File name:

crosec.2.0.6-installer.exe

Full analysis: https://app.any.run/tasks/ce8a2281-357b-4c97-aeb9-d5a54517a238
Verdict: Malicious activity
Analysis date: May 18, 2025, 23:55:10
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

D03782C918467234D0EF8E3A49F88782

SHA1:

16419182217D85AC7DB81192E135E734A8C21827

SHA256:

1B2318E385473EBA862FD5B4EB98F2B1E01F5FAE60BB43A50B8590B43293900C

SSDEEP:

24576:aVyFUHybNprZpOzBLO8t+5mDpg2Fnm1fZhQ6SiaymIKT3PXlq7BcSawGbDmMJqve:YyFUHybNprvOzZO8t+5mDpg2Fnm1f/Q3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • crosec.2.0.6-installer.exe (PID: 1676)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • crosec.2.0.6-installer.exe (PID: 1676)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • crosec.2.0.6-installer.exe (PID: 1676)
    • Executable content was dropped or overwritten

      • crosec.2.0.6-installer.exe (PID: 1676)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 6036)
      • dpinst.exe (PID: 660)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
    • Process drops legitimate windows executable

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
    • Drops a system driver (possible attempt to evade defenses)

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 4244)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 6036)
      • drvinst.exe (PID: 4180)
      • dpinst.exe (PID: 660)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 6036)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
      • crosec.2.0.6-installer.exe (PID: 1676)
    • Creates a software uninstall entry

      • dpinst.exe (PID: 2108)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 660)
      • crosec.2.0.6-installer.exe (PID: 1676)
    • Reads security settings of Internet Explorer

      • crosec.2.0.6-installer.exe (PID: 1676)
  • INFO

    • Reads the computer name

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 6036)
      • drvinst.exe (PID: 5720)
      • dpinst.exe (PID: 660)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
    • Checks supported languages

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 6036)
      • dpinst.exe (PID: 660)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
      • crosecservice.exe (PID: 5324)
      • croskbreload.exe (PID: 6872)
    • Create files in a temporary directory

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 660)
    • The sample compiled with arabic language support

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
    • Creates files in the program directory

      • crosec.2.0.6-installer.exe (PID: 1676)
      • dpinst.exe (PID: 2108)
    • Reads the software policy settings

      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 6036)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 4812)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 660)
    • Reads the machine GUID from the registry

      • dpinst.exe (PID: 2108)
      • drvinst.exe (PID: 4244)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5380)
      • drvinst.exe (PID: 5720)
      • drvinst.exe (PID: 6644)
      • drvinst.exe (PID: 4180)
      • drvinst.exe (PID: 6036)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 5608)
      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 4812)
      • dpinst.exe (PID: 660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
20
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crosec.2.0.6-installer.exe sppextcomobj.exe no specs slui.exe no specs dpinst.exe drvinst.exe dpinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe dpinst.exe drvinst.exe drvinst.exe crosecservice.exe no specs croskbreload.exe no specs conhost.exe no specs crosec.2.0.6-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
660"C:\Program Files\crosec\drivers\dpinst.exe" /sw /f /path "C:\Program Files\crosec\drivers\keyboard"C:\Program Files\crosec\drivers\dpinst.exe
crosec.2.0.6-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\program files\crosec\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1676"C:\Users\admin\AppData\Local\Temp\crosec.2.0.6-installer.exe" C:\Users\admin\AppData\Local\Temp\crosec.2.0.6-installer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\crosec.2.0.6-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2108"C:\Program Files\crosec\drivers\dpinst.exe" /sw /f /path "C:\Program Files\crosec\drivers\coreboot"C:\Program Files\crosec\drivers\dpinst.exe
crosec.2.0.6-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\crosec\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2152DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{9223c96b-40df-734e-bbc2-a979be6d2399}\cbtable.inf" "9" "4bc582013" "00000000000001D8" "WinSta0\Default" "000000000000017C" "208" "c:\program files\crosec\drivers\coreboot"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4180DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{39649d63-1cb5-dd44-9834-3850373d6588}\croskblight.inf" "9" "4b05c8bdf" "000000000000022C" "WinSta0\Default" "0000000000000228" "208" "c:\program files\crosec\drivers\crosec"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4244DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2d7f508a-3c67-7343-8438-6d8ae3b6dc87}\croseccodec.inf" "9" "434c9e0cb" "000000000000017C" "WinSta0\Default" "00000000000001E0" "208" "c:\program files\crosec\drivers\crosec"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4724\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execroskbreload.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4812DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d4ea49e3-3451-e94c-bec5-35fdb13c346d}\croskeyboard.inf" "9" "4278a4ceb" "0000000000000244" "WinSta0\Default" "0000000000000248" "208" "c:\program files\crosec\drivers\keyboard"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4980"C:\Users\admin\AppData\Local\Temp\crosec.2.0.6-installer.exe" C:\Users\admin\AppData\Local\Temp\crosec.2.0.6-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\crosec.2.0.6-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
40 242
Read events
40 188
Write events
54
Delete events
0

