File name:

OfficeSetup.exe

Full analysis: https://app.any.run/tasks/ab14e6db-72d0-47e8-a82d-b5d793f9590e
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:47:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

07E466E6FA4D2BEC8FD118B1CA90D8DB

SHA1:

F8EA01D80B7E4CA925B55D419372E3D31FAF62CD

SHA256:

19378D348529E8DFE298266A2179B0F90B8F77AFB3AA62BDF27961775D7945C9

SSDEEP:

98304:cAaq0sIWeyOyTyXOsTgOi+QwyDMI+KJEj/nh5eyX+4Ht1PuLIH9EBiqG97dcqnss:e26Bt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • OfficeSetup.exe (PID: 8004)
      • OfficeSetup.exe (PID: 936)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • OfficeSetup.exe (PID: 2792)
      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
    • Process drops legitimate windows executable

      • OfficeSetup.exe (PID: 2792)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
    • Application launched itself

      • OfficeSetup.exe (PID: 2792)
      • OfficeSetup.exe (PID: 936)
    • Reads security settings of Internet Explorer

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
    • Reads the date of Windows installation

      • OfficeSetup.exe (PID: 936)
    • Searches for installed software

      • OfficeSetup.exe (PID: 8004)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 8432)
  • INFO

    • Checks supported languages

      • OfficeSetup.exe (PID: 2792)
      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
      • OfficeClickToRun.exe (PID: 8600)
    • Reads the machine GUID from the registry

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
      • OfficeClickToRun.exe (PID: 8600)
    • Reads the computer name

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
      • OfficeClickToRun.exe (PID: 8600)
    • Process checks whether UAC notifications are on

      • OfficeSetup.exe (PID: 936)
    • Process checks computer location settings

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
    • Reads the software policy settings

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8600)
      • OfficeClickToRun.exe (PID: 8244)
    • Creates files or folders in the user directory

      • OfficeSetup.exe (PID: 936)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8600)
    • Reads Microsoft Office registry keys

      • OfficeSetup.exe (PID: 8004)
      • OfficeSetup.exe (PID: 936)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
      • OfficeClickToRun.exe (PID: 8600)
    • Reads CPU info

      • OfficeSetup.exe (PID: 8004)
      • OfficeSetup.exe (PID: 936)
    • Reads Environment values

      • OfficeSetup.exe (PID: 8004)
      • OfficeSetup.exe (PID: 936)
    • Checks proxy server information

      • OfficeSetup.exe (PID: 8004)
      • OfficeSetup.exe (PID: 936)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8600)
      • OfficeClickToRun.exe (PID: 8244)
    • Create files in a temporary directory

      • OfficeSetup.exe (PID: 936)
      • OfficeClickToRun.exe (PID: 8432)
      • OfficeSetup.exe (PID: 8004)
      • OfficeClickToRun.exe (PID: 8600)
    • The sample compiled with arabic language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with english language support

      • OfficeClickToRun.exe (PID: 8432)
    • Creates files in the program directory

      • OfficeClickToRun.exe (PID: 8432)
      • OfficeClickToRun.exe (PID: 8244)
    • The sample compiled with spanish language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with slovak language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with Indonesian language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with Italian language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with korean language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with japanese language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with polish language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with russian language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with swedish language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with portuguese language support

      • OfficeClickToRun.exe (PID: 8432)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 8244)
    • The sample compiled with chinese language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with german language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with bulgarian language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with czech language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with french language support

      • OfficeClickToRun.exe (PID: 8432)
    • The sample compiled with turkish language support

      • OfficeClickToRun.exe (PID: 8432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:09:28 22:59:30+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.42
CodeSize: 4768256
InitializedDataSize: 2723840
UninitializedDataSize: -
EntryPoint: 0x415e86
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.19231.20156
ProductVersionNumber: 16.0.19231.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.19231.20156
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.19231.20156
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
936OfficeSetup.exe RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2792"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" C:\Users\admin\AppData\Local\Temp\OfficeSetup.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
8004"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 RELAUNCHED C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Version:
16.0.19231.20156
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
8244"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.19231.20138
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\vcruntime140_1.dll
8432OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=O365ProPlusRetail.16_en-us_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.19231.20156 mediatype=CDN sourcetype=CDN O365ProPlusRetail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
8580C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
8600OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=O365ProPlusRetail.16_en-us_x-none cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.19231.20156 mediatype.16=CDN sourcetype.16=CDN O365ProPlusRetail.excludedapps.16=groove updatesenabled.16=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown uninstallcentennial=TrueC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.19231.20138
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8892C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
31 888
Read events
31 433
Write events
247
Delete events
208

