OfficeSetup.exe (PID: 6916)
      • OfficeSetup.exe (PID: 7600)
      • OfficeC2RClient.exe (PID: 8744)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • OfficeSetup.exe (PID: 4288)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
    • Application launched itself

      • OfficeSetup.exe (PID: 4288)
      • OfficeSetup.exe (PID: 7600)
    • Starts a Microsoft application from unusual location

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 4288)
      • OfficeSetup.exe (PID: 6916)
    • Reads security settings of Internet Explorer

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeC2RClient.exe (PID: 8744)
    • Reads the date of Windows installation

      • OfficeSetup.exe (PID: 7600)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
    • Searches for installed software

      • OfficeSetup.exe (PID: 6916)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 5484)
  • INFO

    • Checks supported languages

      • OfficeSetup.exe (PID: 4288)
      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
    • Reads the machine GUID from the registry

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
      • OfficeClickToRun.exe (PID: 8932)
    • Reads the computer name

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
    • Process checks whether UAC notifications are on

      • OfficeSetup.exe (PID: 7600)
    • Checks proxy server information

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • BackgroundTransferHost.exe (PID: 8924)
      • OfficeClickToRun.exe (PID: 2648)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
      • slui.exe (PID: 3992)
    • Reads Microsoft Office registry keys

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
    • Process checks computer location settings

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeC2RClient.exe (PID: 8744)
    • Reads the software policy settings

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • BackgroundTransferHost.exe (PID: 8924)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeClickToRun.exe (PID: 2648)
      • slui.exe (PID: 3992)
    • Creates files or folders in the user directory

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 5484)
      • BackgroundTransferHost.exe (PID: 8924)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
    • Reads CPU info

      • OfficeSetup.exe (PID: 7600)
      • OfficeSetup.exe (PID: 6916)
    • Reads Environment values

      • OfficeSetup.exe (PID: 6916)
      • OfficeSetup.exe (PID: 7600)
      • OfficeC2RClient.exe (PID: 8744)
    • Create files in a temporary directory

      • OfficeSetup.exe (PID: 7600)
      • OfficeClickToRun.exe (PID: 5484)
      • OfficeSetup.exe (PID: 6916)
      • OfficeClickToRun.exe (PID: 8932)
      • OfficeC2RClient.exe (PID: 8744)
    • The sample compiled with arabic language support

      • OfficeClickToRun.exe (PID: 5484)
    • Creates files in the program directory

      • OfficeClickToRun.exe (PID: 5484)
      • OfficeClickToRun.exe (PID: 2648)
    • The sample compiled with czech language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with bulgarian language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with german language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with english language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with spanish language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with french language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with japanese language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with Indonesian language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with portuguese language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with korean language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with polish language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with russian language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with swedish language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with turkish language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with Italian language support

      • OfficeClickToRun.exe (PID: 5484)
    • The sample compiled with slovak language support

      • OfficeClickToRun.exe (PID: 5484)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8716)
      • BackgroundTransferHost.exe (PID: 9108)
      • BackgroundTransferHost.exe (PID: 4432)
      • BackgroundTransferHost.exe (PID: 8924)
      • BackgroundTransferHost.exe (PID: 8768)
    • The sample compiled with chinese language support

      • OfficeClickToRun.exe (PID: 5484)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 2648)
    • Manual execution by a user

      • OfficeC2RClient.exe (PID: 8744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:09:28 22:59:30+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.42
CodeSize: 4768256
InitializedDataSize: 2723840
UninitializedDataSize: -
EntryPoint: 0x415e86
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.19231.20156
ProductVersionNumber: 16.0.19231.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.19231.20156
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.19231.20156
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
187
Monitored processes
14
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start officesetup.exe no specs officesetup.exe officesetup.exe officeclicktorun.exe Delivery Optimization User no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs officeclicktorun.exe officeclicktorun.exe slui.exe officec2rclient.exe

Process information

PID
CMD
Path
Indicators
Parent process
2504C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2648"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.19231.20138
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
3992C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4288"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" C:\Users\admin\AppData\Local\Temp\OfficeSetup.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4432"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
5484OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=O365ProPlusRetail.16_en-us_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.19231.20156 mediatype=CDN sourcetype=CDN O365ProPlusRetail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6916"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7600OfficeSetup.exe RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
8716"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8744"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /progressandlaunch AppTargets="root\office16\excel.exe|root\office16\lync.exe|root\office16\msaccess.exe|root\office16\mspub.exe|root\office16\onenote.exe|root\office16\outlook.exe|root\office16\powerpnt.exe|root\office16\winword.exe" ManualUpgrade=False ScenarioToTrack="Scenario:{477E0208-58BD-4F33-978A-09BCC9AA9EB1}@INSTALL"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office Click-to-Run Client
Version:
16.0.19231.20156
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
96 262
Read events
95 667
Write events
371
Delete events
224

Modification events

(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
1
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe\ULSMonitor
Operation:delete keyName:(default)
Value:
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe\ULSMonitor
Operation:writeName:ULSTagIds0
Value:
41816131,5804129,577889346,7202269,39389248,17102418,24262478,41484365,595174594,3700754,593359442,17110988,17962391,17962392,17110992,20502174,3702920,3462423,3965062,24262474,4297094,7153421,24262473,18716193,7153487,7153435,7202265,24262477,6308191,18407617,51475283,9179410,3462365,6104718,9179409,9179411,41185282,39125643,539756558,539756557,528570079
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officesetup.exe\ULSMonitor
Operation:writeName:ULSCategoriesSeverities
Value:
942 6,1329 10,944 15,1329 50,940 10,941 10,942 10,943 10,1329 15,944 10,940 15,944 50,940 6,941 15,940 100,942 15,943 15,940 50,944 6,1329 6,1329 100,943 6,941 6,944 100
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6916) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
409
Suspicious files
408
Text files
593
Unknown types
0