Modification events

(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\B043D7065B98B0C9C8F2FBAF0223790A4E4F7BB3
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\cbtable.inf_amd64_7d7f44e99ab710d7\cbtable.inf
(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\B043D7065B98B0C9C8F2FBAF0223790A4E4F7BB3
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (cbtable) System (04/22/2024 1.0.1.0)
(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\B043D7065B98B0C9C8F2FBAF0223790A4E4F7BB3
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\B043D7065B98B0C9C8F2FBAF0223790A4E4F7BB3
Operation:writeName:DisplayVersion
Value:
04/22/2024 1.0.1.0
(PID) Process:(2108) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\B043D7065B98B0C9C8F2FBAF0223790A4E4F7BB3
Operation:writeName:Publisher
Value:
CoolStar
(PID) Process:(6132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\F017585E906ED3E2BE7915B7E2DEE9A9E6D7BF3D
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\crosecbus.inf_amd64_b19fe4264baca9f4\crosecbus.inf
(PID) Process:(6132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\F017585E906ED3E2BE7915B7E2DEE9A9E6D7BF3D
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (CrosEcBus) System (05/03/2024 2.1.0.0)
(PID) Process:(6132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\F017585E906ED3E2BE7915B7E2DEE9A9E6D7BF3D
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(6132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\F017585E906ED3E2BE7915B7E2DEE9A9E6D7BF3D
Operation:writeName:DisplayVersion
Value:
05/03/2024 2.1.0.0
Executable files
60
Suspicious files
121
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1676crosec.2.0.6-installer.exeC:\Users\admin\AppData\Local\Temp\nssBD67.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\croskbrgb_generic_2.binbinary
MD5:E819A906104EADA94970AE82FA0993A5
SHA256:FCD67E4102572F79527E3041B896375C704EB00DE930CE2C4357C496C6193DB6
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseci2c.catbinary
MD5:AC9C208B412FED6CE8615ED349C07DC2
SHA256:2A69479A72DC0A2E59D5C298D2E5071B84653317BF6AFBB6AF83B5836917AA44
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseccodec.infbinary
MD5:37903A083DE5A2BCDB5264005D620962
SHA256:2A27DC439AD27F6B4D473ABA93CF3451DDC822F783526D7DF15491034050D110
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseccodec.sysexecutable
MD5:5A80D5141C1B7871EE1EDCBC8A6111F6
SHA256:AC537591BE786210F5E9BC5FA1FF14CFB440E016AD45B0E6BC3EF17C8F1AF788
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\crosecbus.sysexecutable
MD5:190B0D3D44B6BF8460732D30C4024F8D
SHA256:C621B5CE910882413F0503D0A137654166C56BF14C21D0C4AB16B02D53AFF8B6
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseccodec.catbinary
MD5:6702074C8D9480A221DBCC8F4A76B424
SHA256:B07D6E6F8684D9F1A48C577B434F02CC6A5E59781A646B58F5AFEC29C4382F80
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseci2c.sysexecutable
MD5:FA45CBA89B57CBCDEA7803CD0D002F52
SHA256:99F591FE5272724F5188AFB6AC1714A39CFD5DB9DC5E4EBFBB647067920A7CB5
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\croseci2c.infbinary
MD5:BE4A72630523C0CC2815AD97DFC817A6
SHA256:C13E395342D7F57354B88B1AD62CD44998DDB4EA47948A41E33380C759A1FD50
1676crosec.2.0.6-installer.exeC:\Program Files\crosec\drivers\crosec\crosectypec.catbinary
MD5:083EC8FDBB038505031B10D59CD8B8FD
SHA256:3381B9A41ACB6CCD6C0BF6B6ABC5095F1C2D4C67C9CB012719C78256E0503006
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
14
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.20
  • 20.190.160.131
  • 20.190.160.2
  • 40.126.32.76
  • 40.126.32.136
  • 20.190.160.132
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted

Threats

No threats detected
No debug info