Modification events

(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ru-ru
Value:
2
(PID) Process:(936) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:tr-tr
Value:
2
Executable files
412
Suspicious files
48
Text files
433
Unknown types
0

Dropped files

PID
Process
Filename
Type
936OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-shmbinary
MD5:EF94FD522F46C16610A2DF590DE14B37
SHA256:4DD8A0B5B42B5C6C8B6E42AE996160A0C1FA2A4F51792877EE96837DD2058CC6
936OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D056CE1E-6E16-430A-93D5-8330E00E9672xml
MD5:AE6F68E8273C6EFB5FD4D4FEBF6A3D91
SHA256:EFA2149B2FA196A70D8B3053EB520421287B4B54781EFB07FB20261DB32F6979
936OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-walbinary
MD5:5D9FE456376040ECE251FAFE4A8C5B94
SHA256:A9D75C147AFD309AC10540ABCF7E7DF9D4722D92D4364A602E41B12650B74381
936OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:5000A273C5A32AB4CBC3344D0A13EEC2
SHA256:D6F5563AE478567E8481479A58B5FFF67C185020B383B9EBEE95460C4EC85038
936OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:671A2E77E489DCABFCFF2C7673B8E229
SHA256:B4B486BA02252846E86E50E74210BB364426882F48A57B57C5A92F1DAEB4F69B
8004OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F59C76228DF8A2918214D353D01EDF08binary
MD5:21DD5A9C356D99539C83AB9C2ACC7BA8
SHA256:33519FB85B00DE8333D536D13E18451E7BF6C1A212CD1E9220D4BB31D78DEE3F
8004OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A583E2A51BFBDC1E492A57B7C8325850
MD5:9A6C3A86296BEC3070824451A699B6E5
SHA256:99E4AB8CC1CD4F8F371416A6D676AF04A864ED1BC7A7E48BA0CD40C1745FC2D6
8004OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A583E2A51BFBDC1E492A57B7C8325850binary
MD5:5E383F101A2DB6F2FE9C02EE5B8E2A3C
SHA256:A556E31EAAC04C277FD4F74C20F36F0F398A9ACE0A46D2B065152FFE90E28E0A
8004OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F59C76228DF8A2918214D353D01EDF08binary
MD5:4D700140B27EE16B35A47D6234198F57
SHA256:2E5DD84952B2B0F4AE3F2DB8310FF5D2A4DC31D06942E3D735929AE158A12E6E
8004OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:FDC4D0E3F0E9C6B55B4A934A02BF1FE1
SHA256:03ACAF66B4B28FE04411E27541825B9BFBED435512D4504F5BB5FC8F708ADBDB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
66
TCP/UDP connections
64
DNS requests
44
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8004
OfficeSetup.exe
HEAD
200
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
8004
OfficeSetup.exe
HEAD
200
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
936
OfficeSetup.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
US
binary
471 b
whitelisted
7252
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
7076
svchost.exe
HEAD
200
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
whitelisted
7076
svchost.exe
GET
206
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
binary
1 b
whitelisted
7076
svchost.exe
HEAD
200
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
binary
1 b
whitelisted
7076
svchost.exe
GET
200
2.16.10.72:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.19231.20156.cab
AT
compressed
12.0 Kb
whitelisted
8004
OfficeSetup.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crl
NL
binary
781 b
whitelisted
8004
OfficeSetup.exe
GET
200
23.216.77.32:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
DE
824 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
8100
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
936
OfficeSetup.exe
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
936
OfficeSetup.exe
52.123.129.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8004
OfficeSetup.exe
52.123.129.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8004
OfficeSetup.exe
52.110.17.75:443
mrodevicemgr.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4192
svchost.exe
239.255.255.250:1900
whitelisted
8004
OfficeSetup.exe
2.16.10.72:80
f.c2r.ts.cdn.office.net
Akamai International B.V.
AT
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
  • 52.109.76.240
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.110.17.75
  • 52.110.17.18
  • 52.110.17.38
  • 52.110.17.26
  • 52.110.17.3
  • 52.110.17.49
  • 52.110.17.32
  • 52.110.17.51
whitelisted
f.c2r.ts.cdn.office.net
  • 2.16.10.72
  • 2.16.10.90
  • 2.16.10.69
  • 2.16.10.85
  • 2.16.10.75
whitelisted
mobile.events.data.microsoft.com
  • 104.46.162.227
  • 20.42.73.31
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
www.bing.com
  • 2.16.241.205
  • 2.16.241.201
  • 2.16.241.207
  • 2.16.241.218
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.68
  • 40.126.31.73
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info