Dropped files

PID
Process
Filename
Type
7600OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-walbinary
MD5:4D4275B012C5D1E5976E8CCA8F57B178
SHA256:102AEE8E4681D917B5750B1DA3951B0873C7679EE1E015DE8E0DE0C61F8B12AC
7600OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-shmbinary
MD5:7083570CE7E8175D6947D9394243DD94
SHA256:65A0E74BDB5052B84D7CA91072A7F7204A1B09285A9C7B0CA755110FC85F9388
7600OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:671A2E77E489DCABFCFF2C7673B8E229
SHA256:B4B486BA02252846E86E50E74210BB364426882F48A57B57C5A92F1DAEB4F69B
6916OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF8C124EF-26E4-49BB-91A3-937DC1852238OfficeC2R44909AD7-746A-459F-BC54-0014643C8F3D\VersionDescriptor.xmlxml
MD5:984B6A77C2EAD033A8BADDE1D5DC3EC0
SHA256:1E8A1F9FECAAF4971C84049F6DDF83A8385CE132D26EC72EB468DF6D62EDE268
5484OfficeClickToRun.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD-20251003-1748.logtext
MD5:2A3A986CE3134EC3DCA1AB289C896381
SHA256:39480742AECF67B47D08B0BF3D94A1151F8895EC51FD0DDA92343F80FA469722
7600OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D839591C-BBFE-47C3-B6A7-B17B5B1E29E3xml
MD5:1800690F301C421E4163024643FBA398
SHA256:53D45D40DD7140F5B0CC94C1B87ED3256A66473111A00687EF43CB749DBA4DE2
6916OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A583E2A51BFBDC1E492A57B7C8325850
MD5:9A6C3A86296BEC3070824451A699B6E5
SHA256:99E4AB8CC1CD4F8F371416A6D676AF04A864ED1BC7A7E48BA0CD40C1745FC2D6
7600OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:102011AD0AB63AA6EA54B08189CADDC3
SHA256:757E49A25D42B7F5941CAA283753CEA811C1E5689F13D87B8644A63C1DB5F169
6916OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF8C124EF-26E4-49BB-91A3-937DC1852238\VersionDescriptor.xmlxml
MD5:984B6A77C2EAD033A8BADDE1D5DC3EC0
SHA256:1E8A1F9FECAAF4971C84049F6DDF83A8385CE132D26EC72EB468DF6D62EDE268
6916OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF8C124EF-26E4-49BB-91A3-937DC1852238OfficeC2R44909AD7-746A-459F-BC54-0014643C8F3D\v64.hashtext
MD5:7DA66D33B4E1CA389229386CDD1DDDDA
SHA256:03390EEEAB0890A385528F125533CC67A61719C21F4AC1A131BEAE7653A9ADA0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
279
TCP/UDP connections
270
DNS requests
162
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6916
OfficeSetup.exe
HEAD
200
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.16026.20146.cab
AT
whitelisted
6916
OfficeSetup.exe
HEAD
200
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
5944
svchost.exe
GET
206
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
binary
1 b
whitelisted
5944
svchost.exe
HEAD
200
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
6916
OfficeSetup.exe
GET
200
23.216.77.32:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
DE
824 b
whitelisted
7600
OfficeSetup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
US
binary
471 b
whitelisted
6916
OfficeSetup.exe
HEAD
200
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
5944
svchost.exe
HEAD
200
2.16.10.75:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
binary
1 b
whitelisted
6916
OfficeSetup.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crl
DE
binary
781 b
whitelisted
5424
svchost.exe
GET
206
199.232.214.172:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.19231.20156/i640.cab
US
text
2 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
8108
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
92.123.104.26:443
www.bing.com
Akamai International B.V.
DE
whitelisted
7600
OfficeSetup.exe
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7600
OfficeSetup.exe
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4192
svchost.exe
239.255.255.250:1900
whitelisted
6916
OfficeSetup.exe
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6916
OfficeSetup.exe
52.110.17.44:443
mrodevicemgr.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 92.123.104.26
  • 92.123.104.33
  • 92.123.104.18
  • 92.123.104.35
  • 92.123.104.20
  • 92.123.104.24
  • 92.123.104.34
  • 92.123.104.22
  • 92.123.104.32
  • 92.123.104.45
  • 92.123.104.37
  • 92.123.104.36
  • 92.123.104.47
  • 92.123.104.50
  • 92.123.104.42
  • 92.123.104.38
  • 92.123.104.46
  • 92.123.104.51
whitelisted
google.com
  • 142.250.186.78
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.110.17.44
  • 52.110.17.51
  • 52.110.17.26
  • 52.110.17.42
  • 52.110.17.48
  • 52.110.17.49
  • 52.110.17.70
  • 52.110.17.19
whitelisted
f.c2r.ts.cdn.office.net
  • 2.16.10.75
  • 2.16.10.90
  • 2.16.10.72
  • 199.232.214.172
  • 199.232.210.172
whitelisted
mobile.events.data.microsoft.com
  • 20.189.173.14
  • 20.42.73.31
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.216.77.32
  • 23.216.77.30
  • 23.216.77.6
  • 23.216.77.11
  • 23.216.77.29
  • 23.216.77.8
  • 23.216.77.43
  • 23.216.77.36
  • 23.216.77.27
whitelisted

Threats

No threats detected
No debug info